Official DoD CMMC Core Documents
The authoritative documents from DoD CIO. These supersede any third-party summary.
CMMC Program Main Page (DoD CIO)
The official home of the DoD's Cybersecurity Maturity Model Certification program. Start here for authoritative announcements.
Why it matters: Anchor source for every C3PAO-referenced program document.
CMMC Documentation Hub
Official index of every DoD-published CMMC guide, model overview, and scoping document.
Why it matters: Bookmark this — versions update here first.
CMMC Model Overviewv2.13
Executive-level overview of the three CMMC levels, practices, and program structure.
Why it matters: Essential context for leadership briefings and CCP fundamentals.
CMMC Assessment Guide — Level 2v2.13
The primary assessment document. Contains all 110 NIST SP 800-171 objectives and assessment methods (Examine, Interview, Test).
Why it matters: This is the single most important document for C3PAO preparation.
Tip: Print or bookmark. Every gap-analysis meeting should map back to a specific objective in this guide.
CMMC Scoping Guide — Level 2v2.13
Defines asset categories (CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, Out-of-Scope Assets).
Why it matters: Wrong scoping is the #1 reason for C3PAO delays and findings.
Tip: Walk your network diagram against this guide before drafting your SSP boundary.
CMMC Assessment Guide — Level 1v2.13
Covers the 17 FAR 52.204-21 safeguards and self-assessment methodology for FCI-only environments.
Why it matters: Use when the contract only requires basic safeguarding of FCI.
32 CFR Part 170 — CMMC Program Final Rule
The federal regulation that codifies the CMMC program, including enforcement, affirmation, and POA&M rules.
Why it matters: Cited by every serious CMMC assessor and legal team.
CMMC FAQs (v5)
The DoD's official plain-language answers on scoping, affirmations, POA&Ms, ESPs, and MSPs.
Why it matters: Fastest way to resolve internal debates with an authoritative citation.
Assessment & Certification Resources
Guides that define how assessments are conducted, scored, and affirmed.
CMMC Assessment Guide — Level 2v2.13
The primary assessment document. Contains all 110 NIST SP 800-171 objectives and assessment methods (Examine, Interview, Test).
Why it matters: This is the single most important document for C3PAO preparation.
Tip: Print or bookmark. Every gap-analysis meeting should map back to a specific objective in this guide.
CMMC Assessment Guide — Level 1v2.13
Covers the 17 FAR 52.204-21 safeguards and self-assessment methodology for FCI-only environments.
Why it matters: Use when the contract only requires basic safeguarding of FCI.
32 CFR Part 170 — CMMC Program Final Rule
The federal regulation that codifies the CMMC program, including enforcement, affirmation, and POA&M rules.
Why it matters: Cited by every serious CMMC assessor and legal team.
CMMC FAQs (v5)
The DoD's official plain-language answers on scoping, affirmations, POA&Ms, ESPs, and MSPs.
Why it matters: Fastest way to resolve internal debates with an authoritative citation.
Scoping, Boundaries & Asset Categorization
Get scoping right before writing a single control response — it drives everything downstream.
CMMC Scoping Guide — Level 2v2.13
Defines asset categories (CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, Out-of-Scope Assets).
Why it matters: Wrong scoping is the #1 reason for C3PAO delays and findings.
Tip: Walk your network diagram against this guide before drafting your SSP boundary.
Practical scoping checklist
- Identify every system that receives, processes, stores, or transmits CUI.
- Categorize each asset per the Scoping Guide (CUI, SPA, CRMA, Specialized, Out-of-Scope).
- Document logical and physical boundaries with a network diagram.
- Confirm ESP/MSP inheritance and shared responsibility statements.
Free Supplementary Resources & Tools
High-value, no-cost resources vetted for defense contractors.
Project Spectrum
Free DoD-supported cybersecurity readiness training, tools, and self-assessments for the DIB.
Why it matters: Excellent no-cost starting point for small contractors.
DoD Mandatory CUI Training (usalearning.gov)
The DoD's baseline CUI awareness course used across defense contracts.
Why it matters: Meets the baseline CUI awareness expectation for personnel handling CUI.
NIST Foundational References
The source material behind CMMC Levels 2 and 3.
NIST SP 800-171 Rev. 2
The 110 security requirements underlying CMMC Level 2.
Why it matters: Every Level 2 objective traces back here.
NIST SP 800-171A (Assessment Procedures)
Assessment procedures and objectives NIST publishes to evaluate 800-171 requirements.
Why it matters: Reinforces the Examine / Interview / Test methodology used in CMMC L2 assessments.
NIST SP 800-172 (Enhanced Requirements)
Enhanced security requirements — foundation for CMMC Level 3.
Why it matters: Reference for contractors on the path toward Level 3.
Cyber AB & Certification Ecosystem
The bodies that accredit assessors, training partners, and practitioners.
How to Use These Documents Effectively
A practical order-of-operations we recommend to contractors preparing for a C3PAO assessment.
- 1Start with the Model Overview
Give leadership a 30-minute briefing so scoping decisions have air cover.
- 2Run the Scoping Guide against your network diagram
Categorize every asset before touching the SSP.
- 3Map objectives from the Level 2 Assessment Guide
For each of the 320 objectives, capture your Examine / Interview / Test evidence path.
- 4Read 32 CFR Part 170
Understand affirmations, POA&M rules, and enforcement — legal + compliance together.
- 5Verify assessors and training in the Cyber AB Marketplace
Never contract an unlisted C3PAO or trainer.
- 6Layer in role-based CUI learning
Use ParablAI's role-based modules to close the human-factor gap the guides can't teach.
Ready to go deeper?
Pair these official documents with ParablAI's role-based CUI learning so your team lives the standard — not just reads it.
Last updated: July 2026. All linked documents are published by the U.S. Department of Defense, NIST, or The Cyber AB.
Disclaimer: Always verify you have the latest version directly from the official source before using any document for a contract or assessment.