Recent sweeping updates to the U.S. Department of Defense Cybersecurity Maturity Model Certification (CMMC) requirements have left the consultants, contractors, and the Defense Industrial Base (DIB) questioning where this leaves us and how to proceed. This course is intended to address the questions of what CMMC 2.0 is all about, how certification will work under the new model, the SP 800-171 requirements that must be satisfied and how to meet them, and what this means for DoD contracting organizations.
These exact 800-171 requirements cover all Non-Federal Organizations (NFOs) that handle U.S. Federal Government controlled unclassified information. This course will also feature self-attestation guidance and will help organizations meet the external 3rd party assessments that will still be required for a subset of businesses handling protected U.S. Federal Government information.
CMMC 2.0 and NIST SP 800-171 Training Delivery Methods
In-Person
Online
CMMC 2.0 and NIST SP 800-171 Training Course Information
CMMC 2.0 and NIST SP 800-171 Training Course Benefits
Understand and comply with the new CMMC 2.0 framework
Assess CMMC 2.0 and CMMC 1.0 differences and repercussions to your organization
Meet NIST SP 800-171 requirements
Perform self-assessments conforming to DFARS standards and generate a SPRS score
Identify which contract levels are subject to independent assessments
Satisfy third-party CMMC 2.0/SP 800-171 assessments
Maintain an acceptable security posture over the contract lifecycle
Continue learning and face new challenges with after-course one-on-one instructor coaching
CMMC 2.0 and NIST SP 800-171 Training Course Prerequisites
Prior security experience is helpful but not necessary. Critical thinking skills and the ability to make decisions are key.
CMMC 2.0 and NIST SP 800-171 Training Outline
Lesson 1 – The Nature of Protected Information
Acknowledging the importance of protecting US Government information
Recognizing categories of protected information
Describing protected information and the law
Lesson 2 – Threats to Protected Information
Lesson 3 – Introduction to CMMC 2.0
Lesson 4 – CMMC 2.0 and NIST SP 800-171
Lesson 5 – Characterizing the Non-Federal System
Lesson 6 – Securing the Organizational System
Lesson 7 – Assessing System Cybersecurity Risk
Lesson 8 – Reporting Self-Assessment Results