Tag

Cmmc

All articles tagged with #cmmc

CUI Marking Chaos Elevates CMMC Costs and Confusion for DoD Contractors
technology9 days ago

CUI Marking Chaos Elevates CMMC Costs and Confusion for DoD Contractors

The DoD's inconsistent and unclear process for marking controlled unclassified information (CUI) keeps driving higher costs and confusion in the Cybersecurity Maturity Model Certification (CMMC) program, with industry groups warning overmarking, blanket flow-downs to subcontractors, and unclear CUI scope. They urge clearer, standardized CUI definitions, better guidance and training, and more selective CMMC application—especially for small businesses—alongside reforms to consolidate CUI categories and clarify contract-level expectations.

DoD kicks off nationwide listening tour to reshape CMMC rules
defense1 month ago

DoD kicks off nationwide listening tour to reshape CMMC rules

The DoD is reviewing the Cybersecurity Maturity Model Certification (CMMC) program and has suspended third-party assessments to reduce burdens on small defense contractors. It will hold nationwide listening sessions, gather 60 days of feedback, and issue a final report with recommendations by late September; the review could overhaul or tweak CMMC 2.0, possibly via interim rules. The department cites cost and assessor capacity as barriers; self-assessments remain allowed, while DIBCAC/NSA/DC3 services cover only part of the required NIST controls, and there are about 1,000 certified assessors versus a projected 2,000–3,000 needed.

Pentagon Pauses CMMC Phase 2 to Reassess Costs and Contractor Capacity
technology1 month ago

Pentagon Pauses CMMC Phase 2 to Reassess Costs and Contractor Capacity

The Pentagon has frozen the planned Phase 2 rollout of the Cybersecurity Maturity Model Certification (CMMC), forming a cross‑department Reform Task Force and issuing an RFI to gather feedback as it reviews the program. The halt aims to prevent driving many small and mid‑sized defense vendors out of the defense industrial base, citing costs (SBA data suggesting potential multi‑billion‑dollar annual expenses) and a shortage of assessors (roughly 100 for more than 100,000 DIB companies). Until the review concludes (within about 60 days), enforcement will rely on self‑assessments under NIST 800‑171, with the possibility of further changes, including potential cancellation of CMMC after the pause.

Pentagon halts phase-two CMMC and launches 60-day reform to ease contractor compliance
policy1 month ago

Pentagon halts phase-two CMMC and launches 60-day reform to ease contractor compliance

The Pentagon is suspending phase two of the Cybersecurity Maturity Model Certification (CMMC) plan and maintaining phase one self-assessments as it launches a 60-day reform review to rebalance the program toward faster capability delivery and lower barriers for small and non-traditional contractors; milestones are paused, with an emphasis on tangible cyber hygiene over costly third-party certifications, a shift supported by the SBA and potentially affecting up to 80,000 defense contractors.

Pentagon halts Phase II CMMC audits to cut red tape for defense firms
defense1 month ago

Pentagon halts Phase II CMMC audits to cut red tape for defense firms

The DoD is pausing Phase II CMMC requirements, including third-party assessments, to reduce burdens on small and nontraditional defense firms while preserving baseline cybersecurity under NIST SP 800-171 Rev 2 via self-assessments. A 60-day task force will review CMMC and propose practical reforms to speed capability delivery and lower entry barriers; contractors must still protect federal data and current solicitations will be amended accordingly.