Attachment 4 - NIST_SP_800-171 Assessment.pdf

PDF 191 KB Posted

Attached to
Program Management Academy & Application Course Federal contract opportunity
Solicitation number
FA860121R0058
Issued by
Department of the Air Force Materiel Command Lifecycle Management Center Wright Patterson Air Force Base

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

From: saf.aqcp.aqcp@us.af.mil To: RUPPERT, JOHN D JR GS-12 USAF AFMC AFLCMC/PZIBC Subject: What"s New in Air Force Contracting: Additional Solicitation and Contract Cybersecurity Requirements --

UPDATED

Date: Thursday, December 3, 2020 7:03:46 AM

UPDATE: This announcement was originally published on 23 Nov 20. This version is updated to include additional supplemental information provided by the DPC memo at reference #3.

Topic: Additional Solicitation and Contract Cybersecurity Requirements References:

1. DFARS Case 2019–D041 — Interim Rule - Effective November 30, 2020

2. DFARS Text

3. OUSD(A&S)/DPC Memo, 25 Nov 20

Summary:

DoD has provided its interim rule published in the Federal Register on September 29, 2020. The interim rule amends the DFARS to implement (1) new requirements for a “NIST SP 800-171 DoD Assessment Methodology” and (2) the Cybersecurity Maturity Model Certification (CMMC) program.

This interim rule requires contracting officers to take specific actions prior to awarding contracts, task or delivery orders, or exercising an option period or extending the period of performance, on and after November 30, 2020.

For more detailed information acquisition professionals are encouraged to review the actual DFARS language, clauses, and provisions referenced above.

Impact:

NIST SP 800-171

The new DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, and new DFARS clause 252.204-7020, NIST SP 800- 171 DoD Assessment Requirements, add additional cybersecurity measures to those already required under DFARS 252.204-7012 by establishing enforcement methodologies for ensuring contractors have implemented the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 DoD Assessment Methodology.

Contracting Officers are directed to include DFARS 252.204-7019 and 252.204- 7020 in all solicitations and contracts including solicitations using FAR part 12 procedures for the acquisition of commercial items, except for solicitations solely for the acquisition of COTS items.

DFARS provision 252.204-7019, Notice of NIST SP 800-171 DoD Assessment Requirements, advises offerors required to implement the NIST SP 800-171 to have a current (not older than three years) NIST SP 800-171 DoD Assessment on record in order to be considered for award. The provision requires offerors to ensure the results of any applicable current Assessments are posted in Supplier Performance Risk System (SPRS) and provides offerors with mailto:saf.aqcp.aqcp@us.af.mil mailto:john.ruppert@us.af.mil https://www.govinfo.gov/content/pkg/FR-2020-09-29/pdf/2020-21123.pdf https://www.acq.osd.mil/dpap/dars/dfars/changenotice/2020/20200929/2019-D041 (i) DFARS Text LILO.docx https://www.acq.osd.mil/dpap/policy/policyvault/USA002524-20-DPC.pdf additional information on conducting and submitting an Assessment when a current one is not posted in SPRS.

Contracting Officers are further directed to verify, prior to contract award, in SPRS at https://www.sprs.csd.disa.mil/ that an offeror has at least a current “BASIC” NIST SP 800-171 DoD Assessment, if the offeror is required to implement NIST SP 800-171 pursuant to DFARS clause 252.204-7012. A “BASIC” Assessment is a self-assessment completed by the contractor per instruction provided in DFARS provision 252.204-7019, Notice of NIST SP 800- 171 DoD Assessment Requirements.

The new DFARS clause 252.204-7020, NIST SP 800-171 DoD Assessment Requirements, requires a contractor to provide the Government with access to its facilities, systems, and personnel when it is necessary for DoD to conduct or renew a higher-level (“MEDIUM “or “HIGH”) assessment. The clause also requires the contractor to ensure that applicable subcontractors have the results of a current Assessment posted in SPRS prior to awarding a subcontract or other contractual instruments. The clause also provides additional information on how a subcontractor can conduct and submit an Assessment when one is not posted in SPRS. Flow-down of this clause to applicable subcontracts is also mandated.

CMMC

DoD is implementing a phased rollout of CMMC. The clause at DFARS 252.204-7021, Cybersecurity Maturity Model Certification Requirements, is prescribed for use in solicitations and contracts, including solicitations and contracts using FAR part 12 procedures (excluding acquisitions exclusively for COTS items). Prior to September 30, 2025, the clause is required only if inclusion of a CMMC requirement in a solicitation is approved by the Office of the Under Secretary of Defense for Acquisition and Sustainment and the requirement document or statement of work requires a contractor to have a specific CMMC level.

Additional information on CMMC will be released as the process continues to mature.

POC: SAF/AQCP | (571) 256-2377 | DSN 260-2377

Contracting Knowledge Center Manage Your Subscription https://www.sprs.csd.disa.mil/ mailto:james.watson.56@us.af.mil?subject=Additional Solicitation and Contract Cybersecurity Requirements ( What's New, 2 Dec 20 ) https://cs2.eis.af.mil/sites/10059/afcc/knowledge_center/Pages/default.aspx https://www.afcontracting.hq.af.mil/whatsnew/wn-membership.cfm?email=john.ruppert@us.af.mil

File details come from the government source that posted it. Updated .