★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/DOD Interim Rule on Cybersecurity Adds New Obstacles to Contract Award
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
DoD·Cyber & Privacy Brief

DOD Interim Rule on Cybersecurity Adds New Obstacles to Contract Award

The Department of Defense has released a long awaited interim rule on contractor cybersecurity requirements, which creates a two-pronged approach for full Cybersecurity Maturity Model Certification compliance by October 2025.

First, contractors must submit NIST SP 800-171 assessments to the Supplier Performance Risk System to be eligible for any future contract or task/delivery order award. New contracts or task/delivery order awards will also require contractors to grant the government access to their facilities to perform higher level NIST SP 800-171 assessments. This requirement is related to, but separate from, CMMC.

Second, the interim rule will allow contracting officers to include CMMC requirements in future contracts with approval from the Office of the Under Secretary of Defense for Acquisition and Sustainment. All DoD contracts and subcontracts will require CMMC by October 2025.

More at Smith Pachter McWhorter

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.