On September 4, the office of the Assistant Secretary of Defense for Acquisition released Version 0.4 of the draft Cybersecurity Maturity Model Certification (CMMC) for comment. Under this model, Defense contractors, including subcontractors, will be required to be certified among the different CMMC levels (1-5) in order to be eligible for contract award. The level of security is determined based on the security requirements needs for each defense contract. A departure from previous cybersecurity mandates, CMMC will require contractors to obtain a third-party certification. Public comments are due on September 25th. According to DOD website, the CMMC model will continue to be improved over the next several months with the collaboration of all the stakeholders with the finalization of v1.0 in January…
Read More