On September 29, 2020, the Department of Defense (DoD) issued a long-anticipated interim rule implementing its Cybersecurity Maturity Model Certification (CMMC) program. The rule introduces a new mandatory construct, the DoD Assessment Methodology, to serve as an interim certification process before contractors undergo a full CMMC review. A full description of the interim rule and what it means for DoD contractors follows. The interim rule becomes effective November 30, 2020, although full implementation of CMMC will not be achieved until 2025.
Cybersecurity, Privacy, & AI
Trending Now
Cyber Leaders Wary of Giving Agentic AI Too Much Authority • TikTok Can Be on Government Phones. Managing It Comes Next. • NIST Wants to Overhaul Its Vulnerability Database for the AI Age • OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns • Cyber-attacks Against State Water Supplies Continue—12 to Date
Department of Defense Issues CMMC Interim Rule, Setting Up a Two-Part Process for Review of Contractor IT Systems
Panchenko Vladimir | Shutterstock
Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.
