# DFARS and CMMC Compliance

DFARS and CMMC compliance is required in order for a company to receive a contract with the Department of Defense (DoD). Any organization that processes, stores, or transmits Controlled Unclassified Information (CUI) must undergo compliance testing to validate their cybersecurity practices.
[Download the CyberStrong Solution Sheet](/content/cs/c/?cta_guid=282be641-370c-4627-96f6-7158e6ac5831&signature=AAH58kH7UzgUsyHayVRM6KdYbBKTpmZosA&portal_id=3936746&pageId=66960712559&placement_guid=36ae9fcf-735e-4966-a8bb-8f511af2593b&click=8921a25a-e5d2-451e-8c47-95b9dc5d262c&redirect_url=APefjpHAE8Q01nLumquhsTxpCUsXRFEA27IYoC93sO9laBDW7nM3z-ntS9hRpXbpfMU4CL1dWq16zHoF9SD8yTwmiOK7Wl1PrSP8Sgjc3uvE6KMabio7UIdbTZ_vsVm7TTm7ZDUaPx-AhNHk7lbQGuBDMGi3yV8qTT_oSplon6HSjAAb51tJLrA&hsutk=&canon=https%3A%2F%2Fwww.cybersaint.io%2Fcybersecurity%2Fframeworks-and-standards%2Fdfars-and-cmmc%2Fcompliance&ts=1781486240614 "Download the CyberStrong Solution Sheet"/index.html)

A third-party security assessment must be performed to make sure that a vendor meets all the requirements of DFARS and CMMC compliance regulations before eligibility for defense contracts is given.

Certified third-party assessment organizations (C3PAOs) have to be verified by the CMMC Accreditation Body before assessment..

**DFARS and CMMC Compliance Requirements**

The Federal Register lays out the DFARS and [CMMC compliance](/content/glossary/who-needs-to-comply-with-cmmc/index.html)requirements as follows:

- In order to achieve a specific CMMC level, a DIB company must demonstrate both process institutionalization or maturity and the implementation of practices commensurate with the level.
- CMMC assessments will be conducted by accredited CMMC Third Party Assessment Organizations (C3PAOs) and upon completion, a company is awarded a certification by an independent CMMC Accreditation Body (AB) at the appropriate CMMC level.
- The certification level is documented in SPRS to enable the verification of an offeror’s certification level and currency (i.e., not more than three years old) prior to contract award.

## Download the Automated Control Scoring Brief

[GET THE BRIEF](https://cta-service-cms2.hubspot.com/web-interactives/public/v1/track/click?encryptedPayload=AVxigLKHichXSGouyS34m03PhqougXawaK6E6IZ78vvZUUA54sluJSNS%2FRE%2FrhMp5VBeDRGaX2%2BK8Yn32e359ReEhWy9sO3y%2F44JqjaxwnVO3PPHfm5b2IeoY64Y8osG3C5Y0gsURARc5JB6PYDUYfVu7xYysDcTauVCJMCzlk%2FLNf89jMaWRzta8sMCwICHlixsLNvTW9SF2mQJ%2FSlXZUR%2FRjJ%2Fn3e9%2Ft9Oc4wM40KjPvvU3mdwxsM%3D&portalId=3936746)

#### Learn more about CyberStrong

## Download the Solution Sheet

[Download the CyberStrong Solution Sheet](/content/cs/c/?cta_guid=282be641-370c-4627-96f6-7158e6ac5831&signature=AAH58kH7UzgUsyHayVRM6KdYbBKTpmZosA&portal_id=3936746&pageId=66960712559&placement_guid=36ae9fcf-735e-4966-a8bb-8f511af2593b&click=8921a25a-e5d2-451e-8c47-95b9dc5d262c&redirect_url=APefjpHAE8Q01nLumquhsTxpCUsXRFEA27IYoC93sO9laBDW7nM3z-ntS9hRpXbpfMU4CL1dWq16zHoF9SD8yTwmiOK7Wl1PrSP8Sgjc3uvE6KMabio7UIdbTZ_vsVm7TTm7ZDUaPx-AhNHk7lbQGuBDMGi3yV8qTT_oSplon6HSjAAb51tJLrA&hsutk=&canon=https%3A%2F%2Fwww.cybersaint.io%2Fcybersecurity%2Fframeworks-and-standards%2Fdfars-and-cmmc%2Fcompliance&ts=1781486240614 "Download the CyberStrong Solution Sheet"/index.html)
