Defense Federal Acquisition Regulation Supplement (DFARS) and NIST 800-171 Audit support. We are ready when you are!
Freguenty Asked Questions
What is DFARS compliance?
DFARS compliance involves meeting the cybersecurity requirements outlined in DFARS clause 252.204-7012, which mandates implementing NIST SP 800-171 controls to protect CUI in non-federal systems. It includes maintaining a System Security Plan (SSP), Plans of Action and Milestones (POA&M), and incident reporting capabilities.
What are the DFARS compliance requirements?
DFARS compliance requirements include:
- Implementing NIST 800-171 controls (110 in Rev 2, 97 in Rev 3).
- Developing an SSP and POA&M.
- Conducting a Basic, Medium, or High NIST 800-171 DoD Assessment.
- Reporting cyber incidents within 72 hours.
- Ensuring subcontractors comply via flow-down clauses.
- Engage with Lazarus Alliance to conduct a DFARS assessment.
What is CMMC, and how does it relate to NIST 800-171?
CMMC (Cybersecurity Maturity Model Certification) is a DoD framework with three levels to verify contractor cybersecurity. CMMC Level 2 aligns with NIST 800-171’s 110 controls, requiring third-party assessments (C3PAO) for certification. It builds on DFARS 7012 requirements.
What is the CMMC to NIST 800-171 mapping?
CMMC Level 2 maps directly to NIST 800-171 Rev 2’s 110 controls, ensuring CUI protection. Level 1 aligns with FAR 52.204-21’s 15 basic controls for Federal Contract Information (FCI). Level 3 adds up to 35 NIST 800-172 controls. Mappings are available in NIST 800-171 Appendix D. Work with Continuum GRC to do this automatically for you.
How does NIST 800-171 differ from NIST 800-53?
NIST 800-171 focuses on protecting CUI in non-federal systems with 110 controls (Rev 2). NIST 800-53 is a broader framework for federal systems, with 421 controls across 20 families, used in FISMA and FedRAMP. NIST 800-171 is a subset of 800-53.
What is the NIST 800-171 self-assessment?
A NIST 800-171 self-assessment (Basic Assessment) involves scoring compliance with 110 controls using the DoD Assessment Methodology. Contractors submit a score (out of 110) to SPRS, with a POA&M for gaps. Scores below 110 require remediation plans.
Just the facts ...
Find out more by calling +1 (888) 896-7580 today.
Defense Federal Acquisition Regulation Supplement (DFARS) and NIST 800-171 Audit support framework. We are ready when you are!
Comprehensive Defense Federal Acquisition Regulation Supplement (DFARS) and NIST 800-171 Compliance Audit Services
The DoD has mandated compliance! You gain many strategic business advantages by offering market differentiation and leadership showing others credible evidence of good practice. In addition to risk avoidance, a Lazarus Alliance Defense Federal Acquisition Regulation Supplement (DFARS) and NIST 800-171 compliance audit will demonstrate due diligence in the event of legal action from breach of contract with the DoD.
Assessments
- Federal Information Processing Standards (FIPS) Publication 199: Standards for Security Categorization of Federal Information and Information Systems (moderate confidentiality impact)
- Federal Information Processing Standards (FIPS) Publication 200: Minimum Security Requirements for Federal Information and Information Systems
- NIST 800-37: Applying the Risk Management Framework to Federal Information Systems
- NIST 800-53: Assessing Security and Privacy Controls in Federal Information Systems and Organizations
- NIST 800-60: Guide for Mapping Types of Information and Information Systems to Security Categories
- NIST 800-171: Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations
Cybervisor™ Consultations
Working Smarter Not Harder
Leveraging the Continuum GRC IT Audit Machine, Security Trifecta methodology and the Policy Machine, Lazarus Alliance provides international standards that are recognized as “Best Practices” for developing organizational security standards and controls that support Defense Federal Acquisition Regulation Supplement (DFARS) and NIST 800-171 based compliance audit certifications and assessments.