DOD has now released CMMC v1.02. What does CMMC mean for defense suppliers?
Beginning in 2020 selected RFIs and RFPs will include CMMC requirements. This means if your company wants to win those selected DOD contracts you will have to be CMMC compliant at the time of contract award.
CMMC Assessors and Assessments: Unlike previous compliance programs where you could self-certify your compliance, there will be an army of CMMC assessors that will act as a third party to review, inspect and certify that you are compliant - starting this summer! That means the time to get ready for those assessments is now.
How can the CMMC Academy help out? We will provide both general background and update information about CMMC as well as information on the specific practices your company may need to comply with. This CMMC 1.02 practice-oriented area will include:
CMMC Research - A way for you to indicate which areas of CMMC are difficult to understand
CMMC Augmentation - The Academy will work to provide further insights about CMMC practices - via assessment and implementation notes, panel discussions, videos, Q&A, and more.
View the Webcast:
DOD CMMC Summary
The goal of the DOD CMMC initiative is to prevent sensitive data from being stolen by
from the 300,000 DOD contractors and subcontractors. The two key types of information DOD wants to protect
but Unclassified Information ("CUI") and Federal Contract Information ("FCI").
The main concerns of DOD include a) theft and use of this information against the national security interests of the United States and b) theft of intellectual property that results in an estimated $600 billion loss to the U.S. economy.
The Bottom Line: Five Key Takeaways You Should Know
Impact on my company: Going forward, companies desiring to win defense contracts (based on RFIs and RFPs) will need to comply with new cybersecurity standards based on CMMC.
Assessments (audits): Unlike in past compliance programs, defense suppliers will no longer be able to "self-certify" or simply declare their compliance; they will be reviewed by reviewed and approved by assessors and third-party assessment companies called C3PAO (CMMC Third Party Assessment Organizations).
Schedule: RFIs and RFPs will begin to include CMMC criteria in June and September of 2020.
Rollout in 2020: DOD estimates there will be about 10 contracts issued in 2020, each of which could impact 150 suppliers. That's a total of 1,500 suppliers impacted by CMMC in the fall of 2020. More suppliers will be impacted beyond that.
Your suppliers: In many cases, it may not be sufficient for your own company to be CMMC certified. If your company needs to use suppliers, those companies may also need to be CMMC certified. You should encourage, and perhaps facilitate, their compliance.
Learn more about CMMC here.
CMMC Academy Events
RECENT WEBINAR: CMMC 2021 Year In Review
We recently held a CMMC 2021 year-in-review webinar. Discussion topics included a review of CMMC 2.0 and how it impacts small and medium-sized businesses.
Threat Spotlight:CISA and CGCYBER release joint alert on Log4J vulnerability.
A joint alert from the Cybersecurity and Infrastructure Security Agency and the United States Coast Guard Cyber Command warns of the ongoing exploitation of the Log4Shell vulnerability.
Threat Spotlight: CISA says 'PwnKit' Linux vulnerability exploited in attacks.
Threat Spotlight:Chinese APT targets rare Earth mining companies in North America and Australia.
CMMC Insights: Training on Implementation by Implementers
These online-only courses provide CMMC training to companies looking to comply with CMMC. The courses are created by an experienced team of cybersecurity implementers with years of experience on NIST standards.
Implementing CMMC will be different for every company. And with the U.S. government doubling down on cybersecurity, it's important to get it right. So where is the best place to start?
Our CMMC Insights courses were created to help companies looking to comply with CMMC understand how to implement the practices. Our team has years of experience implementing NIST 800-53.
One-year access to the learning portal is provided, and we will provide updates on changes to CMMC as clarity is provided on items such as reciprocity. Don't wait -- get started on your CMMC assessment preparation now.
Learn about the above threats – start a trial of the Cyber Defense Network (CDN110)
Learn about recent threats, vulnerabilities, threat actors, Industry threats, malware, and more.
Supports CMMC practices for Situational Awareness and Incident Response
CMMC Academy special – Academy members may receive a 30% discount
THIS SERVICE AND THE CONTENT THEREIN ARE FOR INFORMATIONAL PURPOSES ONLY, AND ARE PROVIDED ON AN “AS IS” AND “AS AVAILABLE” BASIS WITH ALL FAULTS, ERRORS, DEFECTS, INACCURACIES AND OMISSIONS. TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, CELERIUM INC. EXPRESSLY DISCLAIMS ALL WARRANTIES OR CONDITIONS, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO IMPLIED WARRANTIES OR CONDITIONS OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE, OR NON-INFRINGEMENT OF INTELLECTUAL PROPERTY. CELERIUM INC. MAKES NO REPRESENTATION, CONDITION OR WARRANTY AS TO THE SERVICE OR ANY CONTENT, OR THAT YOUR USE OF THE SERVICE OR ANY CONTENT WILL BE UNINTERRUPTED, TIMELY, SECURE, OR ERROR FREE OR THAT DEFECTS WILL BE CORRECTED. CELERIUM INC. MAKES NO REPRESENTATION OR WARRANTY AS TO THE RESULTS THAT MAY BE OBTAINED FROM USE OF THE SERVICE OR ANY CONTENT. CELERIUM INC. DOES NOT IN ANY WAY GUARANTEE, AND SHALL NOT BE LIABLE FOR, THE ADEQUACY, QUALITY, ACCURACY, COMPLETENESS, WORTH, OR TIMELINESS OF CONTENT THAT IS MADE AVAILABLE OR OBTAINED BY WAY OF THE SERVICE. CELERIUM INC. MAKES NO REPRESENTATIONS, WARRANTIES OR GUARANTEES OF ANY KIND, EXPRESS OR IMPLIED, AS TO THE OPERATION OF THE SITE, SERVICE OR THE INFORMATION, CONTENT, MATERIALS OR ANY PRODUCTS OR SERVICES INCLUDED THEREIN. SOME JURISIDICTIONS DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES, SO THE ABOVE EXCLUSION MAY NOT APPLY TO YOU. YOU HAVE THE SOLE RESPONSIBILITY FOR ADEQUATE PROTECTION AND BACKUP OF YOUR DATA OR CONTENT AND/OR YOUR EQUIPMENT USED IN CONNECTION WITH THE SERVICE.