ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your company will process Controlled Unclassified Information (CUI) for a low-priority Department of Defense contract that is subject to CMMC 2.0 Level 2. Given current DoD policy, which approach to meeting the requirement is appropriate?
Adopt ISO/IEC 27001 controls and obtain ISO certification; this is accepted as an alternative path to satisfy CMMC Level 2 requirements.
Implement all NIST SP 800-171 controls and complete an annual self-assessment because third-party certification is required only for prioritized Level 2 contracts.
Implement only the 15 basic FAR 52.204-21 safeguarding practices and file a self-assessment; Level 2 permits the same baseline as Level 1.
Implement all NIST SP 800-171 controls and obtain a triennial C3PAO certification because every Level 2 environment must undergo third-party assessment.
CMMC 2.0 Level 2 requires implementation of all 110 security practices in NIST SP 800-171. For contracts the DoD designates as non-prioritized, the contractor may satisfy the assessment requirement by performing an annual self-assessment scored against NIST SP 800-171 and uploading the results (with a senior executive affirmation) to the Supplier Performance Risk System (SPRS). A certified third-party assessment is required only for prioritized Level 2 programs. Level 1, by contrast, involves just the 15 basic safeguarding practices from FAR 52.204-21, and ISO/IEC 27001 certification is not an approved substitute for CMMC compliance. Therefore, the self-assessment path that still implements the full 110 controls is the correct choice for this scenario.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CMMC 2.0 and how does it differ from previous versions?
Open an interactive chat with Bash
What is NIST SP 800-171, and why is it important for CMMC compliance?
Open an interactive chat with Bash
What is the Supplier Performance Risk System (SPRS) used for in CMMC compliance?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Security and Privacy Governance, Risk Management, and Compliance Program
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .