Learn about the 3 criteria that trigger a CMMC Level 3 requirement, NIST SP 800-172A, the prerequisite for beginning a CMMC Level 3 assessment, and more, through the Frequently Asked Questions (FAQs) below. If you are looking for certified CMMC Professionals and a customized solution for your organization, please schedule a free consultation.
Table of Contents
What is CMMC Level 3 Expert certification and which contractors need it?
Summary: CMMC Level 3 Expert certification is the highest tier of CMMC compliance, requiring implementation of all 110 NIST SP 800-171 Rev 2 controls plus 24 enhanced requirements from NIST SP 800-172, assessed by the DoD’s Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), and applies to a small subset of defense contractors who handle CUI associated with the most sensitive and critical defense programs.
Level 3 is designed for scenarios where the CUI being handled is so sensitive, so aggregated, or so systemically critical that the standard Level 2 protections are insufficient to address the threat posed by Advanced Persistent Threat (APT) actors, typically state-sponsored adversaries. The DoD estimates that only a few hundred contractors will ultimately require Level 3 certification.
These are primarily large prime contractors on major weapons systems programs, aerospace and defense companies with classified-adjacent research, and contractors operating critical information technology infrastructure for the DoD. Level 3 contractors are specifically identified through the contracting process; it is not self-selected. The DoD program office or requiring activity makes the Level 3 determination based on the nature of the CUI and contract program requirements.
What are the three criteria that trigger a CMMC Level 3 requirement?
The three criteria that trigger a CMMC Level 3 certification requirement, as defined in 32 CFR Part 170, are breakthrough or unique technology, large aggregation risk, and ubiquity risk.
Criterion 1, Breakthrough or unique technology: The contractor handles CUI associated with technology that is breakthrough, unique, or advanced, such as next-generation hypersonic weapons, directed energy systems, advanced AI applications for defense, or classified-adjacent research programs. The concern is that exfiltration of this CUI would dramatically close the U.S. technology advantage.
Criterion 2, Large aggregation: The contractor operates an information system containing a significant aggregation or compilation of CUI such that an attack on that single system would result in the adversary obtaining a comprehensive, high-value collection of defense-sensitive information.
Criterion 3, Ubiquity: The contractor operates a system so widely interconnected with DoD programs, systems, or supply chains that a successful attack would create widespread vulnerability across the Defense Industrial Base or multiple DoD programs simultaneously. The DoD program office applies these criteria when specifying CMMC requirements in solicitations.
What is the DIBCAC and how does it certify Level 3?
Summary: The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) is an operational element of the Defense Contract Management Agency (DCMA) that conducts cybersecurity assessments of defense contractors on behalf of the DoD and serves as the sole authorized body for conducting CMMC Level 3 certification assessments.
DIBCAC was established by the DoD to provide government-led cybersecurity oversight of the Defense Industrial Base, conducting both voluntary and mandatory assessments. For CMMC Level 3, DIBCAC assessors evaluate the contractor’s compliance with all 110 NIST SP 800-171 Rev 2 controls plus all 24 required enhancements from NIST SP 800-172, using assessment procedures from NIST SP 800-172A.
DIBCAC assessments are initiated through the contracting process; contractors do not schedule DIBCAC assessments voluntarily; they are scheduled based on contract requirements. The DIBCAC assessment team applies the same three-method assessment approach (Examine, Interview, Test) as C3PAO assessments. Level 3 certification is issued by the DoD, not by the Cyber AB. Valid Final CMMC Level 2 certification from a Cyber AB-authorized C3PAO is a mandatory prerequisite before any DIBCAC Level 3 assessment can be scheduled.
What is NIST SP 800-172A and how is it used in a Level 3 assessment?
NIST Special Publication 800-172A, titled “Assessment Procedures for Enhanced Security Requirements for Protecting Controlled Unclassified Information,” is the NIST companion document to NIST SP 800-172 that provides the specific assessment procedures used by DIBCAC assessors to evaluate contractor implementation of the 24 enhanced security requirements required for CMMC Level 3.
Published by NIST in 2022, SP 800-172A defines the assessment objectives, methods, and evidence standards for each of the 35 enhanced requirements in NIST SP 800-172, of which 24 are selected by the DoD for CMMC Level 3. For each enhanced requirement, SP 800-172A provides the assessment objectives that must be satisfied, the applicable assessment methods (Examine, Interview, and/or Test), and examples of assessment evidence.
DIBCAC assessors apply these procedures alongside the NIST SP 800-171A procedures, which govern the Level 2 controls, to conduct a comprehensive Level 3 evaluation. Contractors preparing for Level 3 should study SP 800-172A to understand exactly what DIBCAC assessors will examine, what they will ask in interviews, and what technical controls they will test, the same way Level 2 contractors study NIST SP 800-171A and the CMMC Assessment Guide, Level 2.
What is the prerequisite for beginning a CMMC Level 3 assessment?
The mandatory prerequisite for beginning a CMMC Level 3 DIBCAC assessment is a current, valid Final CMMC Level 2 C3PAO certification, a Conditional Level 2 status does not satisfy the Level 3 prerequisite, and the DIBCAC will not schedule a Level 3 assessment until the Level 2 certification is Final.
This prerequisite reflects the cumulative structure of the CMMC program: Level 3 builds on top of Level 2 requirements. An organization cannot demonstrate readiness for the 24 enhanced NIST SP 800-172 requirements without first demonstrating that all 110 NIST SP 800-171 Rev 2 requirements are fully implemented. The Level 2 C3PAO certification provides the DoD with an independent, verified baseline that allows DIBCAC to focus its Level 3 assessment on the enhanced requirements.
Contractors identified for Level 3 requirements should plan their Level 2 certification timeline to account for the Level 3 assessment schedule, including the time needed to identify and engage a C3PAO for Level 2, complete Level 2 certification, and then schedule the DIBCAC Level 3 assessment. The cumulative lead time from starting Level 2 preparation to achieving Level 3 certification can exceed 24 to 36 months for organizations beginning from a low baseline.
Explore Blogs, Webinars and other Resources
Trusted by Reputed Companies
What Our Clients Say
We used databrackets (formerly EHR 2.0) in our small medical practice for our risk analysis assessment to be in compliance with meaningful use. Their response was fast, the final report is detailed but simple and easy to follow. They were always available to answer our questions.
E. Compres
Pulmonary and Sleep Center of the Valley
I never miss the opportunity to learn something new …that’s why I am always registering to all free seminars offered on the web. databrackets (formerly EHR 2.0) happened to be the friendliest, comprehensive and up-to- date source of HIPAA Privacy and Security updates.
Alexandra V.
Community Healthcare Network
Today’s presentation was great! Thank you for sending the slides. My only feedback is that it would be fabulous to have the slides ahead of time so I could print them and take notes on the slides.Thanks for your time and knowledge today!
T.B., PM
Community Health Network
Particularly interesting was the flow chart on Administrative Simplification. I utilize all of the Security subcategories you list under the Security tile and appreciate knowing that I am hitting all of the relevant topics during my employee training.
Jessica B.
JD, CHC
I have re-worked our original risk assessment….We are using databrackets' (formerly EHR 2.0) Meaningful Use Security Risk Analysis Toolkit and it meets our needs. It was easy to use and I believe that it very beneficial to our meeting meaningful use.
Bill Curtis
Neurosurgical Associates Of Texarkana, TX
Information (webinars) presented by databrackets (formerly EHR 2.0) highlights some of today’s most demanding healthcare topics. The webinars help to direct those operating in today’s rapidly changing environment in the right direction.
Candace M.
Privacy and Security Officer, Springhill Medical Center
Our Growing List of Credentials
0
+
Assessments
0
+
Clients
0
+
Assessment Libraries
0
+
Years of Experience
0
+
No. of Staff Trained
0
+
HIPAA
0
+
SOC 2 Readiness
0
+
Pen Testing
0
+
ISO 27001 Certifications
0
+
Dollars Saved in Compliance Penalties