48 CFR · Federal Acquisition Regulations System

§ 252.204-7021 — Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.

48 CFR § 252.204-7021

This text of 48 C.F.R. § 252.204-7021 (Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements.) is published on Counsel Stack Legal Research, covering United States primary law. Counsel Stack provides free access to over 12 million legal documents including statutes, case law, regulations, and constitutions.

Bluebook
48 C.F.R. § 252.204-7021 (2026).

Text

252.204-7021 Contractor Compliance With the Cybersecurity Maturity Model Certification Level Requirements. As prescribed in 204.7504(a), use the following clause: CONTRACTOR COMPLIANCE WITH THE CYBERSECURITY MATURITY MODEL CERTIFICATION LEVEL REQUIREMENTS (NOV 2025)

(a)Definitions. As used in this clause- Controlled unclassified information means information the Government creates or possesses, or information an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Governmentwide policy requires or permits an agency to handle using safeguarding or dissemination controls (32 CFR 2002.4(h)). Current means—
(1)With regard to Conditional Cybersecurity Maturity Model Certification (CMMC) Status—
(i)Not older than 180 days for Conditional Level 2 (Se

Free access — add to your briefcase to read the full text and ask questions with AI

Related

§ 170.16
32 C.F.R. § 170.16
§ 170.4
32 C.F.R. § 170.4
§ 170.18
32 C.F.R. § 170.18
§ 170.15
32 C.F.R. § 170.15
§ 170.22
32 C.F.R. § 170.22
§ 170.21
32 C.F.R. § 170.21
§ 170.23
32 C.F.R. § 170.23

Nearby Sections

11

Cite This Page — Counsel Stack

Bluebook (online)
48 C.F.R. § 252.204-7021, Counsel Stack Legal Research, https://law.counselstack.com/cfr/48/252/252.204-7021.
View on eCFR ↗