Breaking News Cybersecurity

CMMC's final rule has now landed

Several other regulatory steps and Congress' 60-day period to review the defense industrial base's new cybersecurity standard still loom before it takes effect.

Defense

DOD unveils proposed final rule for CMMC contracting

A phased rollout of the cybersecurity standard should begin in early 2025, with varying compliance levels and increased program office discretion.

Ideas

The coming cyber reckoning for federal contractors

Contractors face a 90-day deadline to prove their cybersecurity compliance as awards for the OASIS+ vehicle start to fall and that is a precursor to broader industry-wide requirements, DTS CEO Edward Tuorinsky writes.

Cybersecurity

Nearly 300 comment on proposed CMMC rule

The Defense Department now has to process and respond to the comments before it issues the final version of the industry-wide rule in the fall.

Defense

Experts expect some support for small businesses facing CMMC compliance

The Pentagon’s draft CMMC rule doesn’t exempt small firms from the security standards for defense contractors and subcontractors, but that doesn’t mean they won’t receive any help meeting the requirements.

Cybersecurity

Pentagon issues proposed CMMC rule

The long-anticipated draft rule, which will be officially published on Dec. 26, outlines proposed updates to DOD’s cybersecurity requirements for defense contractors and subcontractors who handle sensitive military data.

Cybersecurity

New Pentagon cyber strategy emphasizes industry and global partnerships

A top Defense Department official described the private sector as “absolutely essential” in implementing the agency’s new cyber strategy.

Cybersecurity

DOD, OMB expect September release of proposed CMMC rule

The rule that details the defense industrial base's new cybersecurity standard appears ready for review at the Office of Management and Budget.

Cybersecurity

New CMMC Training to Align with Certification Changes

Look for trainers working on the Cybersecurity Maturity Model Certification program to realign their efforts to support recent changes to the certification process in 2022.

Cybersecurity

Closing the CMMC training gaps

Look for trainers working on the Cybersecurity Maturity Model Certification program to realign their efforts to support recent changes to the certification process in 2022.

Cybersecurity

CMMC assessments could resume in January

The governing body responsible for implementing the Defense Department’s unified cybersecurity program for contractors expects security procedures for authorized third party assessors to start back up in early 2022. But DOD has the final say on the timeline.

Acquisition

What’s next for CMMC

After the Defense Department revamped cybersecurity standards for contractors, the Cybersecurity Maturity Model Certification program’s accreditation body is making adjustments.

Acquisition

Who's going to volunteer for the new CMMC?

The Defense Department is looking for contractors to test out its revamped cybersecurity standard to protect unclassified but sensitive data.

Cybersecurity

DOD revamps controversial CMMC program

After a nine-month review, the Defense Department is replacing its original cyber compliance program for the industrial base with CMMC 2.0, putting more emphasis on self-assessment.

Cybersecurity

White House pick for DOD CIO eyes tweaks to CMMC

The Biden administration's pick to be the Pentagon's tech chief wants to make it easier for small businesses to adhere to the Defense Department's cybersecurity standards and expand network optimization across the entire enterprise.

Cybersecurity

CMMC's Arrington sues DOD to clear her name

Katie Arrington, who has been off the job since May, is suing the Department of Defense to get resolution on her personnel case.

Acquisition

DOD wants industry to continue with CMMC prep amid program review

Dr. Christine Michienzi, the chief technology officer for the Office of the Deputy Assistant Secretary of Defense for Industrial Policy, said while results were coming soon, defense contractors should "continue on" with updates to cybersecurity practices as DOD finalizes its review of its Cybersecurity Maturity Model Certification program.

Acquisition

DOD's silence on CMMC is worrying industry, trade groups claim

Months of silence from the Defense Department on the status of the Cybersecurity Maturity Model Certification program is palpable and stirring unease among defense contractors, trade associations say in a letter to Deputy Defense Secretary Kathleen Hicks.

Acquisition

CMMC board chief talks assessors, IT staff

Matt Travis, the CEO for the Cybersecurity Maturity Model Certification Accreditation Body, said proper training and IT access to the Defense Department's Enterprise Mission Assurance Support Service (eMASS) application, which will house CMMC data, still needs to be finalized for the third-party organizations that will be charged with conducting cyber assessments.

Acquisition

DHS eyes CMMC model

DHS' Office of the Chief Procurement Officer issued a special notice Aug. 10, noting that it is looking for a way to check contractors' compliance with its cyber hygiene clauses released in 2015.