CMMC

DOD, OMB expect September release of proposed CMMC rule

The rule that details the defense industrial base's new cybersecurity standard appears ready for review at the Office of Management and Budget.

New CMMC Training to Align with Certification Changes

Look for trainers working on the Cybersecurity Maturity Model Certification program to realign their efforts to support recent changes to the certification process in 2022.

Closing the CMMC training gaps

Look for trainers working on the Cybersecurity Maturity Model Certification program to realign their efforts to support recent changes to the certification process in 2022.

CMMC assessments could resume in January

The governing body responsible for implementing the Defense Department’s unified cybersecurity program for contractors expects security procedures for authorized third party assessors to start back up in early 2022. But DOD has the final say on the timeline.

What’s next for CMMC

After the Defense Department revamped cybersecurity standards for contractors, the Cybersecurity Maturity Model Certification program’s accreditation body is making adjustments.

Who's going to volunteer for the new CMMC?

The Defense Department is looking for contractors to test out its revamped cybersecurity standard to protect unclassified but sensitive data.

DOD revamps controversial CMMC program

After a nine-month review, the Defense Department is replacing its original cyber compliance program for the industrial base with CMMC 2.0, putting more emphasis on self-assessment.

White House pick for DOD CIO eyes tweaks to CMMC

The Biden administration's pick to be the Pentagon's tech chief wants to make it easier for small businesses to adhere to the Defense Department's cybersecurity standards and expand network optimization across the entire enterprise.

CMMC's Arrington sues DOD to clear her name

Katie Arrington, who has been off the job since May, is suing the Department of Defense to get resolution on her personnel case.

DOD wants industry to continue with CMMC prep amid program review

Dr. Christine Michienzi, the chief technology officer for the Office of the Deputy Assistant Secretary of Defense for Industrial Policy, said while results were coming soon, defense contractors should "continue on" with updates to cybersecurity practices as DOD finalizes its review of its Cybersecurity Maturity Model Certification program.

DOD's silence on CMMC is worrying industry, trade groups claim

Months of silence from the Defense Department on the status of the Cybersecurity Maturity Model Certification program is palpable and stirring unease among defense contractors, trade associations say in a letter to Deputy Defense Secretary Kathleen Hicks.

CMMC board chief talks assessors, IT staff

Matt Travis, the CEO for the Cybersecurity Maturity Model Certification Accreditation Body, said proper training and IT access to the Defense Department's Enterprise Mission Assurance Support Service (eMASS) application, which will house CMMC data, still needs to be finalized for the third-party organizations that will be charged with conducting cyber assessments.

DHS eyes CMMC model

DHS' Office of the Chief Procurement Officer issued a special notice Aug. 10, noting that it is looking for a way to check contractors' compliance with its cyber hygiene clauses released in 2015.

Small businesses ask Congress to focus CMMC on primes and DOD

Jonathan Williams, a partner at the Washington, D.C.-based law firm PilieroMazza, told lawmakers much of small businesses concerns could be assuaged if DOD and prime contractors shoulder the burden.

First CMMC assessment organization approved

The accrediting body overseeing the Defense Department's Cybersecurity Maturity Model Certification program announced the debut of the first organization authorized to assess defense contractors.

CMMC assessor training expected in late summer

The professional training needed to carry out assessments for the Defense Department's unified cybersecurity standard for contractors won't kick off until later this summer.

Is it time to test the limits -- and potential -- of expanding CMMC?

Calls for a certified baseline of cybersecurity seem to increase with every cyberattack. Is the CMMC model the right template for a universal and independently verifiable way to protect supply chains?