Assessment frameworks
Every federal cybersecurity obligation traces back to a framework — a certification, a control catalog, a process, or a clause. We work inside all of them daily. Here is what each one actually demands, who it binds, and the artifacts an assessment will ask for.
Framework 01 · FWK-001
The DoD's certification that contractor cybersecurity claims are true — enforced through contract awards, not audits after the fact.
Level 1 — 15 practices · Level 2 — 110 controls · Level 3 — +24 (DIBCAC) · Phase 2 paused Jul 2026
Documentation Official source ↗CMMC 2.0 turns NIST SP 800-171 from an honor system into a certification — a condition of award, live in solicitations since Phase 1 began November 10, 2025. Level 1 (FCI) self-assesses annually against 15 basic safeguards; Level 2 (CUI) requires all 110 controls of 800-171; Level 3 adds SP 800-172 enhancements, government-assessed. On July 13, 2026, DoD suspended Phase 2 — the third-party certification mandate due November 10, 2026 — pending a 60-day reform review. The audit is paused; the standard is not: DFARS 252.204-7012, SPRS scores, and Phase 1 self-assessments all remain in force.
What it requires
Assessment artifacts
Phased implementation — current status
Where NSC comes in
A solicitation names a CMMC level · The Phase 2 pause has leadership asking whether readiness spend should stop · An executive must affirm and wants to know what they're signing.
Framework 02 · FWK-002
The control standard behind every CUI obligation — what "protect it" actually means, requirement by requirement.
110 controls (Rev 2) · 14 families · ~320 objectives (171A) · 800-172 enhanced set
Documentation Official source ↗SP 800-171 defines how CUI must be protected in systems the government doesn't own — yours. Rev 2's 110 requirements are what CMMC Level 2 certifies and what DFARS 252.204-7012 has required since 2017. Rev 3 (2024) restructures the set with organization-defined parameters, but DoD assessment today still runs against Rev 2. SP 800-172 layers enhanced requirements on top for CUI associated with critical programs — the basis of CMMC Level 3.
What it requires
Assessment artifacts
Where NSC comes in
A prime asks for your 800-171 posture with evidence · Your SPRS score was posted from a template SSP · CUI just appeared in a new contract.
Framework 03 · FWK-003
The federal control catalog everything else draws from — the common vocabulary of federal security.
20 families · Baselines: Low / Mod / High · Rev 5 + 53A / 53B · Overlays & tailoring
Documentation Official source ↗SP 800-53 is the master catalog: a thousand-plus controls and enhancements across twenty families, from which FedRAMP baselines, agency overlays, and most federal security requirements are assembled. You never implement "all of 800-53" — you implement a baseline selected by impact level (FIPS 199), tailored to the system, and assessed against 800-53A procedures. Fluency here is what makes every other federal framework legible.
What it requires
Assessment artifacts
Where NSC comes in
An agency or FedRAMP baseline lands on your roadmap · Controls are implemented but nobody can say which baseline · Inheritance is assumed and never mapped.
Framework 04 · FWK-004
The gate between a commercial cloud product and federal customers — one certification, reused across agencies.
20x Classes A / B / C / D · KSIs & automated validation · 3PAO assessed · Rev5 sunset: Jun 2027
Documentation Official source ↗FedRAMP authorizes cloud services for federal use — one certification, reused across agencies via the public Marketplace. FedRAMP 20x is now the program itself: certification by class (A / B / C, with Class D piloting FY27) against Key Security Indicators and automated, machine-readable evidence instead of narrative packages. The Consolidated Rules for 2026 fix the requirements, the submission pipeline opens FY26 Q4 — and new Rev5 certifications end June 11, 2027, which puts every classic-path CSP on a transition clock. Continuous monitoring still starts the day certification is granted.
What it requires
Assessment artifacts
20x program timeline
Where NSC comes in
An agency asks if you're in the Marketplace · The class decision (A / B / C) is open and engineering wants an answer · Rev5 sunsets June 2027 and there's no transition plan.
Framework 05 · FWK-005
The federal operating system for security decisions — how systems get categorized, controlled, assessed, and authorized.
7 steps: Prepare → Monitor · SP 800-37 Rev 2 · ATO decisions · Common controls
Documentation Official source ↗The RMF is the process wrapper around everything else: Prepare, Categorize (FIPS 199), Select (800-53), Implement, Assess (800-53A), Authorize, Monitor. Its output is the ATO — a named official personally accepting a system's risk. Done well, it's a reusable engine of categorizations, common controls, and living packages; done poorly, it's an eighteen-month document chase that expires in place. The difference is architecture and preparation, not paperwork volume.
What it requires
Assessment artifacts
Where NSC comes in
An ATO is expiring and the package is stale · Every system change reopens authorization debate · Categorizations were guessed years ago.
Framework 06 · FWK-006
The executive lingua franca of cyber risk — six functions a board can govern by.
Govern (new in 2.0) · Identify · Protect · Detect · Respond · Recover · Profiles & tiers
Documentation Official source ↗CSF 2.0 organizes cybersecurity into six functions — Govern, Identify, Protect, Detect, Respond, Recover — with the 2024 revision elevating governance to a function of its own: risk appetite, roles, oversight, and supply-chain accountability now sit at the top of the framework, not the appendix. It certifies nothing. Its power is translation: current-versus-target profiles turn technical posture into a roadmap executives can fund and boards can oversee.
What it requires
Assessment artifacts
Where NSC comes in
The board asks "how do we compare?" and there's no common language · Security reporting is a vulnerability count · Strategy needs a frame investors recognize.
Framework 07 · FWK-007
The contract fine print that makes federal cybersecurity legally binding — obligation by clause, not by memo.
252.204-7012 · -7019 / -7020 · -7021 (CMMC) · FAR 52.204-21
Documentation Official source ↗The DFARS clauses are where cybersecurity stops being advice: -7012 requires 800-171 protection of covered defense information, 72-hour incident reporting, and FedRAMP-Moderate-equivalent clouds; -7019 and -7020 make your self-assessment score in SPRS current and give the government the right to check it; -7021 inserts CMMC itself as a condition of award. FAR 52.204-21 sits underneath with fifteen basic safeguards for FCI. Each clause flows down the supply chain verbatim — your customer's obligations become yours.
What it requires
Assessment artifacts
Where NSC comes in
A new award carries clauses nobody read · An incident starts the 72-hour clock · A sub's gap is about to become your non-compliance.
Framework 08 · FWK-008
The emerging reference for trustworthy AI — voluntary today, procurement language tomorrow.
Govern · Map · Measure · Manage · AI RMF 1.0 · GenAI Profile (600-1)
Documentation Official source ↗The NIST AI RMF organizes AI risk into four functions: Govern (policies, roles, inventories), Map (context, intended use, failure modes), Measure (testing, evaluation, monitoring), Manage (respond, prioritize, retire). The 2024 Generative AI Profile extends it to GenAI-specific risks — confabulation, data leakage, prompt injection, provenance. Nothing certifies against it yet, but federal buyers, regulators, and diligence teams already use its vocabulary — and systems designed to it have answers when the questionnaire arrives.
What it requires
Assessment artifacts
Where NSC comes in
AI shipped faster than governance · A customer questionnaire asks about the AI RMF by name · Diligence wants the model inventory that doesn't exist.