Cybersecurity, Privacy, & AI

Trending Now
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns • Cyber-attacks Against State Water Supplies Continue—12 to Date • A Crucial Cybersecurity System Is Getting a Closer Look From Congress • Why Federal AI Governance Must Be Built for Continuous Change • NATO and an AI Startup Can Now Name and Track Software Vulnerabilities

CMMC Won’t Apply to Commercial-Off-The-Shelf Suppliers, DOD Website Shows

The Cybersecurity Maturity Model Certification will not apply to Department of Defense suppliers that only provide commercial-off-the-shelf products, a recent change to DoD’s website shows. “Companies that solely produce Commercial-Off-The-Shelf (COTS) products do not require a CMMC certification,” the site now says. However, attorneys caution against thinking this new information will apply to many contractors. “Companies should be careful not to assume they or their subcontractors will fall within this narrow exception,” Morrison and Foerster attorneys wrote in a recent blog post on the topic. They identified not-IT focused contractors such as food and fuel suppliers as examples of vendors who would be exempt under this clause.

More at FedScoop

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.