Cybersecurity, Privacy, & AI

Trending Now
Weaponized Email AI Assistants Could Help Attackers Hijack Accounts • CISA Guidance Targets Water Sector Security, Open Source AI and More • Salesforce Previews Plans to Deliver Newly Authorized ‘AI Agents’ Across DOD • CMS Pivots to Risk-Based Cybersecurity Model, CISO Says • Senate Set to Debate Package of Bills on Privacy, AI and Kids Safety

All CUI-Handling DoD Contractors Will Need Assessments Under CMMC 2.0

G-Tech Studios | Shutterstock

When the Defense Department announced CMMC 2.0, it said that instead of requiring a third-party assessment for all contractors that handle Controlled Unclassified Information, only about half of them would need one, because the CUI handled by the other half wasn’t especially risky. However, DoD’s deputy CIO David McKeown now says that, based on further analysis, “pretty much everybody” handling CUI will need an independent assessment. The roughly 140,000 defense contractors handling only less sensitive “federal contract information” will still only need to submit a self-assessment.

Source:

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.