
The DoD Assessment Methodology is a great attempt to create a standardized approach to evaluating contractor cybersecurity programs. However, it suffers from a fundamental flaw. That flaw is best illustrated through an example.
Imagine that Mavis’ Machine Shop is a DoD contractor and only ever handles Federal Contact Information (“FCI”), never Controlled Unclassified Information (“CUI”). However, Mavis, the CEO of Mavis’ Machine Shop, receives a call from a contracting officer for one of Mavis’ DoD contracts, and the Contracting Officer informs Mavis that the contract is up for renewal in 2 weeks. As part of the renewal the Contracting Officer will be granting Mavis’ request for a price increase, and the Contracting Officer will also be incorporating the DFARS 252.204-7019 and -7020 clauses in the contract. The Contracting Officer informs Mavis that Mavis must perform a self-assessment using the DoD Assessment Methodology and submit a score to SPRS before the renewal can be processed. Failure to submit a score within the next 2 weeks will cause the contract to terminate and open for recompute.
Mavis has attended enough CMMC and DFARS webinars to know that since her company only handles FCI, the Contracting Officer’s assertion that a basic self assessment must be performed and a score submitted to SPRS is fundamentally wrong. The -7019 and -7020 clauses are only triggered if the -7012 clause applies, and it doesn’t apply since Mavis’ Machine Shop doesn’t handle CUI. However, Mavis is also a shrewd enough business person to know that if she contests the Contracting Officer’s assertion, she will likely ruin her chances for the renewal.
So, she conducts a basic self assessment. She was smart enough to put together a basic System Security Plan (“SSP”) a few weeks ago, so the timing is pretty good, and she starts reviewing the SSP using the DoD Assessment Methodology.
As she does so, she notices that she can mark controls as Not Applicable and receive credit for them in the scoring methodology. So, she marks all of the controls that are not required under FAR 52.204-21 as “not applicable”. Mavis then evaluates her company’s program against the remaining 17 controls, and gives her company a score of 97.
Some readers might argue that the DoD Assessment Methodology requires that all Not Applicable findings be approved by the DoD CIO, so Mavis’ approach is improper. However, the DoD CIO would, inherently, have to accept that the requirements are Not Applicable since they literally cannot apply to Mavis’ Machine Shop since they do not handle CUI.
While there is a rational basis for Mavis’ score, as a practical matter, her company’s cybersecurity program is far less mature than an organization that handled CUI and whose program was correctly scored at 97. This result makes the DoD Assessment Methodology less valuable as a means for identifying contractor risk.
The FAR and Above approach mitigates this shortcoming. By implementing a phased scoring approach that requires that certain controls be implemented before higher scores can be achieved, FAR and Above allows better visibility into, and more consistent evaluation of, contractor cybersecurity programs.
Our free Comprehensive NIST SP 800-171 Self-Assessment Tool includes scoring for both FAR and Above and the DoD Assessment Methodology. You can download a copy below:
- Reforming CMMC and Reducing Compliance Burden for the DIB
- False Claims Act in 2025 – Key take-aways
- CUI Institute Public Comments on FAR CUI Rule
- CMMC: A National Imperative
- Disseminating CUI to Someone Else (e.g., Mary)
- CUI Recipient Preparedness Questionnaire
- CUI and CMMC in a Nutshell
- Mavis’s Machine Shop Attributes (Employees, Roles, Teams)
- Mavis’ Machine Shop Written Information Security Policy
- Mavis’ Machine Shop Data Breach and Incident Response Policy and Plan
- Mavis’ Machine Shop Network Diagram
- Mavis’ Machine Shops Site 2 Data Flow Diagram
- Mavis’ Machine Shops Site 2 Map
- Mavis’ Machine Shop Site 1 Map
- Protecting the Government’s Information – Version 2023.03a
- 3.11.2 – Vulnerability Scans (Kevin Mann)
- CMMC: Budgets, Competition, and Protests…Oh My! (Eric Crusius and Josh Duvall) – Slides
- CMMC Workflow: Pre-Kickoff to Done (Thomas Graham and Robert Teague) – Slides
- 3.14.1 – Flaw Remediation (Thomas Graham) – Slides
- 3.1.11 – Terminate (Automatically) a User Session After a Defined Condition (Robert Teague) – Slides
- Evidence & Path to Compliance (Regan Edens) – Slides
- CMMC in Higher Education (Amy Starzynski Coddens, Jason Pufahl, Mike Corn) – Slides
- Techniques for Assessing a Remote Work Environment (Tara Lemieux) – Slides
- v2023.02a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- Standardizing the Assessment Experience (Ben Tchoubineh) – Slides
- Helping Business Leaders to care about Cybersecurity (Ace Swerling) – Slides
- Gap Assessment Workflow (Leia Shilobod) – Slides
- Shared Responsibility Matrices (Carley Salmon and Robert McVay) – Slides
- Scoping your Environment (Matt Titcombe) – Slides
- Pricing Gap Assessments (Toby Musser) – Slides
- 3.11.1 Risk Assessments (Robert McVay) – Slides
- 3.5.3 Multifactor Authentication (Fernando Machado) – Slides
- Practical Approaches to Testing CMMC Compliance (Kyle Lai) – Slides
- 3.1.3 Controlling CUI Flow (Matt Hoeper) – Slides
- 3.14.1 Flaw Remediation (Thomas Graham) – Slides
- Finding Prep Expertise and a C3PAO (Joy Beland) – Workbook
- Finding Prep Expertise and a C3PAO (Joy Beland) – Slides
- OLD – v2022.11a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- v.2021.10a – The CMMC Assessment Lifecycle
- OLD – v2022.08d – Comprehensive FAR and Above and NIST SP 800-171 Self-Assessment and DoD SPRS Scoring Tool
- OLD – FAR and Above Phased Approach to NIST SP 800-171 and CMMC Compliance
- Policy – Client Data Breach Incident Response Policy
- Plan – Client Data Breach Incident Response
- List – Processes Authorized to Act on Behalf of a User
- List – Employees and Authorized Users
- List – Authorized Visitors
- Worksheet – Client Data Breach Incident Response
- Record – Meeting Agenda
- Procedure – Employee Offboarding
- Policy – Nondiscrimination and Anti-Harassment
- Policy – Information Systems Audit
- Policy – Data Protection
- Open Letter to the President Regarding CMMC 2.0
- US DoD 2021-NOV-04 – Cybersecurity Maturity Model Certification 2.0 Updates and Way Forward
- DFARS Clause Applicability Decision Tree
- The CMMC Assessment Lifecycle – OLD
- Paper and Electronic Media (“Media”) Certificate of Destruction/Sanitization
- C3PAO ISO 17020 and 17021 Slides – Part 3
- C3PAO ISO 17020 and 17021 Slides – Part 2
- C3PAO ISO 17020 and 17021 Slides – Part 1
- DCMA C3PAO CMMC Assessment Lessons Learned
- CMMC-AB Statement of Work
- CUI Disclosure Decision Trees
