Defence-industrial supply

CMMC supplier verification: the claims a prime receives, checked against evidence.

CMMC supplier verification is the independent check of the claims a supplier makes about its cybersecurity posture (the CMMC level it states, the NIST SP 800-171 controls it says it operates, the flow-down it passes to subcontractors) against evidence, before a prime relies on them. Certisyn verifies each claim and seals the determination, so the prime, its auditor and the contracting officer read the same record.

The claims a prime relies on

ClaimEvidence examinedDetermination
A CMMC level is heldThe assessment record and the stated scopeHeld, in scope and in date, or the reason it could not be determined
NIST SP 800-171 controls are operatedPolicy, configuration snapshots, telemetry, logsDocumented, Operational or Adversarial-ready, per control
A reported score reflects the environmentThe scoring basis and the evidence behind itReconciled to the evidence, with differences listed
Flow-down reaches subcontractorsSubcontractor attestations and agreementsEstablished for the examined subcontractors, with the remainder named

A coverage statement with denominators

A supply chain verification states what it examined. The coverage statement declares the examined population with explicit denominators, enumerates every unexamined unit with a specific reason, and carries each determination under the policy version in force. A prime reading it knows how much of the supply base the result describes.

Fit with the existing ecosystem

Certification decisions sit with the Department of War's assessment ecosystem and its C3PAOs. Certisyn determinations serve the prime's own reliance decision: which supplier claims it can accept, which it must test further, and on which it holds evidence an auditor can replay.

What stays checkable

  • The policy version travels with every determination.
  • The derivation root is recomputable from the record.
  • The anchor fixes the time of issue.
  • The registry resolves each code publicly.

Frequently asked

What is CMMC supplier verification?

CMMC supplier verification is the independent check of the claims a supplier makes about its cybersecurity posture against evidence, before a prime relies on them.

Which claims can be verified?

The CMMC level a supplier states, the NIST SP 800-171 controls it says it operates, the score it reports, and the flow-down it passes to its own subcontractors.

How does it sit alongside a CMMC assessment?

Certification decisions sit with the Department of War's assessment ecosystem and its C3PAOs. Certisyn operates upstream and alongside: it verifies the claims a prime receives and seals the determination, so the prime, its auditor and the contracting officer read the same record.

What does a prime receive?

A sealed determination for each claim, a coverage statement naming what was examined and what was not, and a registry code that resolves publicly.

Related