Skip to content
COOEY
REGULATORY LIBRARY
98 docs in this shelf

The load-bearing documents for a DIB program — CMMC / DFARS regulatory text (eCFR), federal rulemaking, NIST publications and OIRA review — organized as a library. Pick a document; the reader shows the dex dossier: what it says, why it matters, and the concrete obligations it imposes. Originals open at the source.

DIRECTORY_TREE
CMMC / DFARS · eCFR 98
DFARS 252.204 (cyber clauses): 252.204-7025 Notice of Cybersecurity Maturity Model Certification Level Requirements. amended 2025-11-10 2025-11-10 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. amended 2025-11-10 2025-11-10 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7007 Alternate A, Annual Representations and Certifications. amended 2025-10-01 2025-10-01 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7025 xxx amended 2025-09-10 2025-09-10 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7021 Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirement. amended 2025-09-10 2025-09-10 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7007 Alternate A, Annual Representations and Certifications. amended 2025-08-25 2025-08-25 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.14 CMMC Model. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.23 Application to subcontractors. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.8 Accreditation Body. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.13 CMMC Certified Professional (CCP). amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.24 CMMC Scoring Methodology. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.17 CMMC Level 2 certification assessment and affirmation requirements. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.7 DCMA DIBCAC. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.1 Purpose. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.12 CMMC Instructor. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.5 Policy. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.18 CMMC Level 3 certification assessment and affirmation requirements. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.4 Acronyms and definitions. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.19 CMMC scoping. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.20 Standards acceptance. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.21 Plan of Action and Milestones requirements. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.22 Affirmation. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.15 CMMC Level 1 self-assessment and affirmation requirements. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.3 Applicability. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.9 CMMC Third-Party Assessment Organizations (C3PAOs). amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.6 CMMC PMO. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.16 CMMC Level 2 self-assessment and affirmation requirements. amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.11 CMMC Certified Assessor (CCA). amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.10 CMMC Assessor and Instructor Certification Organization (CAICO). amended 2024-12-16 2024-12-16 · ecfr-amendment 32 CFR 170 (CMMC Program): § 170.2 Incorporation by reference. amended 2024-12-16 2024-12-16 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7007 Alternate A, Annual Representations and Certifications. amended 2024-10-01 2024-10-01 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7007 Alternate A, Annual Representations and Certifications. amended 2024-09-26 2024-09-26 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting. amended 2024-05-30 2024-05-30 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7004 Antiterrorism Awareness Training for Contractors. amended 2023-12-07 2023-12-07 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7007 Alternate A, Annual Representations and Certifications. amended 2023-11-17 2023-11-17 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements. amended 2023-11-17 2023-11-17 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7020 NIST SP 800-171 DoD Assessment Requirements. amended 2023-11-17 2023-11-17 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7006 Billing Instructions—Cost Vouchers. amended 2023-05-25 2023-05-25 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7024 Notice on the Use of the Supplier Performance Risk System. amended 2023-03-22 2023-03-22 · ecfr-amendment DFARS 252.204 (cyber clauses): 252.204-7018 Prohibition on the Acquisition of Covered Defense Telecommunications Equipment or Services. amended 2023-03-01 2023-03-01 · ecfr-amendment
1/3 NEXT ▸
Federal rulemaking 14 NIST publications 14 OIRA · OMB review 1
LAST_SYNC: 2026-08-23 18:00
DOC_VIEWER open original ↗
eCFR rule 2024-12-16 ◆ DEX DOSSIER

32 CFR 170 (CMMC Program): § 170.6 CMMC PMO. amended 2024-12-16

32 CFR 170.24 establishes the CMMC scoring methodology, allowing partial credit for certain controls like MFA and FIPS implementation.

This section of the CMMC Program regulation outlines the methodology used to score contractor compliance with the CMMC Model. It specifically addresses how partial credit is awarded for controls such as Multi-Factor Authentication (MFA) and FIPS-compliant cryptographic modules, aligning with the broader CMMC assessment framework.

--- [ Regulatory impact ] ---

DIBs must understand the scoring methodology to accurately self-assess and prepare for third-party assessments, as partial credit rules directly impact the final compliance score and certification outcome.

Obligations it imposes · 2
  1. Understand and apply the CMMC scoring methodology, including partial credit rules for MFA and FIPS.
  2. Ensure self-assessments and third-party assessments accurately reflect the scoring methodology.
OPEN_ORIGINAL ↗ PERMALINK ⎘ ecfr/b834bf36-8b9b-42b8-a297-8e4441a378d1◈ IRIX document body stays at the source — we index, enrich & link