Cybersecurity, Privacy, & AI

Trending Now
Doxim Data Breach Settlement Underscores Third-Party Data Security Risk • SASC Proposes Reorganization of Pentagon’s IT, Cyber Leadership • Anthropic Suspends Top AI Models After U.S. Export Control Order • Senate Bill Seeks to Restore Funding for Cyber Information-Sharing Program • CISA Directive Orders Agencies to Prioritize Vulnerability Patching in a New Way

What the Defense Department’s Cyber Certification Will Mean for Small Businesses

The Defense Department’s impending cybersecurity certification requirement for all contractors has caused no shortage of concerns among small businesses worried about the cost. But the Pentagon’s lead for the effort made the case Wednesday that the move is necessary and, in some cases, will help small contractors. Under the Cybersecurity Maturity Model Certification, all vendors doing business with DoD will be required to be certified by a third-party assessor as fully compliant or be prohibited from being awarded the contract.

“We need to lower the barriers. We need to speed up acquisition. But we also need to secure the [defense industrial base],” remarked Katie Arrington, CISO for the assistant secretary for defense acquisition. “With 70% to 80% of our data living on my contractors’ networks, I don’t have a choice but to worry about how they’re doing it.”

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.