The Cybersecurity Maturity Model Certification won’t require all subcontractors on a contract to meet the same level of requirements, depending on the type of information they will be handling. This means smaller companies won’t need to obtain the more-costly higher level CMMC certifications to be included on contracts that require the prime to meet that requirement. DoD will clarify in requests for information notices which parts of a contract will require different certification levels.
Cybersecurity, Privacy, & AI
Trending Now
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns • Cyber-attacks Against State Water Supplies Continue—12 to Date • A Crucial Cybersecurity System Is Getting a Closer Look From Congress • Why Federal AI Governance Must Be Built for Continuous Change • NATO and an AI Startup Can Now Name and Track Software Vulnerabilities
Primes, Subs Won’t Face the Same CMMC Security Requirements on All Contracts
Gorodenkoff | Shutterstock
Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–Saturday — Subscribe here.
