
Since the United States Department of Defense (DoD) published multiple cybersecurity-related interim rules in late 2020, industry has been anxiously waiting for updated guidance on how the proposed Cybersecurity Maturity Model Certification program will be updated. Over a year after the publication of those interim rules, DoD submitted an “Advance notice of proposed rulemaking” to the Federal Register dated November 1, 2021. The unpublished document, entitled “Cybersecurity Maturity Model Certification 2.0 Updates and Way Forward”, which you can be viewed via the link below, sets forth significant changes to the CMMC program, including:
- Eliminating levels 2 and 4 and removing CMMC-unique practices and all maturity processes from the CMMC Model;
- Allowing annual self-assessments with an annual affirmation by DIB company leadership for CMMC Level 1;
- Bifurcating CMMC Level 3 requirements to identify prioritized acquisitions that would require independent assessment, and non-prioritized acquisitions that would require annual self-assessment and annual company affirmation;
- CMMC Level 5 requirements are still under development;
- Development of a time-bound and enforceable Plan of Action and Milestone process; and,
- Development of a selective, time-bound waiver process, if needed and approved.
However, as of 11:15 AM eastern on November 4, 2021, the document has been withdrawn from the Federal Register (see Federal Register :: Public Inspection: Cybersecurity Maturity Model Certification 2.0 Updates and Way Forward).
DoD has, however, published a “CMMC 2.0” update to the DoD Acquisition and Sustainment website (OUSD A&S – Cybersecurity Maturity Model Certification (CMMC) (osd.mil)). We will provide additional updates as they become available.
- Reforming CMMC and Reducing Compliance Burden for the DIB
- False Claims Act in 2025 – Key take-aways
- CUI Institute Public Comments on FAR CUI Rule
- CMMC: A National Imperative
- Disseminating CUI to Someone Else (e.g., Mary)
- CUI Recipient Preparedness Questionnaire
- CUI and CMMC in a Nutshell
- Mavis’s Machine Shop Attributes (Employees, Roles, Teams)
- Mavis’ Machine Shop Written Information Security Policy
- Mavis’ Machine Shop Data Breach and Incident Response Policy and Plan
- Mavis’ Machine Shop Network Diagram
- Mavis’ Machine Shops Site 2 Data Flow Diagram
- Mavis’ Machine Shops Site 2 Map
- Mavis’ Machine Shop Site 1 Map
- Protecting the Government’s Information – Version 2023.03a
- 3.11.2 – Vulnerability Scans (Kevin Mann)
- CMMC: Budgets, Competition, and Protests…Oh My! (Eric Crusius and Josh Duvall) – Slides
- CMMC Workflow: Pre-Kickoff to Done (Thomas Graham and Robert Teague) – Slides
- 3.14.1 – Flaw Remediation (Thomas Graham) – Slides
- 3.1.11 – Terminate (Automatically) a User Session After a Defined Condition (Robert Teague) – Slides
- Evidence & Path to Compliance (Regan Edens) – Slides
- CMMC in Higher Education (Amy Starzynski Coddens, Jason Pufahl, Mike Corn) – Slides
- Techniques for Assessing a Remote Work Environment (Tara Lemieux) – Slides
- v2023.02a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- Standardizing the Assessment Experience (Ben Tchoubineh) – Slides
- Helping Business Leaders to care about Cybersecurity (Ace Swerling) – Slides
- Gap Assessment Workflow (Leia Shilobod) – Slides
- Shared Responsibility Matrices (Carley Salmon and Robert McVay) – Slides
- Scoping your Environment (Matt Titcombe) – Slides
- Pricing Gap Assessments (Toby Musser) – Slides
- 3.11.1 Risk Assessments (Robert McVay) – Slides
- 3.5.3 Multifactor Authentication (Fernando Machado) – Slides
- Practical Approaches to Testing CMMC Compliance (Kyle Lai) – Slides
- 3.1.3 Controlling CUI Flow (Matt Hoeper) – Slides
- 3.14.1 Flaw Remediation (Thomas Graham) – Slides
- Finding Prep Expertise and a C3PAO (Joy Beland) – Workbook
- Finding Prep Expertise and a C3PAO (Joy Beland) – Slides
- OLD – v2022.11a – FAR and Above and NIST SP 800-171 Self-Assessment DoD Score Tool
- v.2021.10a – The CMMC Assessment Lifecycle
- OLD – v2022.08d – Comprehensive FAR and Above and NIST SP 800-171 Self-Assessment and DoD SPRS Scoring Tool
- OLD – FAR and Above Phased Approach to NIST SP 800-171 and CMMC Compliance
- Policy – Client Data Breach Incident Response Policy
- Plan – Client Data Breach Incident Response
- List – Processes Authorized to Act on Behalf of a User
- List – Employees and Authorized Users
- List – Authorized Visitors
- Worksheet – Client Data Breach Incident Response
- Record – Meeting Agenda
- Procedure – Employee Offboarding
- Policy – Nondiscrimination and Anti-Harassment
- Policy – Information Systems Audit
- Policy – Data Protection
- Open Letter to the President Regarding CMMC 2.0
- US DoD 2021-NOV-04 – Cybersecurity Maturity Model Certification 2.0 Updates and Way Forward
- DFARS Clause Applicability Decision Tree
- The CMMC Assessment Lifecycle – OLD
- Paper and Electronic Media (“Media”) Certificate of Destruction/Sanitization
- C3PAO ISO 17020 and 17021 Slides – Part 3
- C3PAO ISO 17020 and 17021 Slides – Part 2
- C3PAO ISO 17020 and 17021 Slides – Part 1
- DCMA C3PAO CMMC Assessment Lessons Learned
- CMMC-AB Statement of Work
- CUI Disclosure Decision Trees
