Event banner
Microsoft Government CMMC AMA
Event Ended
Tuesday, Apr 12, 2022, 10:30 AM PDTEvent details
We want to hear from our customers and answer their questions around how we can help them achieve CMMC compliance with your Microsoft Azure and Microsoft 365 subscriptions. We will be hosting an "Ask...
Sarah_Gilbert
Updated Apr 12, 2022
Smccartin
Apr 12, 2022Copper Contributor
A good place to start is reading the NIST SP 800-171 Doc, this is what CMMCv2 Level 2 (The CUI level) maps to, the version 1 of CMMC includes a couple extra controls though. There's a decent amount of overlap in the M365 compliance manager with this too. So it's a good idea to go through that compliance template before you buy the premium compliance template addon that Microsoft has for CMMCv1 L3 (the V1 CUI level).
https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final
Smccartin
Apr 12, 2022Copper Contributor
adding the assessment objects to my recommendation. It's great for writing up a document to hand off to auditors or for just doing a self-audit.
https://csrc.nist.gov/publications/detail/sp/800-171a/final