Piliero Mazza attorneys identify primary concerns for DoD contractors in revision 0.7 of the Department of Defense’s Cybersecurity Maturity Model Certification. Rev. 0.7’s biggest change to Levels 1–3 lies not in direct changes, but in the materials surrounding them. It now contains discussions and clarifications for Levels 1–3, including helpful models of how the practices in those Levels might look when applied to real-life situations.
The new revision has fleshed out the requirements for Levels 4 and 5 specifically, providing new summaries of the practices and processes required for those Levels. It also significantly streamlines these practices and processes. In particular, rev. 0.7 has removed 36 practices from Level 4 and removed 10 practices from Level 5.
