Cybersecurity, Privacy, & AI

Trending Now
What Business Leaders Need to Know About Cybersecurity Certification and Enforcement in 2025–2026 • NRC Efficiency Plan to Reuse DOE, DoD Data Met With Skepticism • Closed Briefing Sets Stage For House Hearing On Anthropic’s Mythos and Cyber Risks • CISA, G7 Partners Release AI Software Bill of Materials Guidance • OMB to Refresh the Federal IT Dashboard

Department of Defense Takes a More Gradual Approach to Cybersecurity Maturity Model Certification

Gorodenkoff | Shutterstock

In the lead up to the release of Cybersecurity Maturity Model Certification version 1.0, DoD representatives walked back the timing for full implementation. Contractors will all need to be certified in the coming years, but concerns about a mad scramble towards certification of the entire defense industrial base in calendar year 2020 have now been allayed. The new standards will be phased in over the next five years so that, by fiscal year 2026, all DoD contracts will include CMMC requirements.

Under CMMC, contractors and subcontractors will have their compliance with security requirements evaluated by neutral third-party evaluators, and all of them will need to meet some level of certification, not just those that handle “covered defense information.”

More at Morrison Foerster

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.