CMMC Rule Clears OIRA Review

Although the United States Department of Defense’s Cybersecurity Maturity Model Certification (“CMMC”) program was previously the subject of a regulatory review process in 2020, DoD decided in 2021 to retool the program before it was fully in effect. DoD has been working on corresponding revisions to the Defense Federal Acquisition Regulations Supplement (“DFARS”) ever since. (more…)

This entry was posted in and tagged . Bookmark the .

DoD Adding New Arrows to Contracting Officers’ Quivers (via SPRS)

DoD published a notice that DFARS 252.204-7024 will soon be published. This new clause requires contracting officers to consider supply chain risk and SPRS-reported risk information, as part of the award decisions. Click through for additional information!

Certified CMMC Assessor Program Update

2023 is shaping up to be a HUGE year for the CMMC program! DoD closed out 2023 by kicking off the “Joint Surveillance Program” (“JSP”) assessments of some DoD contractors, and many more are scheduled for 2023. If you aren’t familiar with the JSP assessments, they are voluntary assessments that are led by DoD’s DIBCAC (more…)

Pentagon’s Joint Surveillance Program in Full Swing

The United States Department of Defense (“DoD”) has begun its “Joint Surveillance Program” in conjunction with the CyberAB, the organization tasked with overseeing the CMMC ecosystem. Under the Joint Surveillance Program, members of DoD’s Defense Industrial Base Cybersecurity Assessment Center (“DIBCAC”) accompany and oversee representatives from CyberAB authorized Certified 3rd Party Assessment Organizations (“C3PAOs”) as (more…)

CMMC 2.0 Model and Scoping Guide Now Available

The US Department of Defense updated their main website (OUSD A&S – Cybersecurity Maturity Model Certification (CMMC) (osd.mil)) to include an updated CMMC Model consistent with the information released on Nov. 4 about CMMC 2.0. They also released scoping guidance for CMMC 2.0 Levels 1 and 2, and a hashing approach for preserving evidence. Among (more…)

Coming in September: Final CMMC DFARS Rule and More

Changes to the FAR/DFARS imposed by the recent Executive Order on Increasing our Nation’s Cybersecurity and the expected publication of the Final Rule for CMMC are now both expected in September, although the exact dates are still unknown. With all the expected changes, October promises to be a very busy time for defense contractors!