Cybersecurity, Privacy, & AI

Trending Now
Google Sees 5 Chinese Groups Exploiting React2Shell for Malware Delivery • INDOPAC’s Rudd Said to Be Trump’s Pick for US Cyber Command Chief • NIST Releases Draft AI Cybersecurity Framework for Public Comment • DOJ Announces Takedown of Alleged Laundering Platform Used by Cybercriminal Groups • When AI Starts Doing the Work: The Rise of Agentic AI in Government Contracting

Who Pays for CMMC Certification?

With the announcement of the Cybersecurity Maturity Model Certification version 1.0, attention is turning to the question of who is going to pay the significant costs associated with the certification and work necessary to comply. DoD has been less than clear about whether contractors can seek reimbursement for these costs, or claim costs as an allowable indirect cost.

Attorneys at Fox Rothschild speculate that the cost of certification itself might be covered, but not the greater costs associated with becoming compliant as a reimbursable direct cost. The CMMC level involved may be a factor. “Since complying with CMMC level 3 is the equivalent to complying with DFARS 252.204-7012, it should follow that, at a minimum, the cost of Level 3 certification should be an allowable cost,” they note.

More at Fox Rothschild

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.