★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/CMMC Won’t Apply to Commercial-Off-The-Shelf Suppliers, DOD Website Shows
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
DoD·Cyber & Privacy Brief

CMMC Won’t Apply to Commercial-Off-The-Shelf Suppliers, DOD Website Shows

The Cybersecurity Maturity Model Certification will not apply to Department of Defense suppliers that only provide commercial-off-the-shelf products, a recent change to DoD’s website shows. “Companies that solely produce Commercial-Off-The-Shelf (COTS) products do not require a CMMC certification,” the site now says. However, attorneys caution against thinking this new information will apply to many contractors. “Companies should be careful not to assume they or their subcontractors will fall within this narrow exception,” Morrison and Foerster attorneys wrote in a recent blog post on the topic. They identified not-IT focused contractors such as food and fuel suppliers as examples of vendors who would be exempt under this clause.

More at FedScoop

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.