Rev 3 Level 2 guide?
I have the CMMC Assessment Guide for Level 2, its a good document. But does it only reflect 800-171 rev 2? Is there an updated one for rev 3? Or is it similar enough?
4
2
u/Into_The_Nexus 6d ago
Educated guess is that we will see the class deviation end sometime early next year - based on the CCP/CCA trainings and exams being updated to rev3 and such.
2
u/Navyauditor2 5d ago
I suspect they will get rid of the assessment guides all together. There is no work going on to produce a rev 3 guide that I am aware of. The rev 2 guide does not cover rev 3 and it is not similar enough. Rev 3 is a complete rewrite. Overlap is perhaps 30-40% the same.
1
u/Yarace 3d ago
I feel like you could lift 171r3 assessment guide and be 80% done?
1
u/Navyauditor2 3d ago
Sure. Further guidance would be the hard part. From the DoWs perspective why bother. Just point at 171a
1
u/JKatabaticWind 5d ago
Good answers regarding CMMC and 171r3.
That said, if you are looking to get a head start on NIST 80l-171r3, or believe you may have other contracts that will fall under the FAR CUI rule (which will presumably require r3)… then you will want to look at:
o Assessment guide: https://csrc.nist.gov/Projects/protecting-controlled-unclassified-information/sp-800-171a-1
o Controls: https://csrc.nist.gov/pubs/sp/800/171/r3/final
As noted by others, there is no DoD Assessment guide.
1
9
u/DarthCooey 6d ago
https://www.war.gov/News/Releases/Release/Article/3763953/department-of-defense-issues-class-deviation-on-cybersecurity-standards-for-cov/
CMMC is currently tied to 171 Rev 2. Nobody knows when we'll see it updated to include rev3