Under the Cybersecurity Maturity Model Certification (“CMMC”) Program Rule (i.e., 32 CFR 170), companies that must meet CMMC Level 2 requirements should be pushing toward meeting all 110 requirements defined in the NIST SP 800-171 Rev. 2. However, the United States Department of Defense (“DoD“) also recognizes that sometimes defense contractors may not meet all of the requirements during a CMMC assessment. That is why DoD included in the CMMC Program Rule (specifically 32 CFR 170.17) the idea of a “conditional” certification. To earn a conditional certification, defense contractors must still ensure that:

     

      • all requirements, except those specifically called out under 32 CFR 170.21, are met; and,

      • their total score, as calculated using the scoring methodology defined in 32 CFR 170.24, is at least an 88.

    The list of requirements in 32 CFR 170.21 can be a little difficult to decipher. So, the CUI Institute has published this table of the POA&M’able requirements (i.e., those which can be “not met” during an assessment but still allow a contractor to earn a Conditional Certification). We hope this information is helpful!

    Sort OrderFamilyRequirementCMMC IDScore ValuePOA&Mable?Security Requirement