Brian Hubbard Brian Hubbard

Department of Defense Organization-Defined Parameters for National Institute of Standards and Technology Special Publication 800-171 Revision 3

The Department of Defense (DoD) memorandum titled “Department of Defense Organization-Defined Parameters for National Institute of Standards and Technology Special Publication 800-171 Revision 3” establishes standardized values for Organization-Defined Parameters (ODPs) within NIST SP 800-171 Revision 3. These ODPs allow organizations to tailor specific security controls based on their unique risk management strategies. The DoD’s defined ODP values are intended to serve as the minimum security requirements for contractors handling Controlled Unclassified Information (CUI).

Read More
32 CFR Part 170
Brian Hubbard Brian Hubbard

32 CFR Part 170

32 CFR Part 170 is a section of the Code of Federal Regulations that establishes the rules governing the CMMC (Cybersecurity Maturity Model Certification) program under the authority of the Department of Defense (DoD).

Read More
CMMC Scoping Guide for Level 1
Brian Hubbard Brian Hubbard

CMMC Scoping Guide for Level 1

The CMMC Scoping Guide for Level 1 provides guidance on identifying which assets within a contractor’s environment must be protected and assessed when handling Federal Contract Information (FCI).

Read More
CMMC Level 1 Self-Assessment Guide
Brian Hubbard Brian Hubbard

CMMC Level 1 Self-Assessment Guide

The CMMC Level 1 Self-Assessment Guide provides instructions for DoD contractors to evaluate their compliance with 15 basic safeguarding practices required under FAR 52.204-21 to protect Federal Contract Information (FCI).

Read More
CMMC Level 2 Scoping Guidance
Brian Hubbard Brian Hubbard

CMMC Level 2 Scoping Guidance

The CMMC Level 2 Scoping Guidance outlines how contractors must identify and categorize assets in their environment when preparing for an assessment related to Controlled Unclassified Information (CUI). This applies to both self-assessments and third-party/government-led assessments.

Read More
CMMC Level 2 Assessment Guide
Brian Hubbard Brian Hubbard

CMMC Level 2 Assessment Guide

The CMMC Level 2 Assessment Guide provides detailed instructions for conducting assessments against the 110 security requirements outlined in NIST SP 800-171, which are mandatory for protecting Controlled Unclassified Information (CUI).

Read More
CMMC Level 3 Assessment Guide
Brian Hubbard Brian Hubbard

CMMC Level 3 Assessment Guide

The CMMC Level 3 Assessment Guide provides a framework for evaluating an organization’s implementation of advanced cybersecurity practices required to protect highly sensitive Controlled Unclassified Information (CUI) in support of critical national security objectives.

Read More
CMMC Level 3 Scoping Guidance
Brian Hubbard Brian Hubbard

CMMC Level 3 Scoping Guidance

The CMMC Level 3 Scoping Guidance (v2.13) outlines how DoD contractors must identify and document systems and assets in preparation for a Level 3 certification assessment, as defined in 32 CFR § 170.19. This guide is for organizations handling highly sensitive Controlled Unclassified Information (CUI) that supports national security missions.

Read More
CMMC Hashing Guide
Brian Hubbard Brian Hubbard

CMMC Hashing Guide

The CMMC Hashing Guide (v2.13) provides instructions for using the CMMC Artifact Hashing Tool, a PowerShell-based script that generates cryptographic hashes (using SHA-256) of assessment artifacts. This process ensures the integrity of evidence collected during a CMMC Level 2 or Level 3 assessment.

Read More
Brian Hubbard Brian Hubbard

Useful CMMC Links

Useful CMMC links to additional resources from the DoD CMMC website.

Read More
Brian Hubbard Brian Hubbard

DoD Published Briefings on CMMC

The DoD Publishes official briefings from time to time. It is important to note that these briefings should NOT be treated as official guidance.

Read More