02-2020-21123
02-2020-21123
5001-06-P
DEPARTMENT OF DEFENSE
[Docket DARS-2020-0034]
RIN 0750-AJ81
Case 2019-D041)
Defense (DoD).
chain.
telephone 571-372–6104.
SUPPLEMENTARY INFORMATION:
I. Background
U.S. economy between $57 billion and $109 billion in 2016. Over
a ten-year period, that burden would equate to an estimated $570
information within the supply chain. Toward this end, DoD has
171 DoD Assessment and CMMC assessments will not duplicate efforts
from each assessment, or any other DoD assessment, except for rare
compliance.
https://www.acq.osd.mil/dpap/pdi/cyber/strategically_assessing_c
ontractor_implementation_of_NIST_SP_800-171.html.
current (i.e., not more than three years old, unless a lesser
from the broader community. The CMMC levels and the associated
sets of processes and practices are cumulative. The CMMC model
Level Description
certification level and currency (i.e. not more than three years
https://www.acq.osd.mil/cmmc/index.html.
current (i.e. not older than three years) certification for the
items.
have a current (not older than three years) NIST SP 800-171 DoD
SPRS.
current and meets the required level prior to making the award.
chain and prevent the appropriate flow of CUI and FCI. The
C. Conforming Changes
conforming changes:
the contract.
contract clauses:
Assessment Requirements;
Requirements; and
Certification Requirements.
achieve the desired policy outcome, DoD intends to apply the new
A. Benefits
enhance the protection of FCI and CUI within the DIB sector.
B. Costs
2. CMMC Requirements
U.S.C. 804.
is summarized as follows:
However, neither the FAR clause, nor the DFARS clause, provide
development effort.
Furthermore, given the size and scale of the DIB sector, the
Threats (APTs).
and Organizations.”
of cybersecurity practices.
the use of accredited C3PAOs. The company must achieve the CMMC
scale of the DIB sector, the Department cannot scale its organic
threshold.
system for fiscal years (FYs) 2016, 2017, and 2018, on an annual
High 81 81 81
7012.
rollout assumes that for every unique prime contractor there are
These NAICS codes are the same as the DoD Assessment NAICS codes
252.204-7012.
CMMC Framework, the estimated public costs are based on the cost
three years. A company that has fully implemented all 110 NIST
their score.
the score. DoD estimates that the burden to calculate the Basic
$49.54/assessment)).
To submit the Basic Assessment, the contractor is required to
complete 6 fields: system security plan name (if more than one
total score; and the date a score of 110 will be achieved. All
contractor selects the date when the last plan of action will be
The estimate for the rate of pay for both preparation and
a GS-9 clerk, the GS-13 (or perhaps GS-11) is the most likely
who would complete the assessment and submit the data in SPRS
and will identify any descriptions that may not properly address
their system security plan. DoD will post the results in SPRS.
For the Medium Assessment, DoD estimates that the burden for a
For the High Assessment, DoD estimates that the burden for a
this rule. Since assessments are valid for three years, the
The following table presents the average annual cost per small
revenue for a small entity for four of the top five NAICS codes.
Range of Annual
Basic Assessment Medium Assessment High Assessment
NAICS Revenues for
Annual Cost as % Annual Cost as % Annual Cost as %
Code Small Businesses
of Annual Revenue of Annual Revenue of Annual Revenue
(in millions)
2. CMMC Framework
https://www.acq.osd.mil/cmmc/index.html.
Level Description
reports to the CMMC-AB who will then maintain and store these
software, and the associated labor. The costs are incurred only
certification cost.
i. Level 1 Certification
45 hours each to conduct the assessment (16 hours for pre- and
= $2,000 airfare)).
v. Level 5 Certification
every 3 years.
Average
Recurring Average Total Annual
Nonrecurring
CMMC Cert Engineering Assessment Assessment
Engineering
Costs Costs Cost
Costs
The following table presents the average annual cost per small
the top five NAICS codes. The low-end of the range of annual
presents the annual cost per small entity for CMMC certification
small in the System for Award Management (SAM) for their primary
Annual Revenue of
NAICS
7012, and ensures that the entire DIB sector has the appropriate
cybersecurity processes and practices in place to properly
on small entities
163,391 or 74% being small entities. The RIA also specifies the
assessment.
Level 2.
For CMMC Level 3, the practices encompass all the 110 security
abrupt.
flow of CUI and FCI. The Department seeks public comment on the
Number.
a. Basic Assessment
Respondents: 13,068.
Respondents: 200.
c. High Assessment
Respondents: 110.
Respondents: 13,068.
Respondents: 8,823.
FAR and DFARS. In 2013, DoD issued a final DFARS rule (78 FR
the FAR Council mandated the use of FAR clause 52.204-21, Basic
the DIB sector, the results were reinforced by the findings from
2 National Defense Industrial Association (NDIA). “Implementing Cybersecurity in DoD Supply Chains.” White
Paper. July 2018.
3 NDIA. “Beyond Obfuscation: The Defense Industry’s Position within Federal Cybersecurity Policy.” A Report of
the NDIA Policy Department. October 2018. page 20 and page 24.
national security. The various industry surveys and Government
Department’s assessment.
4Section 1648 of the NDAA for FY 2020 mandates the formulation of “unified cybersecurity . . . regulations . . . to
be imposed on the defense industrial base for the purpose of assessing the cybersecurity of individual contractors,”
It is equally urgent for the Department to ensure DIB
Government procurement.
Jennifer D. Johnson,
System.
Therefore, 48 CFR parts 204, 212, 217, and 252 are amended as
follows:
1. The authority citation for 48 CFR parts 204, 212, 217, and
5FAR 1.501-3(b) states that “[a]dvance comments need not be solicited when urgent and compelling circumstances
make solicitation of comments impracticable prior to the effective date of the coverage, such as when a new statute
must be implemented in a relatively short period of time. In such case, the coverage shall be issued on a temporary
basis and shall provide for at least a 30 day public comment period.”
2. Amend section 204.7302 by revising paragraph (a) to read as
follows:
204.7302 Policy.
252.204-7019).
located at
https://www.acq.osd.mil/dpap/pdi/cyber/strategically_assessing_c
ontractor_implementation_of_NIST_SP_800-171.html.
such as, but not limited to, when cybersecurity risks, threats,
or awareness have changed, requiring a re-assessment to ensure
current compliance.
* * * * *
204.7303 Procedures.
items.
for those that are solely for the acquisition of COTS items.
to read as follows:
Sec.
204.7501 Policy.
204.7502 Procedures.
https://www.acq.osd.mil/cmmc/index.html).
Program.
204.7501 Policy.
(c) The CMMC Assessments shall not duplicate efforts from any
204.7502 Procedures.
contract.
approved by OUSD(A&S).
* * * * *
(f) * * *
(ii) * * *
(b).
* * * * *
follows:
spare parts.
DoD Assessment (i.e., not more than 3 years old, unless a lesser
read as follows:
Sec.
* * * * *
* * * * *
Requirements.
(a) Definitions.
Assessments.
have a current assessment (i.e., not more than 3 years old unless a
https://www.acq.osd.mil/dpap/pdi/cyber/strategically_assessing_cont
ractor_implementation_of_NIST_SP_800-171.html.
current NIST SP 800-171 DoD Assessment (i.e., not more than 3 years
strategic assessments.
to SPRS.
Contractor self-assessment).
CAGE
Brief Date
Codes
System description Date of Total score of
supported
Security Plan of the plan assessment Score 110 will
by this
architecture achieved
plan
(2) Medium and High Assessments. DoD will post the following
Medium and/or High Assessment summary level scores to SPRS for each
system assessed:
high.
(vi) Summary level score (e.g., 105 out of 110, not the
the assessment was conducted may access SPRS to view their own
https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf.
(End of provision)
(a) Definitions.
system(s);
score.
Government that—
resulting score.
contract.
https://www.acq.osd.mil/dpap/pdi/cyber/strategically_assessing_cont
ractor_implementation_of_NIST_SP_800-171.html, if necessary.
(2) Medium and High Assessments. DoD will post the following
Medium and/or High Assessment summary level scores to SPRS for each
high.
(vi) Summary level score (e.g., 105 out of 110, not the
level scores prior to posting the summary level scores to SPRS (see
https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf).
Information (PI).
the assessment was conducted may access SPRS to view their own
https://www.sprs.csd.disa.mil/pdf/SPRS_Awardee.pdf.
COTS items).
https://www.acq.osd.mil/dpap/pdi/cyber/strategically_assessing_cont
(End of clause)
clause:
https://www.acq.osd.mil/cmmc/index.html).
not older than 3 years) CMMC certificate at the CMMC level required
items; and
(End of clause)
[FR Doc. 2020-21123 Filed: 9/28/2020 8:45 am; Publication Date: 9/29/2020]