CMMC Level 2 Readiness: NIST SP 800-171 for Defense Contractors

Description

Duration: 3 days

CMMC Level 2 is becoming a contract requirement across the defense supply chain, and the people who can implement it are in demand. This three-day course works through all 110 requirements in NIST SP 800-171 Revision 2, how an assessment is scoped and scored, and how to write the System Security Plan and Plan of Action and Milestones an assessor will ask for.

Please note: This is a readiness course. It is not a CMMC assessment and it does not certify your company. The Certified CMMC Professional (CCP) and Certified CMMC Assessor (CCA) credentials are delivered by CMMC Licensed Training Providers. We do not teach them.

Target Audience

  • IT and security staff who will implement and evidence the controls
  • Compliance, contracts and program managers at defense contractors and subcontractors
  • Managed service providers supporting companies that handle CUI

Prerequisites

  • Working knowledge of IT systems and networks
  • Security+ level knowledge is helpful but not required

What’s included?

  • Course workbook and NIST SP 800-171 Revision 2 reference material
  • Instruction from an experienced cyber security subject matter expert
  • Hands-on gap assessment exercises using a sample company
  • Optional: Package for Hotel Accommodations, Lunch and Transportation

With several convenient training delivery methods offered, The Code Academy makes getting the training you need easy. Whether you prefer to learn in a classroom or an online live learning virtual environment, training videos hosted online, and private group classes hosted at your site. We offer expert instruction to individuals, government agencies, non-profits, and corporations. Our live classes, on-sites, and online training videos all feature certified instructors who teach a detailed curriculum and share their expertise and insights with trainees. No matter how you prefer to receive the training, you can count on The Code Academy for an engaging and effective learning experience.

Methods

  • Instructor Led (the best training format we offer)
  • Live Online Classroom – Online Instructor Led
  • Self-Paced Video

Speak to an Admissions Representative for complete details

StartFinishPublic PricePublic Enroll Private PricePrivate Enroll
10/19/202610/21/2026
11/9/202611/11/2026
11/30/202612/2/2026
12/21/202612/23/2026
1/11/20271/13/2027
2/1/20272/3/2027
2/22/20272/24/2027
3/15/20273/17/2027
4/5/20274/7/2027
4/26/20274/28/2027
5/17/20275/19/2027
6/7/20276/9/2027
6/28/20276/30/2027
7/19/20277/21/2027
8/9/20278/11/2027
8/30/20279/1/2027
9/20/20279/22/2027
Learning Objectives
  • Explain the CMMC levels, the four rollout phases and what Phase 2 changes
  • Tell Federal Contract Information (FCI) apart from Controlled Unclassified Information (CUI) and trace where CUI lives in your company
  • Scope an assessment using the five CMMC asset categories
  • Interpret all 110 requirements across the 14 families
  • Score a self-assessment the way the CMMC rule does and post it in SPRS
  • Write a System Security Plan and a Plan of Action and Milestones that meet the rules
  • Prepare people, evidence and systems for a third-party assessment
Course Outline
Module 1: The CMMC Program

Levels 1 to 3, the four phases, the DFARS acquisition rule (48 CFR, DFARS case 2019-D041) and why NIST SP 800-171 Revision 2 is the standard. NIST has since published Revision 3, but the CMMC rule incorporates Revision 2 by reference, so Revision 2 is what a Level 2 assessment uses.

Module 2: FCI, CUI and Scoping

Where FCI and CUI enter and move through your company, and scoping with the five asset categories: CUI Assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets, Out-of-Scope Assets.

Module 3: Requirements, Part 1

Access Control, Awareness and Training, Audit and Accountability, Configuration Management and Identification and Authentication, with examples of acceptable evidence for each.

Module 4: Requirements, Part 2

Incident Response, Maintenance, Media Protection, Personnel Security, Physical Protection, Risk Assessment and Security Assessment.

Module 5: Requirements, Part 3

System and Communications Protection and System and Information Integrity, including encryption of CUI and monitoring.

Module 6: Scoring, SPRS and the POA&M

How a self-assessment is scored out of 110, with 5, 3 or 1 point deducted for each requirement not met; when a Plan of Action and Milestones is allowed only if the score is at least 80% of the maximum, only for lower-value requirements, and it must be closed within 180 days; and the reassessment every three years and an affirmation every year.

Module 7: Hands-on Gap Assessment

Work through a sample company against the requirements, record findings and turn them into a System Security Plan and a prioritised remediation plan.

Module 8: Preparing for the Assessment

Evidence collection, interviewing staff, working with an assessment organisation (C3PAO) and keeping the status current after certification.

The 14 requirement families covered
  • Access Control
  • Awareness and Training
  • Audit and Accountability
  • Configuration Management
  • Identification and Authentication
  • Incident Response
  • Maintenance
  • Media Protection
  • Personnel Security
  • Physical Protection
  • Risk Assessment
  • Security Assessment
  • System and Communications Protection
  • System and Information Integrity

Source: 32 CFR 170.14 and NIST SP 800-171 Rev. 2.