Skip to content
Obfuscation Hub
Intermediate Self-paced · 7 modules 1 of 7 modules open now

CMMC and NIST 800-171 Foundations

For organizations in the defense supply chain — or heading there. Understand CUI, the 800-171 requirement families, and the assessment landscape before contract clauses make it urgent.

CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense’s mechanism for verifying that contractors actually implement the NIST SP 800-171 protections they have long been contractually required to have. For thousands of small manufacturers, integrators, and service firms, it converts security from a self-attested checkbox into an assessed condition of doing business.

This path builds the conceptual foundation: the vocabulary, the requirement structure, the documents, and the assessment landscape. It will not, by itself, make an organization assessment-ready — real readiness is an implementation effort measured in quarters — but it will let you scope that effort realistically and avoid the two expensive mistakes newcomers make: treating all systems as in-scope, and deferring the SSP until “after implementation.”

A note on authority: CMMC requirements flow from your contracts and the official program — always confirm specifics against current Department of Defense and Cyber AB publications rather than any secondary source, including this one. Assessment for certification is performed by authorized C3PAOs (CMMC Third-Party Assessment Organizations), not by training platforms or advisors.

Most modules in this path arrive as guided lessons in the next release; Module 5 connects to material you can use today.

Module sequence

Modules marked “Open now” link to working material. The rest arrive as guided lessons in the next release.

  1. 01

    The defense supply-chain context

    Coming in the next release

    CUI, FCI, DFARS 252.204-7012 in plain language, and how CMMC levels map to contract requirements.

  2. 02

    Reading NIST SP 800-171

    Coming in the next release

    The requirement families, how they relate, and how to read requirements without drowning.

  3. 03

    Scoping CUI environments

    Coming in the next release

    Tracing where CUI enters, lives, and flows — and why enclave strategies exist.

  4. 04

    The SSP and POA&M

    Coming in the next release

    The two documents at the center of everything, and how to draft honest first versions.

  5. 05

    The access-control family through an operational lens — including the review cadence you can start today.

  6. 06

    Evidence and assessment preparation

    Coming in the next release

    What assessors examine, interview, and test — and building the artifact set as you implement.

  7. 07

    Self-assessment vs. C3PAO assessment

    Coming in the next release

    The assessment ecosystem, scoring, affirmations, and choosing the path your contracts require.

What you will produce

  • A CUI flow sketch for a representative environment
  • A starter SSP outline scoped to your boundary
  • A prioritized POA&M draft using the roadmap template
  • An evidence map for the access-control family