Cybersecurity Compliance and Risk Assessment
Purpose: Introduces the concept of a common Cybersecurity Compliance and Risk Assessment (CCRA) for the Defense Industrial Base CCRA Announcement Letter
The CCRA concept allows suppliers to complete ONE assessment which would be accepted on a reciprocal basis by DoD Prime contractors, or other companies who recognize the CCRA. This will introduce efficiencies and cost savings in contrast to current practices. As suppliers have observed, while the regulatory requirements for cybersecurity continue to grow and evolve, companies have resorted to developing proprietary assessments or using outdated questionnaires to capture compliance and risk information. This approach has introduced a significant burden to suppliers that are required to provide unique responses to assessment tools containing varying numbers of security requirements and inconsistent language.
The transition to the CCRA will introduce a consistent approach for acquiring cybersecurity compliance and risk information, introduce a reduced set of required responses, and introduce the efficiency of answering once and sharing with many who recognize the reciprocal value of the CCRA.
What is driving the change?
What is the Cybersecurity Compliance and Risk Assessment?
When will the CCRA be available?
The assessment will be available for download below beginning December 14, 2023.
CCRA Deployment
Company Name | Website |
ND-ISAC – CCRA Working Group | https://ndisac.org/ |
Lockheed Martin | https://www.lockheedmartin.com |
Boeing Company | https://www.boeing.com/ |
Leidos, Inc. | https://www.leidos.com/ |
RTX | https://www.rtx.com/ |
Booz Allen Hamilton | https://www.boozallen.com/ |
Centurum, Inc. | https://www.centurum.com/ |
Frontgrade | https://frontgrade.com/ |
Win-Tech | https://win-tech.net/ |
Northrop Grumman | https://www.northropgrumman.com/ |
L3Harris | https://www.l3harris.com/ |
BAE Systems | https://www.baesystems.com/en/home |
Huntington Ingalls Industries | https://hii.com/ |
Accenture Federal Services | https://www.accenture.com/ |
Rolls Royce | https://www.rolls-royce.com/ |
What is the Cybersecurity Compliance and Risk Assessment (CCRA) and why do we need to complete this survey?
Where can I find the latest version of the CCRA?
Where should users be directed if they need technical support/general questions?
Feedback on the CCRA’s content can be submitted using the CCRA Feedback Form.
Can the Cybersecurity Compliance and Risk Assessment (CCRA) be used across different prime contractors?
Note: Each organization will begin piloting use of the CCRA following this general announcement. Please contact the requesting organization for additional information.
How will the CCRA be used and how is the information I put into the form secured?
It will also be implemented in web-based formats, like Exostar Onboarding Module (OBM) or OneTrust, where suppliers can select the organizations they want to share it with. Please contact the requesting organization for more information on how the response to the CCRA will be used.
I do not receive CUI/CDI. Why do I need to complete the CCRA to show that I’m compliant with NIST 800-171 controls?
Why were only a subset of security controls used in the CCRA? What was the reasoning behind the control selection?
Since the form is in an excel macro-enabled format (.xlsm), how can I be assured that it is safe to open?
You can calculate the checksum (hash) of the downloaded file using several options:
1. Navigate to the extracted file. Right-click on the file and select the “CRC SHA” option. Then select “SHA-256”. Then use the prompt with the checksum information to verify you have the same value as what’s provided on the CyberAssist site.
2. If the above doesn’t work, open a Windows Powershell prompt and use the command “Get-FileHash <filename>”, where <filename> is the sample. For more details, see: Get File Hash with PowerShell
How does the survey help represent my compliance with the Cyber DFARS requirements?
If DFARS 252.204-7020 is applicable, you will be asked for the status of your Supplier Performance Risk System (SPRS) submission. To be compliant with DFARS 7020, the supplier’s NIST Assessment results (performed within the prior 3-year period) must be posted to the DoD SPRS.
The CCRA will ask for the status of your compliance with these requirements with a few high-level questions. It should be noted, however, that completing the CCRA does not waive, or substitute for any DoD-required assessments, or imply approval to host or process controlled unclassified information (CUI).
How does the CCRA calculate and assess the risk rating?
The following rules are applied for calculating Cyber Risk:
- Negligible = All Category 1, 2, and 3 controls are implemented
- Moderate= All Category 1 implemented AND > 1 Category 2 or 3 implemented
- Significant = Less than 11 Category 1 implemented.
For Suppliers receiving only FCI and no other customer-sensitive or Controlled data types, the following rules are applied:
- FCI- only suppliers = Negligible if all 6 FCI security controls are implemented or else Significant.
** The subset of FCI security controls is highlighted Yellow on the “Questionnaire”
What does the risk ratings represent?
- Negligible = (All Category 1, 2, and 3 controls are implemented)
- Negligible to minimal risks are identified based on the response provided. The supplier has a strong performing cyber risk management program.
- Moderate = (All Category 1 implemented AND > 1 Category 2 or 3 implemented)
- Minimal to moderate risks are identified based on the response provided. The supplier has a Cyber risk management program with good protections in place, but additional risk mitigations are likely required to protect Sensitive Information and/or Government/DOD Controlled Unclassified Information (CUI).
- Significant = (Less than 11 Category 1 implemented)
- Moderate to significant risks are identified based on the response provided. The supplier has minimal or no cyber risk management program and significant cyber protections are lacking.
Can the offline version of the CCRA be uploaded into Exostar or other “buyer” organization’s supply chain risk management systems/platforms?
Note that the CCRA has a built-in capability to enable the export of the responses to a comma-separated value (.csv) file that may be used to upload across multiple platforms.
I don’t possess, manage, or generate Controlled Unclassified Information (CUI) and DFARS 252.204-7012 does not apply to me. Why do I have to complete the CCRA?
Will completing the CCRA satisfy the requirements to be compliant with DFARS 252.204-7012, DFARS 252.204-7020 and/or CMMC?
To be compliant with DFARS 7012, you must attest that all 110 NIST cybersecurity controls are implemented OR for controls not implemented, the supplier must have a documented Plan of Action and Milestone (POAM) in your System Security Plan (SSP).
To be compliant with DFARS 7020, the supplier’s NIST Assessment results (performed within the prior 3-year period) must be posted to the DoD SPRS.
How do I access and complete the CCRA?
If organizations are implementing the CCRA in different systems and applications, how can I share my responses to the CCRA across the DIB.
Submission of the CCRA will vary by requesting organization. Please contact your requesting organizations for details on how it should be submitted.
What is the Onboarding Module (OBM)?
When will suppliers be expected to move off of the current NIST SP 800-171 and Cybersecurity Questionnaire (CSQ) that is hosted in Exostar Partner Information Manager (PIM)?
Note: Each organization will begin piloting use of the CCRA following this general announcement. Please contact the requesting organization for additional information.
I recently completed the Cyber Security Questionnaire (CSQ) in Exostar. Do I now need to complete this new questionnaire?
Note: Each organization will begin piloting use of the CCRA following this general announcement. Please contact the requesting organization for additional information.