DI-MGMT-82509
Information Management and Control Plan (IMCP) for Cybersecurity Maturity Model Certification (CMMC)
This DID defines the format and content of the Information Management and Control Plan (IMCP) that a contractor prepares to protect and control the flow of Federal Contract Information and Controlled Unclassified Information within the supply chain for CMMC.
Approval DateDecember 8, 2025
AMSC Number10611
Preparing ActivityMDA
Project NumberMGMT-2025-026
OPR—
DTIC ApplicableNo
GIDEP ApplicableNo
LimitationTBD
Applicable FormsNone
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
This Data Item Description (DID) supports the Information Management and Control Plan (IMCP) for the Cybersecurity Maturity Model Certification (CMMC). It is separate and distinct from the IMCP for DoD Assessments (DI-MGMT-82383).
The IMCP describes the contractor's plan to protect and control the flow of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) within the supply chain.
The IMCP Supplier Compliance Supplement (SCS) is used to identify prime contractors and subcontractors, at all tiers of the supply chain, who develop, store, or transmit FCI and/or CUI. A link to a SCS template can be found in the Instructions for Use section of this DID (page 5).
This DID contains the format and content preparation instructions for the data product generated by the specific task requirement included in the contract.
Preparation Instructions
1.1National Institute of Standards and Technology (NIST), Special Publication (SP) 800-171 (Latest revision)."Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations.". U.S. Department of Commerce.
1.2National Institute of Standards and Technology (NIST). Special Publication (SP) 800-172, "Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171".February 2021. U.S. Department of Commerce. https://csrc.nist.gov/Pubs/sp/800/172/Final
1.3General Services Administration (August 2025). Federal Acquisition Regulation (FAR) 52.204-21: "Basic Safeguarding of Covered Contractor Information Systems".
1.4Department of Defense. (January 2025). Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012: "Safeguarding Covered Defense Information and Cyber-Incident Reporting."
1.5Department of Defense (January 2025). DFARS 252.204-7019: "Notice of NIST SP 800-171 DoD Assessment Requirements."
1.6Department of Defense. (January 2025). DFARS 252.204-7020: "NIST SP 800-171 DoD Assessment Requirements."
1.7Department of Defense. (January 2025). DFARS 252.204-7021: "Cybersecurity Maturity Model Certification Requirements."
2Format.The IMCP for CMMC data submission requirements:
2.1MS Word format in accordance with the IMCP for CMMC Template and its instructions for use (see Table 1).
2.2Use the MS Excel template for IMCP for CMMC SCS data submissions in accordance with the SCS instructions.
2.3Readable by approved Government systems.
Figures

Figure Table 1. IMCP Template

Figure Table 1. IMCP Template (continued)

Figure Table 2. IMCP Supplier Compliance Supplement Template

Figure Table 2. IMCP Supplier Compliance Supplement Template (continued)
Schema v3.0Community-maintained · Verify against ASSIST