Curated · Official Sources Only

CMMC Guidance from Official Sources

A curated hub of the DoD, NIST, and Cyber AB documents defense contractors, CCP candidates, and assessors actually use — organized for preparation, gap analysis, and C3PAO readiness.

Last updated: July 2026 · All documents referenced at version 2.13 where applicable

Section 01

Official DoD CMMC Core Documents

The authoritative documents from DoD CIO. These supersede any third-party summary.

CMMC Program Main Page (DoD CIO)

The official home of the DoD's Cybersecurity Maturity Model Certification program. Start here for authoritative announcements.

Why it matters: Anchor source for every C3PAO-referenced program document.

CMMC Documentation Hub

Official index of every DoD-published CMMC guide, model overview, and scoping document.

Why it matters: Bookmark this — versions update here first.

CMMC Model Overviewv2.13

Executive-level overview of the three CMMC levels, practices, and program structure.

Why it matters: Essential context for leadership briefings and CCP fundamentals.

CMMC Assessment Guide — Level 2v2.13

The primary assessment document. Contains all 110 NIST SP 800-171 objectives and assessment methods (Examine, Interview, Test).

Why it matters: This is the single most important document for C3PAO preparation.

Tip: Print or bookmark. Every gap-analysis meeting should map back to a specific objective in this guide.

CMMC Scoping Guide — Level 2v2.13

Defines asset categories (CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, Out-of-Scope Assets).

Why it matters: Wrong scoping is the #1 reason for C3PAO delays and findings.

Tip: Walk your network diagram against this guide before drafting your SSP boundary.

CMMC Assessment Guide — Level 1v2.13

Covers the 17 FAR 52.204-21 safeguards and self-assessment methodology for FCI-only environments.

Why it matters: Use when the contract only requires basic safeguarding of FCI.

32 CFR Part 170 — CMMC Program Final Rule

The federal regulation that codifies the CMMC program, including enforcement, affirmation, and POA&M rules.

Why it matters: Cited by every serious CMMC assessor and legal team.

CMMC FAQs (v5)

The DoD's official plain-language answers on scoping, affirmations, POA&Ms, ESPs, and MSPs.

Why it matters: Fastest way to resolve internal debates with an authoritative citation.

Section 02

Assessment & Certification Resources

Guides that define how assessments are conducted, scored, and affirmed.

Section 03

Scoping, Boundaries & Asset Categorization

Get scoping right before writing a single control response — it drives everything downstream.

CMMC Scoping Guide — Level 2v2.13

Defines asset categories (CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, Out-of-Scope Assets).

Why it matters: Wrong scoping is the #1 reason for C3PAO delays and findings.

Tip: Walk your network diagram against this guide before drafting your SSP boundary.

Practical scoping checklist

  • Identify every system that receives, processes, stores, or transmits CUI.
  • Categorize each asset per the Scoping Guide (CUI, SPA, CRMA, Specialized, Out-of-Scope).
  • Document logical and physical boundaries with a network diagram.
  • Confirm ESP/MSP inheritance and shared responsibility statements.
Section 04

Free Supplementary Resources & Tools

High-value, no-cost resources vetted for defense contractors.

Section 05

NIST Foundational References

The source material behind CMMC Levels 2 and 3.

Section 06

Cyber AB & Certification Ecosystem

The bodies that accredit assessors, training partners, and practitioners.

Section 07

How to Use These Documents Effectively

A practical order-of-operations we recommend to contractors preparing for a C3PAO assessment.

  1. 1
    Start with the Model Overview

    Give leadership a 30-minute briefing so scoping decisions have air cover.

  2. 2
    Run the Scoping Guide against your network diagram

    Categorize every asset before touching the SSP.

  3. 3
    Map objectives from the Level 2 Assessment Guide

    For each of the 320 objectives, capture your Examine / Interview / Test evidence path.

  4. 4
    Read 32 CFR Part 170

    Understand affirmations, POA&M rules, and enforcement — legal + compliance together.

  5. 5
    Verify assessors and training in the Cyber AB Marketplace

    Never contract an unlisted C3PAO or trainer.

  6. 6
    Layer in role-based CUI learning

    Use ParablAI's role-based modules to close the human-factor gap the guides can't teach.

Ready to go deeper?

Pair these official documents with ParablAI's role-based CUI learning so your team lives the standard — not just reads it.

Last updated: July 2026. All linked documents are published by the U.S. Department of Defense, NIST, or The Cyber AB.

Disclaimer: Always verify you have the latest version directly from the official source before using any document for a contract or assessment.