The Pentagon’s Cybersecurity Maturity Model Certification (CMMC) Version 2.0 To Start Early 2025

Standard

“BREAKING DEFENSE” –By Carley Welch

“We are moving forward, we’re hoping by the first quarter of calendar year [2025] we’ll be able to start enforcing this and putting this in contracts,” – Dave McKeown, Deputy CIO for the DoD”

________________________________________________________________________________________________________

“The DoD published the new proposed rule of CMMC 2.0 on Dec. 26, 2023, long after the department announced CMMC 2.0 in November 2019. The goal of CMMC 2.0 is to create an upgraded version of the cyber certification program designed to strengthen the defense industrial base’s cybersecurity capabilities, while responding to industry’s complaints of CMMC 1.0 being too costly and restrictive. 

“We are moving forward, we’re hoping by the first quarter of calendar year [2025] we’ll be able to start enforcing this and putting this in contracts as we go forward. We just keep plugging along because this has been discovered learning, and they’ve got so many roadblocks that have popped up and so much resistance to this, but we feel this is super important,” McKeown said during the Potomac Officer’s Club Cyber Summit.

As with 1.0, CMMC 2.0, contractors who handle controlled unclassified information (CUI) would be mandated to adopt cybersecurity standards at different levels. However, CMMC 2.0 includes a three-level scale instead of the original program’s five-level scale, something McKeown said would reduce complexity by eliminating unique processes and security practices that are not necessary.

CMMC 2.0 reaffirmed that these contractors have to adhere to controls set by the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. 

Other changes CMMC 2.0 plans to bring forward require contractors and subcontractors to do either self-assessments, evaluations by a third-party assessment organization (C3PAOs) or government evaluators, depending on the contractor’s capacity of controlled unclassified or classified information. 

McKeown said these self-assessments are only doable through level 1 and some of level 2 — the levels with the least controlled unclassified or classified capabilities.

“So for the types of controlled unclassified and classified information that we don’t care that much about, they will be able to do the self-attestation […] they will not have to go though a CMS disaster,” McKeown said. 

Level 3 partners, given their level of classification, will not be eligible for any self-assessments, but will have to go through government evaluators — a step up from C3PAOs. 

“It’s not just about protecting the data. It’s about doing battle with persistent threats. We figured there’s about 600 companies here at this level. They will have to go through this more rigorous assessment,” McKeowen said of the companies with level 3 capabilities. 

Because companies could utilize self-assessments instead, they would save on the costs industry partners would have to pay for the planning and reparation for the assessment, the assessment itself and the reporting of the results.

“In estimating the Public costs, DoD considered applicable nonrecurring engineering costs, recurring engineering costs, assessment costs, and affirmation costs for each CMMC Level,” the proposed rule states

The public comment on the new rule ended on February 26, and the Pentagon is planning to roll out CMMC 2.0 in parts. The rollout phase is supposed to begin early next year, but the Pentagon intends to include CMMC requirements in all applications on or after Oct.1, 2026, according to the federal register. However, waivers may be issued in select cases.”

https://breakingdefense.com/2024/06/cmcc-2-0-on-track-to-start-early-2025

ABOUT THE AUTHOR:

Carly Welch is a Networks & Digital Warfare Reporter for ‘Breaking Defense ‘

About rosecoveredglasses

Ken Larson was awarded the Bronze Star during two military tours in Vietnam. His career subsequently spanned 36 years with major aerospace and defense companies and small business consulting. Ken received the SCORE National Achievement Award in 2010 and the MicroMentor Award for Outstanding Service In Mentorship in 2021. Micro Mentor and SCORE are non-profit organization offering free assistance to small business in business planning, operations, marketing and other aspects of starting and successfully operating a small enterprise. Ken is the author of two books, "Odyssey Of Armaments" and "Small Business Federal Government Contracting". He specializes in Small, Veteran-owned, Minority-Owned and Woman-Owned Businesses beginning work with the Federal Government. You can contact Ken for small business assistance at MicroMentor by going to: https://www.micromentor.org/mentor/38640 or by going to SCORE at: https://southmetro.score.org/mentors/ken-larson

Leave a comment