The load-bearing documents for a DIB program — CMMC / DFARS regulatory text (eCFR), federal rulemaking, NIST publications and OIRA review — organized as a library. Pick a document; the reader shows the dex dossier: what it says, why it matters, and the concrete obligations it imposes. Originals open at the source.
32 CFR 170 (CMMC Program): § 170.21 Plan of Action and Milestones requirements. amended 2024-12-16
32 CFR 170.24 establishes the CMMC scoring methodology, allowing partial credit for certain controls like MFA and FIPS implementation.
This section of the CMMC Program regulation outlines the methodology used to score contractor compliance with the CMMC Model. It specifically addresses how partial credit is awarded for controls such as Multi-Factor Authentication (MFA) and FIPS-compliant cryptographic modules, aligning with the broader CMMC assessment framework.
DIBs must understand the scoring methodology to accurately self-assess and prepare for third-party assessments, as partial credit rules directly impact the final compliance score and certification outcome.
- Understand and apply the CMMC scoring methodology, including partial credit rules for MFA and FIPS.
- Ensure self-assessments and third-party assessments accurately reflect the scoring methodology.