THE QUICK READ
  1. Certification timing and assessment notice
  2. Required CMMC deliverables
  3. SSP review before achieving the contracted level
Research GE Aerospace beyond the requirements.

Explore supply-chain relationships and public security observations.

View research plans →Save this guide free

GE Aerospace’s REMARK Enterprise Cyber Flowdowns require sellers subject to those terms to obtain and maintain the contracted CMMC level throughout the contract.

Certification timing and assessment notice

Section 3.2.6 requires the contracted level no later than one year after the CMMC rules take effect. It does not print a calendar deadline. Notify the PM Cyber Lead at least 60 days before any third-party CMMC assessment and permit designated Government representatives to audit the process.

Sources: [1]

Required CMMC deliverables

Deliver a CMMC Implementation Plan listing controls implemented and planned for audit under SDRL 282. Deliver a Cybersecurity POAM listing CMMC audit deficiencies under SDRL 283. These requirements flow down to subcontractors and vendors.

Sources: [1]

SSP review before achieving the contracted level

Section 3.2 requires an SSP maintained to NIST SP 800-171 Revision 2 and Government access for review at the seller’s facility. Its Government-review provisions do not require copies of the SSP or associated POAM to be shared with the buyer; the separate CMMC deliverables above remain specified in section 3.2.6.

Sources: [1]
LETTERS, TERMS AND SUPPLIER INSTRUCTIONS

Source documents