Cybersecurity, Privacy, & AI

Trending Now
What Business Leaders Need to Know About Cybersecurity Certification and Enforcement in 2025–2026 • NRC Efficiency Plan to Reuse DOE, DoD Data Met With Skepticism • Closed Briefing Sets Stage For House Hearing On Anthropic’s Mythos and Cyber Risks • CISA, G7 Partners Release AI Software Bill of Materials Guidance • OMB to Refresh the Federal IT Dashboard

DoD Warns Vendors about Fake Third-Party CMMC Certifiers

Casimiro PT | Shutterstock

Stacy Bostjanick, director of the CMMC policy office and the Under Secretary of Defense for Acquisition and Sustainment, cautioned vendors to be wary of companies falsely claiming they can get other vendors certified under the new Cybersecurity Maturity Model Certification. She said the accreditation body, which is independent of DoD, is considering sending “cease and desist” letters to any company saying they can get another vendor certified under CMMC.

Bostjanick also said that civilian agencies and U.S. allies including Canada, Sweden, and the UK are paying attention to how DoD rolls out the program. “They are all watching to see if we fall on our face or not,” she remarked. “If we roll this out and make it work, they have indicated they will adopt CMMC as well.”

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.