Cybersecurity Maturity Model Certification (CMMC) Program Reporting and Recordkeeping Requirements Information Collection
New collection (Request for a new OMB Control Number)
No
Regular
Approved with change
10/18/2024
06/25/2024
This collection is approved based on the revised materials provided by the Department.
table that charts list comparision
Inventory as of this Action
Requested
Previously Approved
10/31/2027
36 Months From Approved
11,155
0
0
5,771,829
0
0
1,125,585,314
0
0
This information collection supports the implementation of the CMMC program as defined in DODâs final rule published on October 15, 2024 (89 FR 83092). Specifically, this collection describes recordkeeping requirements such as records developed in the process of accrediting Third-Party Assessment Organizations (C3PAOs) and CMMC Accreditation Body plans. These requirements support the implementation of the CMMC assessment process for Levels 2 and 3 certification assessments.
US Code:
5 USC 301
Name of Law: Departmental regulations
PL:
Pub.L. 116 - 92 1648
Name of Law: National Defense Authorization Act for Fiscal Year 2020
On behalf of this Federal agency, I certify that the collection of information encompassed by this request complies with 5 CFR 1320.9 and the related provisions of 5 CFR 1320.8(b)(3).
The following is a summary of the topics, regarding the proposed collection of information, that the certification covers:
(i) Why the information is being collected;
(ii) Use of information;
(iii) Burden estimate;
(iv) Nature of response (voluntary, required for a benefit, or mandatory);
(v) Nature and extent of confidentiality; and
(vi) Need to display currently valid OMB control number;
If you are unable to certify compliance with any of these provisions, identify the item by leaving the box unchecked and explain the reason in the Supporting Statement.