FINAL REVIEW PACK COMPLETE QUESTION
SET AND CORE CONCEPT SUMMARY
◉ What problem is CMMC trying to reduce? Answer: The theft/loss
of intellectual property and sensitive unclassified information from
the DoD supply chain due to malicious cyber activity.
◉ What are the two key unclassified info types CMMC is designed to
protect? Answer: Federal Contract Information (FCI) and Controlled
Unclassified Information (CUI).
◉ What is Federal Contract Information (FCI)? Answer: Information
provided by or generated for the Government under contract that is
not intended for public release.
◉ What is Controlled Unclassified Information (CUI)? Answer:
Information requiring safeguarding or dissemination controls per
laws/regulations/government-wide policy, excluding classified
information and Atomic Energy Act information.
◉ Which contract clauses and standards are the backbone sources
for CMMC v2.0? Answer: FAR 52.204-21 (FCI basic safeguarding)
, and NIST SP 800-171 Rev 2 via DFARS 252.204-7012 (CUI security
requirements).
◉ What does DFARS 252.204-7012 add beyond NIST SP 800-171
requirements? Answer: It includes additional requirements such as
incident reporting (beyond the 800-171 control set).
◉ What is the high-level idea behind "levels" in CMMC? Answer:
CMMC measures implementation maturity in tiers so the required
practices match the sensitivity/risk of the information handled.
◉ How many levels are in CMMC 2.0? Answer: Three levels: Level 1,
Level 2, Level 3.
◉ Is CMMC cumulative? Answer: Yes. To achieve a level, you must
satisfy that level plus all practices in the lower levels.
◉ If an organization misses its targeted level, what happens?
Answer: It is certified at the highest level for which it has achieved
all applicable practices.
◉ What does CMMC Level 1 focus on? Answer: Protection of FCI
using basic safeguarding requirements aligned to FAR 52.204-21.