Breaking it Down: Why CRMAs Must Implement NIST SP 800-171 Requirements
Clarifying CRMA Obligations and Assessment Expectations This position article addresses common misunderstandings surrounding Contractor Risk Managed Assets (CRMAs). Effectively managing CRMAs is crucial for organizations striving to comply with NIST SP 800-171 Level 2 requirements under the Cybersecurity Maturity Model Certification (CMMC). While CRMAs are not intended to process, store, or transmit Controlled Unclassified Information…