Sources & Official References
Quick answer: Prefer primary sources over blogs (including ours) for requirements that affect contracts. This page lists starting points we point people toward. Always confirm current versions.
Standards & baselines
- NIST SP 800-171 Rev 2 — Protecting CUI in nonfederal systems
- NIST SP 800-171 Rev 3 — Updated baseline (confirm applicability for your contracts)
- NIST — standards organization home
CMMC program
- DoD CMMC program — official program information
- DoD CIO — cyber policy context
SPRS & acquisition
- SPRS (DISA) — Supplier Performance Risk System
- DFARS — Defense Federal Acquisition Regulation Supplement
- Acquisition.gov — FAR / DFARS portal
CUI
How we use these
DefensibleScore articles translate these topics for small contractors. They are educational and may lag official updates. If a page and a primary source disagree, trust the primary source and your contract language.
See also: Disclaimer · Glossary ·How we help