← Custodia
32 CFR 170.18

CMMC Level 3 Certification Assessment Requirements

In plain English

32 CFR 170.18 establishes the requirements for CMMC Level 3 certification, which is reserved for DoD programs involving CUI of the highest priority. It requires implementation of all 110 NIST SP 800-171 controls plus 24 enhanced controls drawn from NIST SP 800-172, with the certification assessment performed by the DoD's Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).

Who must comply

Contractors on the specific DoD programs designated as requiring Level 3.

What it requires

  1. 01Hold a current Level 2 certification as a prerequisite.
  2. 02Implement 24 enhanced controls selected from NIST SP 800-172 in addition to all 110 NIST SP 800-171 controls.
  3. 03Undergo a Level 3 assessment performed by DIBCAC, not a C3PAO.
  4. 04Renew the certification every three years and submit annual affirmations between cycles.
Primary source
Read 32 CFR 170.18 at its source

Related clauses

Related terms

Stop reading. Start filing.

Find your SPRS score in 4 minutes. Then file it in 7 days.

Take the free SPRS quiz to see exactly where you stand on the 15 FAR 52.204-21 safeguarding requirements — no signup, no card. If you like what you see, the 7-day Custodia trial picks up where the quiz leaves off and walks you to a signed, bid-ready package.

7-day free trial · No credit card required · $249/mo Self Service ($2,496/yr on annual — two months free)