Skip to main content

CMMC Pause: What DoW & Primes Still Require

  • blog
  • JCP Certification: Requirements, How to Apply, and Where NIST 800-171 Fits

JCP Certification: Requirements, How to Apply, and Where NIST 800-171 Fits

  • August 04, 2026
Author

Emily Bonnie

Senior Content Marketing Manager

What is JCP certification?

The Joint Certification Program (JCP) is a joint effort between the United States and Canada that certifies contractors in both countries to receive unclassified export-controlled technical data from the US Department of Defense and the Canadian Department of National Defence.

In the US, this data is governed by DoD Directive 5230.25, "Withholding of Unclassified Technical Data From Public Disclosure." In Canada, it's governed by the Technical Data Control Regulations. The program is administered by the US/Canada Joint Certification Office (JCO), part of the Defense Logistics Agency (DLA).

The certification itself is built around DD Form 2345, the Militarily Critical Technical Data Agreement. When your application is approved, the JCO assigns your company a certification number that identifies you as a "certified contractor" under DoDD 5230.25. That number is what controlling DoD offices check before releasing technical data to you.

Who needs JCP certification?

Plenty of companies participate in the defense supply chain without ever touching export-controlled technical data. But if your work involves building, repairing, or supplying parts and systems to government specifications, you'll quickly hit the technical data wall: the solicitation is public, but the drawings you need to price it are not.

JCP certification belongs on your roadmap if you plan to:

  • Bid on DoD solicitations that include export-controlled technical data. Many solicitations attach technical data packages (drawings, specs, standards) that only certified contractors can access.
  • Access the DLA Internet Bid Board System (DIBBS). DIBBS contains export-controlled and Controlled Unclassified Information (CUI), so JCP certification is a prerequisite for access.
  • Exchange export-controlled technical data with another JCP-certified company. Primes often require subcontractors to hold a JCP certification number before sharing drawings or specifications.

Universities and research institutions also obtain JCP certification to participate in defense-related research and industry groups.

JCP vs. ITAR registration vs. CMMC: What's the difference?

JCP certification ITAR (DDTC) registration CMMC
What it does Certifies you to receive unclassified export-controlled technical data from DoD/DND Registers manufacturers, exporters, and brokers of defense articles with the State Department Verifies you've implemented the cybersecurity controls required to protect FCI and CUI
Who runs it DLA Joint Certification Office Directorate of Defense Trade Controls (State Department) Department of Defense
Legal basis DoDD 5230.25 ITAR (22 CFR Parts 120-130), Arms Export Control Act 32 CFR Part 170, DFARS 252.204-7021
What it's about Access: can DoD release this data to you? Activity: are you making, exporting, or brokering defense articles? Security: can you protect the data once you have it?
Cost Free Annual registration fee Self-assessment costs

JCP gets you access to the data. ITAR registration covers what you do with defense articles and technical data as a manufacturer or exporter. CMMC proves you can protect the data on your systems. Defense contractors often need all three.

JCP certification requirements

As of 2024, the JCP only accepts applications through its online portal. Before you start the application, make sure you already have each of the following requirements. The portal checks several of them automatically, and if any are missing, the system will reject your application.

1. An active CAGE code. Your Commercial and Government Entity (CAGE) code must be active, and every piece of information you enter in the application must match your record in the CAGE database. Canadian companies use an NCAGE code.

2. An active SAM registration. Your System for Award Management (SAM) registration must be current.

3. A NIST 800-171 assessment posted to SPRS. Under the interim DFARS Case 2019-D041, JCP applicants must have a NIST SP 800-171 self-assessment documented in the Supplier Performance Risk System (SPRS). The application asks you to attest to this directly, and the JCO checks SPRS before approving.

4. Compliance with DFARS export control and cybersecurity clauses. The application requires you to certify that your company is in full compliance with DFARS 252.204-7008, 252.204-7009 and 252.204-7012, the clauses that establish safeguarding requirements for controlled technical information and covered defense information.

5. A designated Data Custodian. You must name one Data Custodian per physical location CAGE code. This is the individual responsible for downloading, receiving, and disseminating export-controlled technical data for your company. For US companies, the Data Custodian must be a US citizen or lawful permanent resident.

6. The computer where the data will live. The application asks for the IP address, permanent MAC address, and full physical address of the specific computer or server where export-controlled technical data will be stored. For US firms, that machine must be physically located in the United States, and everyone with access to it must be a US citizen or lawful permanent resident. Randomized or changeable MAC addresses are not accepted.

7. A completed training certificate. The Data Custodian must complete the DLA Introduction to Proper Handling of DoD Export-Controlled Technical Data training and upload the certificate with the application.

8. Proof of business. US companies upload documentation showing the company is a registered business entity, such as Secretary of State registration. Just make sure that no documents containing personally identifiable information are uploaded to the portal.

9. Export control details. The application asks whether your equipment, materials, or services relate to the United States Munitions List (USML) or the Commerce Control List (CCL), whether you're registered with the Directorate of Defense Trade Controls (DDTC), and whether you hold any US export control licenses. If you hold an export license, you'll need to attach proof.

10. A signing authority. The application must identify and be signed by an individual with authority to legally bind the company to a contract. A knowing and willful false statement on the form is punishable by fine or imprisonment under 18 U.S.C. 1001.

Nine of these ten items are paperwork tasks you can knock out in a matter of days. Number three is a project all in itself. Let's talk about why.

JCP certification prerequisites: NIST 800-171 compliance

NIST Special Publication 800-171 is the federal standard for protecting Controlled Unclassified Information (CUI) on non-government systems, and the technical data JCP unlocks is a type of CUI. The government requires proof you can protect sensitive data before sharing it with you.

Here's what NIST 800-171 compliance involves:

  • 110 security requirements across 14 control families. These requirements cover areas like access control, incident response, encryption, audit logging, personnel security, physical protection, configuration management, and more.
  • A System Security Plan (SSP). This document describes how your environment meets each of the 110 requirements. An SSP can span hundreds of pages, and contracting officers treat it as a foundational artifact.
  • A scored self-assessment posted to SPRS. Follow the DoD Assessment Methodology to score your implementation on a scale from 110 to -203. Every unimplemented requirement subtracts 1, 3, or 5 points depending on its weight. Your score is visible to DoD contracting officers, and it's a formal attestation to the government. Misrepresenting your score exposes you to risk under the False Claims Act.
  • Plans of Action and Milestones (POA&Ms). This is your remediation document for any requirement you haven't fully implemented, with dates and owners.

Even for a company already running a mature security program, documenting all of this is a heavy lift. For a company entering the defense industrial base for the first time, it usually means standing up capabilities that don't exist yet: deciding whether to build a CUI enclave or bring your whole environment into scope, deploying new tooling, writing policies, training people, and then assessing and scoring the result. This can take months of work, and it's the real critical path to your JCP certification, your DIBBS access, and DoD contract eligibility.

How the Cybersecurity Maturity Model Certification (CMMC) relates

JCP data is CUI, which means CMMC Level 2 requirements also apply. The good news is that Level 2 is built on NIST 800-171, so no new safeguarding requirements are introduced.

However, these are two different assessments of the same 110 requirements, run under two different rulebooks. The score that gets you through the JCP application is a Basic self-assessment under the DoD Assessment Methodology. A CMMC Level 2 self-assessment follows the CMMC program rule (32 CFR Part 170).

There are four meaningful differences:

  1. CMMC is graded at the objective level. The SPRS assessment scores the 110 requirements. A CMMC Level 2 self-assessment evaluates the 320 assessment objectives in NIST SP 800-171A that sit underneath them, and a requirement only counts as MET if every one of its objectives is satisfied.
  2. There's a minimum passing score for Level 2. Your Basic Assessment score can be anything, even negative. It's visible to contracting officers, but no floor is enforced. CMMC Level 2 requires full implementation, or at minimum a conditional status with a score of at least 88 out of 110.
  3. POA&Ms are treated differently. Under the SPRS assessment, any gap can sit on a Plan of Action & Milestones as long as your score reflects it. Under CMMC, only a limited set of lower-weighted requirements are POA&M-eligible, and open items must be closed within 180 days or your conditional status lapses.
  4. Annual affirmations are required. CMMC requires an annual affirmation of continuing compliance by a named Affirming Official, a senior company executive attesting in SPRS that the implementation still holds. That recurring, personal attestation is a sharper False Claims Act exposure than a score sitting in a database.

When you're thinking about your NIST 800-171 compliance program, build to the CMMC Level 2 bar from the start. The SPRS score is what gets you through the JCP application, but the objective-level standard is what your work will eventually be measured against, and building to it once beats retrofitting later.

CMMC Readiness Assessment

Answer a series of questions tailored to your CMMC Level to get an approximate readiness score, estimated SPRS score, and a prioritized gap analysis in under 5 minutes.

The JCP certification application process

Once you've met the NIST 800-171 prerequisite and posted your score into SPRS, the application itself moves quickly. Here's how the process works in the current online portal.

Step 1: Register for the JCP Portal

Go to public.dacs.dla.mil/jcp/ext and create an account. The portal requires two-factor authentication through Google Authenticator or another TOTP app.

Step 2: Join or create your organization

The portal links your user account to your company's CAGE code and pulls in your legal business name and physical address from the CAGE database. Verify this information is current before proceeding, because mismatches will stall your application.

Step 3: Complete the Applicant Information section

This is the longest section of the application. You'll enter the following information:

  • Your Data Custodian's name, title, phone, and email
  • The IP address, MAC address, and physical address of the computer that will store the data
  • Whether you're a prime contractor or subcontractor
  • A short description of what your company does (200 character limit)
  • Your relevant NAICS or FSC codes
  • Your USML, CCL, DDTC, and export license answers
  • A statement of your purpose for accessing export-controlled technical data (400 character limit)

If you're a non-manufacturer, you also list the CAGE codes of the manufacturers that produce your products.

Step 4: Upload attachments

Two attachments are required for US companies: proof of business (Secretary of State documentation) and the Data Custodian's Introduction to Proper Handling training certificate.

Step 5: Review the pre-submission checklist and submit

Before the portal accepts your application, it presents a final attestation screen. You confirm compliance with DFARS 252.204-7008, DFARS 252.204-7009, and DFARS 252.204-7012, confirm your NIST 800-171 assessment is in SPRS, and acknowledge that your CAGE, SAM, SPRS, and (if you're requesting DLA access) DIBBS records will be checked. If any of those systems shows a problem, the application will be rejected.

Step 6: Wait for JCO review

The JCO reviews your application and, if approved, assigns your JCP certification number and expiration date. Processing times vary based on application volume, and errors on the application are the most common cause of delays, so it pays to double-check every field against your CAGE and SAM records before hitting submit.

How much does JCP certification cost?

There are no fees to obtain or maintain JCP certification. But there are costs associated with the NIST 800-171 compliance prerequisite.

Getting from zero to a defensible NIST 800-171 posture, building an SSP, and achieving a qualifying SPRS score takes a significant amount of time and resources. Organizations usually need security tooling to close technical gaps like MFA, logging, and FIPS-validated encryption, consultant fees if you bring in help for gap assessments or documentation, staff time to write policies and collect evidence, and potentially architectural changes like a CUI enclave to keep your scope manageable. Companies routinely spend more time and money implementing NIST 800-171 and preparing their SPRS submission than they ever will on the JCP application itself.

The good news is that the same NIST 800-171 compliance program also satisfies your DFARS 252.204-7012 obligations and the CMMC self-assessment requirements appearing in DoD contracts, so budget for it once and it carries you through all three.

JCP certification renewal and maintenance

JCP certification is valid for five years. DLA recommends submitting your renewal at least 60 days before expiration to allow for review. If you don't renew, your certification is canceled.

A few ongoing obligations trip up certified companies:

  • Report changes. If your company's status or data changes during the certification period (address, Data Custodian, ownership), you must notify the JCP Office by submitting a revision with supporting documentation.
  • Keep your portal account active. JCP portal accounts are disabled after 35 days without a login. Warning emails go out five days and one day before an account locks. Put a recurring reminder on your Data Custodian's calendar to avoid being locked out.
  • Renewals also have to clear the NIST 800-171 SPRS check. No SPRS assessment, no renewal.

Your security program also has its own maintenance clock, and it runs faster than JCP's. Certification lasts five years, but DoD requires the NIST 800-171 assessment behind your SPRS score to be no more than three years old, and CMMC self-assessments carry the same three-year validity with an annual affirmation in between. A set-and-forget score will lapse mid-certification.

Keeping your assessment current as your environment changes covers your JCP renewal, your contract eligibility, and your CMMC self-assessment obligations with the same work.

Enhanced JCP: DLA enhanced validation and DIBBS

If you want to sell to the Defense Logistics Agency, standard JCP certification is step one. You also need DLA Enhanced Validation (DEV), sometimes called enhanced JCP certification, which provisions access to DIBBS, the web-based system where you search and quote on DLA solicitations.

The DEV application lives in the same JCP portal and builds on your JCP certification. Because DIBBS contains export-controlled data and CUI, the enhanced review takes a deeper look at your justification for access and your SPRS posture.

Accelerating the path through NIST 800-171 and CMMC

The JCP application itself is a matter of hours, but the NIST 800-171 and CMMC work behind it is the project that determines your timeline. You're left to figure out which systems are in scope, what 110 requirements mean in practice for your environment, whether your SPRS score is defensible, and how to keep documentation current while you run your business. The traditional answer is consultants, spreadsheets, and hope, and for a small team entering the DIB it can significantly stall your market entry by months.

Secureframe Defense was purpose-built to be your map to NIST 800-171 compliance. It gives defense contractors a single platform to:

  • Know exactly what you need to do. Defense Navigator's guided workflow walks you through scoping and requirements step by step. You'll know what's in scope and where to start, so you can make progress starting on day one.
  • Post a score you can stand behind. See your live SPRS score and exactly how specific controls affect it, so you can prioritize the work that moves the number most. When it's time to self-assess, you work through each control with a clear MET or NOT MET and the supporting evidence at your fingertips.
  • Stop hand-building documentation. Generate and maintain your SSP and POA&Ms from your live environment, eliminating hours of manual work and keeping documentation current.
  • Get expert guidance along the way. Access compliance specialists who work with defense contractors daily and have been through a CMMC Level 2 assessment themselves.

Don't let NIST 800-171 compliance delay your JCP certification, your DIBBS access, and your first contract. Secureframe Defense offers a fast, clear path to compliance that carries you through every stage of your defense contracting journey.

Get certified. Stay compliant.

Request a demo

FAQs

What is JCP certification?

JCP certification, issued through the US/Canada Joint Certification Program, certifies that a US or Canadian contractor is eligible to receive unclassified export-controlled technical data from the US Department of Defense and Canadian Department of National Defence. It's based on DD Form 2345 and administered by the DLA Joint Certification Office.

How do I get a JCP certification number?

Apply through the JCP Portal at public.dacs.dla.mil/jcp/ext. You'll need an active CAGE code, current SAM registration, a NIST 800-171 assessment in SPRS, a designated Data Custodian who has completed the DLA data handling training, and proof of business. Approved applicants receive a certification number from the Joint Certification Office.

How long does JCP certification take?

Processing times vary with application volume and accuracy. Applications with errors or mismatches against CAGE, SAM, or SPRS records take longer or get rejected, so verify those systems before you submit.

How much does JCP certification cost?

There is no fee to obtain or maintain JCP certification.

How often does JCP certification need to be renewed?

Every five years. DLA recommends submitting renewals at least 60 days before your expiration date. Renewals must also pass the NIST 800-171 SPRS check.

What is the Introduction to Proper Handling training certificate?

The DLA Introduction to Proper Handling of DoD Export-Controlled Technical Data training is a mandatory prerequisite for JCP certification. Your designated Data Custodian completes the training and uploads the certificate as a required attachment in the JCP application.

What is enhanced JCP certification?

Enhanced JCP usually refers to DLA Enhanced Validation (DEV), an additional review required to access the DLA Internet Bid Board System (DIBBS) and sell to DLA. You apply for DEV through the same JCP portal after (or alongside) your standard JCP certification.

Does JCP certification mean I'm ITAR registered?

No. JCP certification and ITAR (DDTC) registration are separate. JCP certifies you to receive export-controlled technical data from DoD. DDTC registration, required under ITAR, covers manufacturers, exporters, and brokers of defense articles. Many companies need both.

Does JCP certification require CMMC?

Not directly. The JCP application requires a NIST 800-171 self-assessment documented in SPRS under DFARS Case 2019-D041, a requirement that predates CMMC and applies regardless of your CMMC status. No CMMC level or certificate is a JCP prerequisite, and the third-party assessments that would have applied to CUI contracts were suspended in July 2026 pending DoD's program review. In practice, though, the work is the same: CMMC assesses the same 110 requirements behind your SPRS score, Phase 1 CMMC self-assessment requirements remain in DoD contracts, and the data JCP unlocks is CUI. Build the 800-171 program once and it carries your JCP application, your SPRS score, and your CMMC obligations together.

Note the reverse is also true: a CMMC assessment doesn't substitute for the SPRS requirement. DLA requires the NIST 800-171 assessment posted in SPRS regardless of your CMMC status.

Emily Bonnie

Senior Content Marketing Manager

Emily Bonnie is a seasoned digital marketing strategist with over ten years of experience creating content that attracts, engages, and converts for leading SaaS companies. At Secureframe, she helps demystify complex governance, risk, and compliance (GRC) topics, turning technical frameworks and regulations into accessible, actionable guidance. Her work aims to empower organizations of all sizes to strengthen their security posture, streamline compliance, and build lasting trust with customers.