GSA’s Use of DoD Cybersecurity Language for Future Contracts Signals Increased Security Requirements in Civilian Contracts

The General Services Administration confirmed recently that businesses preparing to submit proposals in response to two proposed governmentwide acquisition contracts should expect to see Cybersecurity Maturity Model Certification level-specific requirements in certain subsequent orders issued against those contracts. These new CMMC requirements will be incorporated at the order level rather than the contract level, in order to introduce flexibility in addressing unique needs and bolster an agile framework. These efforts reflect the GSA’s attempt to synchronize GWAC requirements with the cybersecurity efforts of the Department of Defense.
Source:

