Cybersecurity, Privacy, & AI

Trending Now
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns • Cyber-attacks Against State Water Supplies Continue—12 to Date • A Crucial Cybersecurity System Is Getting a Closer Look From Congress • Why Federal AI Governance Must Be Built for Continuous Change • NATO and an AI Startup Can Now Name and Track Software Vulnerabilities

Arrington: Cybersecurity Outlays an Allowable Cost

Ahead of the release of the next draft version of the Cybersecurity Maturity Model Certification, Katie Arrington, the special assistant to the assistant secretary of defense for acquisition for cyber, thanked industry for its support and noted that expenses related to boosting the cybersecurity of contractor systems will be considered an allowable cost.

While DoD has set out a five-year plan for fully implementing the CMMC, Arrington expects the full rollout will take less time, as industry is on-board with the program. According to Arrington, DoD expects third-party assessors to certify about 1,500 vendors in 2021, 7,500 more in 2022 and 25,000 more by 2023.

Speaking at an event sponsored by Holland & Knight, Arrington also acknowledged the cost of the initiative. “We also are telling you security is an allowable cost now,” she remarked. “We are working through the Office of Management and Budget to ensure we have cost realism built into our estimations for our programs and acquisitions moving forward.” Proposed DFARS rules incorporating CMMC into DoD’s regulations are expected by spring and should be finalized by September.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.