[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-162758-105":53,"doc-detail-162758-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","microsoft-technical-reference-guide-for-cmmc-l2-preview-sept-2024","Microsoft Technical Reference Guide for CMMC L2 - Preview Sept 2024","","The guide explains how the Cybersecurity Maturity Model Certification (CMMC) supports implementation of cybersecurity across the U.S. Defense Industrial Base, including the need to protect sensitive unclassified information across multi-tier supply chains. It introduces Microsoft’s approach for pursuing CMMC compliance using Microsoft cloud services, focusing on CMMC Level 2 and mapping all 110 controls from NIST SP 800-171. It also defines the intended audience and clarifies that compliance assessments and guidance are governed by CYBER AB.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/microsoft-technical-reference-guide-for-cmmc-l2-preview-sept-2024/162758/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/microsoft-technical-reference-guide-for-cmmc-l2-preview-sept-2024/162758.png","ImageObject",442,249,{"name":88,"@type":89},"Chloe Bennett","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-20","2026-08-30",true,{"@type":98,"interactionType":99,"userInteractionCount":47},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What is CMMC and what problem does it address for the Defense Industrial Base?","Question",{"text":108,"@type":109},"CMMC is a unifying certification standard for implementing cybersecurity across the U.S. Defense Industrial Base. It verifies that DIB organizations protect sensitive unclassified information with controls aligned to maturity levels and considers information flow down to subcontractors.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"Which CMMC level and control set does the Microsoft Technical Reference Guide focus on?",{"text":113,"@type":109},"The guide focuses on CMMC Level 2 (L2). CMMC L2 includes all 110 controls from NIST SP 800-171.",{"name":115,"@type":106,"acceptedAnswer":116},"Do Microsoft products and this guide cover all security controls required for CMMC?",{"text":117,"@type":109},"No. The guide provides a resource to pursue CMMC compliance using Microsoft products and services, and it explicitly does not address security controls occurring outside of Microsoft products and services.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},162758,1788129998,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":76,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":135,"language":136,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":61,"update_tm":125,"read_time":140},962084925782,"https://ap-avatar.wpscdn.com/davatar_9964176cb1d06d4a9deccf72a44ae3dc","\u0003Microsoft Technical Reference Guide for CMMC\u0004\nAccelerate your journey to cmmc with the Microsoft cloud\nJune 2024\n\u0003\n\u000f\u0004\n\u0013 TOC \\o \"1-3\" \\h \\z \\u \u0014\u0013 HYPERLINK \\l \"_Toc118452961\" \u0014Introduction\t\u0013 PAGEREF _Toc118452961 \\h \u00143\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452962\" \u0014Notices\t\u0013 PAGEREF _Toc118452962 \\h \u00144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452963\" \u0014Microsoft CMMC Acceleration Program\t\u0013 PAGEREF _Toc118452963 \\h \u00145\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452964\" \u0014Cybersecurity Maturity Model Certification (CMMC)\t\u0013 PAGEREF _Toc118452964 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452965\" \u0014CMMC 2.0 Implementation Guidance\t\u0013 PAGEREF _Toc118452965 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452966\" \u0014Overview of Implementation\t\u0013 PAGEREF _Toc118452966 \\h \u00146\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452967\" \u0014CMMC 2.0 NIST Alignment\t\u0013 PAGEREF _Toc118452967 \\h \u00147\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452968\" \u0014CMMC 2.0 Assessment Model\t\u0013 PAGEREF _Toc118452968 \\h \u00148\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452969\" \u0014POA&M\t\u0013 PAGEREF _Toc118452969 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452970\" \u0014CMMC Risk Assessment\t\u0013 PAGEREF _Toc118452970 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452971\" \u0014Shared Responsibility in the Microsoft Cloud\t\u0013 PAGEREF _Toc118452971 \\h \u001410\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452972\" \u0014Customer Eligibility for Azure Commercial and Azure Government\t\u0013 PAGEREF _Toc118452972 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452973\" \u0014Microsoft Services Implementation Guidance\t\u0013 PAGEREF _Toc118452973 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452974\" \u0014Microsoft Primary and Secondary Services Definition\t\u0013 PAGEREF _Toc118452974 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452975\" \u0014Azure Policy\t\u0013 PAGEREF _Toc118452975 \\h \u001412\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452976\" \u0014Microsoft Service Implementation Guidance\t\u0013 PAGEREF _Toc118452976 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452977\" \u0014Access Control (AC)\t\u0013 PAGEREF _Toc118452977 \\h \u001414\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452978\" \u0014Audit and Accountability (AU)\t\u0013 PAGEREF _Toc118452978 \\h \u001467\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452979\" \u0014Awareness and Training (AT)\t\u0013 PAGEREF _Toc118452979 \\h \u001487\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452980\" \u0014Configuration Management (CM)\t\u0013 PAGEREF _Toc118452980 \\h \u001491\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452981\" \u0014Identification and Authentication (IA)\t\u0013 PAGEREF _Toc118452981 \\h \u0014118\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452982\" \u0014Incident Response (IR)\t\u0013 PAGEREF _Toc118452982 \\h \u0014136\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452983\" \u0014Maintenance (MA)\t\u0013 PAGEREF _Toc118452983 \\h \u0014144\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452984\" \u0014Media Protection (MP)\t\u0013 PAGEREF _Toc118452984 \\h \u0014157\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452985\" \u0014Personnel Security (PS)\t\u0013 PAGEREF _Toc118452985 \\h \u0014183\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452986\" \u0014Physical Protection (PE)\t\u0013 PAGEREF _Toc118452986 \\h \u0014188\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452987\" \u0014Risk Assessment (RA)\t\u0013 PAGEREF _Toc118452987 \\h \u0014192\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452988\" \u0014Security Assessment (CA)\t\u0013 PAGEREF _Toc118452988 \\h \u0014202\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452989\" \u0014Systems and Communications Protection (SC)\t\u0013 PAGEREF _Toc118452989 \\h \u0014213\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452990\" \u0014System and Information Integrity (SI)\t\u0013 PAGEREF _Toc118452990 \\h \u0014259\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452991\" \u0014CMMC Blogs\t\u0013 PAGEREF _Toc118452991 \\h \u0014280\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452992\" \u0014CMMC Resources\t\u0013 PAGEREF _Toc118452992 \\h \u0014280\u0015\u0015\n\u0013 HYPERLINK \\l \"_Toc118452993\" \u0014CMMC Tools\t\u0013 PAGEREF _Toc118452993 \\h \u0014280\u0015\u0015\n\u0015\n\u000f\nIntroduction\nThe Cybersecurity Maturity Model Certification (CMMC) is a unifying standard for the implementation of cybersecurity across the United States Defense Industrial Base (DIB). The DIB encompasses the commercial organizations that produce or provide products and services to the United States Department of Defense (DoD). CMMC includes a comprehensive and scalable certification element to verify the implementation of controls associated with the achievement of a cybersecurity maturity level. CMMC is designed to provide increased assurance to the DoD that a DIB company can adequately protect sensitive unclassified information, accounting for information flow down to subcontractors in a multi-tier supply chain.\nThe Microsoft Technical Reference Guide for CMMC inc","cbCaihSUahwNX5w6","https://ap.wps.com/l/cbCaihSUahwNX5w6","docx",998719,338,"English","# Introduction\n# Notices\n# Microsoft CMMC Acceleration Program\n# Cybersecurity Maturity Model Certification (CMMC)\n# CMMC 2.0 Implementation Guidance\n## Overview of Implementation\n## CMMC 2.0 NIST Alignment\n## CMMC 2.0 Assessment Model\n## POA&M\n## CMMC Risk Assessment\n## Shared Responsibility in the Microsoft Cloud\n# Microsoft Services Implementation Guidance\n## Microsoft Primary and Secondary Services Definition\n## Azure Policy\n# Security Control Implementation Guidance\n## Access Control (AC)\n## Audit and Accountability (AU)\n## Awareness and Training (AT)\n## Configuration Management (CM)\n## Identification and Authentication (IA)\n## Incident Response (IR)\n## Maintenance (MA)\n## Media Protection (MP)\n## Personnel Security (PS)\n## Physical Protection (PE)\n## Risk Assessment (RA)\n## Security Assessment (CA)\n## Systems and Communications Protection (SC)\n## System and Information Integrity (SI)\n# CMMC Blogs\n# CMMC Resources\n# CMMC Tools","[{\"question\":\"What is CMMC and what problem does it address for the Defense Industrial Base?\",\"answer\":\"CMMC is a unifying certification standard for implementing cybersecurity across the U.S. Defense Industrial Base. It verifies that DIB organizations protect sensitive unclassified information with controls aligned to maturity levels and considers information flow down to subcontractors.\"},{\"question\":\"Which CMMC level and control set does the Microsoft Technical Reference Guide focus on?\",\"answer\":\"The guide focuses on CMMC Level 2 (L2). CMMC L2 includes all 110 controls from NIST SP 800-171.\"},{\"question\":\"Do Microsoft products and this guide cover all security controls required for CMMC?\",\"answer\":\"No. The guide provides a resource to pursue CMMC compliance using Microsoft products and services, and it explicitly does not address security controls occurring outside of Microsoft products and services.\"}]","Microsoft Technical Reference Guide for CMMC L2 - Preview Sept 2024 | DOCX",118]