Cybersecurity, Privacy, & AI

Trending Now
Cyber Leaders Wary of Giving Agentic AI Too Much Authority • New ‘Water Watch Center’ Launched to Help Small Utilities Stop Cyberattacks • TikTok Can Be on Government Phones. Managing It Comes Next. • CISA, FBI and Partners Detail Gunra Ransomware Tactics • NIST Wants to Overhaul Its Vulnerability Database for the AI Age

Pentagon Ready to Name First 15 ‘Pathfinder’ Contracts for CMMC

G-Tech Studios | Shutterstock

December has already seen new rules take effect that serve as a precursor to the full CMMC implementation, and the Defense Department is ready to announce the first 15 contracts that will serve as “pathfinders” for the new model. These contracts will demonstrate the first real-world use of the CMMC, moving beyond the non-punitive tabletop exercises acquisition officials have performed so far.

The new rules require vendors bidding on new contracts to use the Supplier Performance Risk System web portal to self-assess their compliance with the security controls in NIST SP 800-171. The certification will be verified by auditors, at least for vendors who have claimed a medium or high score.

More at Federal News Network

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.