Cybersecurity, Privacy, & AI

Trending Now
What Business Leaders Need to Know About Cybersecurity Certification and Enforcement in 2025–2026 • NRC Efficiency Plan to Reuse DOE, DoD Data Met With Skepticism • Closed Briefing Sets Stage For House Hearing On Anthropic’s Mythos and Cyber Risks • CISA, G7 Partners Release AI Software Bill of Materials Guidance • OMB to Refresh the Federal IT Dashboard

4 Ways to Prepare for Cybersecurity Maturity Model Certification

T.Dallas | Shutterstock

Dave Simprini of Grant Thornton identifies four best practices that defense suppliers can use to prepare for – and ultimately achieve the necessary rating under – the Cybersecurity Maturity Model Certification:

  • Select the CMMC level that is right for your organization, for now and in the future. Level 3 or higher is needed only if you handle controlled unclassified information.
  • Evaluate your business relationships with subcontractors; this involves them, too. It is your responsibility to ensure that your subcontractors achieve the right level of compliance.
  • Define your system boundaries to minimize threat surface, and designate a defined enclave that can hold CMMC relevant data.
  • Approach CMMC as an enterprise-wide initiative, not just a security challenge. It is critical to get stakeholder buy-in and continue to engage decision-makers from across your organization.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.