KAMONRAT | Shutterstock

Ellen Lord, the defense undersecretary for acquisition and sustainment, says that wth the final specification of the Cybersecurity Maturity Model Certification due before the end of January, training for the program’s third-party accreditors will take place from now until June. The CMMC accreditation body, a not-for-profit and independent group of stakeholders, has been stood up and recently selected its chair. The consortium will use DoD’s new cyber standards to develop training and certification requirements for the third-party assessment organizations and individual assessors that will evaluate companies. Lord said the accrediting body “will incorporate semi-automated processes” and “include a tool that certified third-party assessors will employ for audits and collecting metrics to inform risk.”

More at Federal Computer Week