Cybersecurity, Privacy, & AI

Trending Now
What Business Leaders Need to Know About Cybersecurity Certification and Enforcement in 2025–2026 • NRC Efficiency Plan to Reuse DOE, DoD Data Met With Skepticism • Closed Briefing Sets Stage For House Hearing On Anthropic’s Mythos and Cyber Risks • CISA, G7 Partners Release AI Software Bill of Materials Guidance • OMB to Refresh the Federal IT Dashboard

Arrington: Cybersecurity Outlays an Allowable Cost

Ahead of the release of the next draft version of the Cybersecurity Maturity Model Certification, Katie Arrington, the special assistant to the assistant secretary of defense for acquisition for cyber, thanked industry for its support and noted that expenses related to boosting the cybersecurity of contractor systems will be considered an allowable cost.

While DoD has set out a five-year plan for fully implementing the CMMC, Arrington expects the full rollout will take less time, as industry is on-board with the program. According to Arrington, DoD expects third-party assessors to certify about 1,500 vendors in 2021, 7,500 more in 2022 and 25,000 more by 2023.

Speaking at an event sponsored by Holland & Knight, Arrington also acknowledged the cost of the initiative. “We also are telling you security is an allowable cost now,” she remarked. “We are working through the Office of Management and Budget to ensure we have cost realism built into our estimations for our programs and acquisitions moving forward.” Proposed DFARS rules incorporating CMMC into DoD’s regulations are expected by spring and should be finalized by September.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.