Cybersecurity, Privacy, & AI

Trending Now
Agriculture Department Kicks Off $300M Palantir Deal on IT, National Security Work • Vercel Attack Fallout Expands to More Customers and Third-Party Systems • Seeing the Cyber in Economic Statecraft • Responding to a Data Breach: How to Preserve the Attorney-Client Privilege • NIST Cyber Center to Launch OT ‘Visibility’ Project

What the Defense Department’s Cyber Certification Will Mean for Small Businesses

The Defense Department’s impending cybersecurity certification requirement for all contractors has caused no shortage of concerns among small businesses worried about the cost. But the Pentagon’s lead for the effort made the case Wednesday that the move is necessary and, in some cases, will help small contractors. Under the Cybersecurity Maturity Model Certification, all vendors doing business with DoD will be required to be certified by a third-party assessor as fully compliant or be prohibited from being awarded the contract.

“We need to lower the barriers. We need to speed up acquisition. But we also need to secure the [defense industrial base],” remarked Katie Arrington, CISO for the assistant secretary for defense acquisition. “With 70% to 80% of our data living on my contractors’ networks, I don’t have a choice but to worry about how they’re doing it.”

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.