DIBStack
All resources

CMMC, DFARS, and NIST: The Authoritative Sources (and Where to Find Them)

A pointer map to the authoritative CMMC, FAR/DFARS, NIST, and CUI sources — read the requirements at the source, not from a summary.

Read it at the source

There is a lot of secondhand commentary about CMMC. The best way to avoid being misled is to read the requirements at the authoritative source. This page is a pointer map — it tells you where each source lives and what it covers. It does not interpret the regulations, summarize them as advice, or tell you how they apply to your organization. For that, use qualified internal personnel, legal counsel, or an authorized advisor.

One currency note: the current CMMC Level 2 baseline is NIST SP 800-171 Rev. 2. Revision 3 exists and is worth watching for future planning, but do not treat it as the assessment baseline unless and until the program rule changes. Regulations move — always verify against the source.

CMMC

FAR and DFARS cyber clauses

NIST

CUI

From sources to evidence

Reading the requirements is step one; organizing the evidence that shows what you do is the ongoing work. If you want a standardized, self-service way to organize that evidence, see the DIBStack Evidence Binder or start free with the DIB evidence folder structure. DIBStack provides the organizing tools; it does not interpret these sources or determine your compliance.

Related product

DIBStack Evidence Binder

Folder structures, evidence checklists, workbooks, logs, and templates for organizing cybersecurity evidence.

View DIBStack Evidence Binder