Correct Answer: D
Which NIST SP Defines the Assessment Procedures for CMMC?CMMC Level 2 isdirectly based on NIST SP
800-171, and the assessment procedures used in CMMC assessments are derived fromNIST SP 800-171A.
Step-by-Step Breakdown:#1. NIST SP 800-171A Defines Assessment Procedures
* NIST SP 800-171Ais titled"Assessing Security Requirements for Controlled Unclassified Information (CUI)".
* It providesdetailed assessment objectives and test proceduresfor evaluating compliance withNIST SP
800-171 security requirements, whichCMMC Level 2 is fully aligned with.
* CMMC Assessors use 800-171Aas abaseline for assessing the effectiveness of security controls.
#2. Why the Other Answer Choices Are Incorrect:
* (A) NIST SP 800-53#
* 800-53 defines security controlsfor federal information systems, but it doesnot provide assessment procedures specific to CMMC.
* (B) NIST SP 800-53A#
* 800-53A provides assessment procedures for 800-53 controls, butCMMC is based on NIST SP
800-171, not 800-53.
* (C) NIST SP 800-171#
* 800-171 defines security requirements, butit does not provide assessment procedures.
Theassessment proceduresare in800-171A.
* TheCMMC Assessment Guide (Level 2)explicitly states that assessment procedures are derived fromNIST SP 800-171A.
Final Validation from CMMC Documentation:Thus, the correct answer is: