★ ANNUAL REVIEW 2027 SPONSORSHIPS NOW OPEN   Learn more →

Log In  |  Become a Member  |  Sponsor  |  ⌕ Search

News/Cyber & Privacy/DoD’s Interim Rule Adds a New Twist to Implementing Cyber Maturity Model
Free SampleYou’re reading a free sample of the Cyber & Privacy Brief. Members get every case digest like this, six days a week.See Membership Options
DoD·Cyber & Privacy Brief

DoD’s Interim Rule Adds a New Twist to Implementing Cyber Maturity Model

The Defense Department has released one of the last major pieces to complete the Cybersecurity Maturity Model Certification (CMMC) program puzzle: an interim rule under the Defense Federal Acquisition Regulations to add more clarity around the implementation timeline and around the requirements contractors will have to adhere to over the next five years. DoD estimates more than 26,000 small businesses would be impacted by this new rule at the basic assessment level.

Observers were surprised by new requirements for vendors working at medium or high security levels to undergo an assessment by the government of how they comply with the standards outlined in NIST Special Publication 800-171.

More at Federal News Network

Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.