Cybersecurity, Privacy, & AI

Trending Now
Cyber Leaders Wary of Giving Agentic AI Too Much Authority • TikTok Can Be on Government Phones. Managing It Comes Next. • NIST Wants to Overhaul Its Vulnerability Database for the AI Age • OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns • Cyber-attacks Against State Water Supplies Continue—12 to Date

DoD’s Interim Rule Adds a New Twist to Implementing Cyber Maturity Model

G-Tech Studios | Shutterstock

The Defense Department has released one of the last major pieces to complete the Cybersecurity Maturity Model Certification (CMMC) program puzzle: an interim rule under the Defense Federal Acquisition Regulations to add more clarity around the implementation timeline and around the requirements contractors will have to adhere to over the next five years. DoD estimates more than 26,000 small businesses would be impacted by this new rule at the basic assessment level.

Observers were surprised by new requirements for vendors working at medium or high security levels to undergo an assessment by the government of how they comply with the standards outlined in NIST Special Publication 800-171.

More at Federal News Network

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.