10/03/2024
Are you ready?
The Cybersecurity Maturity Model Certification (CMMC) is expected to become a mandatory requirement for companies working with the U.S. Department of Defense (DoD) on November 12th. That is if Congress doesn't take any actions over these 60 days. While voluntary for some time, CMMC 2.0, the streamlined version of the framework, is expected to become a legal requirement for contractors in 2025. Once this happens, all defense contractors and subcontractors will need to obtain certification to demonstrate compliance with the specified cybersecurity practices at one of three levels, depending on the sensitivity of the information they handle.
The time to dust off all the work you were doing before CMMC 1.0 was pulled back and re-released as CMMC 2.0 is long overdue. Even though the Cyber AB is working to qualify certified assessors, they are going to be a commodity for a long time and if you haven't spoken to an approved company in the Cyber AB marketplace, you may be putting your existing Federal contract at risk. For contractors, failing to comply with CMMC once it becomes a legal mandate could lead to loss of contracts or even legal penalties. As the CMMC framework becomes more tightly integrated into federal procurement processes, companies that haven't yet aligned their cybersecurity practices with the certification will need to accelerate their efforts. With the shift to a mandatory CMMC.
Send a message to learn more