The Department of Defense’s long-awaited cybersecurity compliance policy cleared the regulatory review process, moving toward Congressional review before it becomes law. The Office of Information and Regulatory Affairs (OIRA) cleared the final rule for the DoD’s Cybersecurity Maturity Model Certification (CMMC) program on Sept. 13, meaning no further changes can be made unless the House, Senate, and president decide to overturn it – an unlikely scenario. The final rule has been under OIRA’s review since late June.
The finish line is in site, as the CMMC final rule becomes law and becomes effective immediately after the 60-day Congressional review. For defense contractors handling CUI, this is your time to get started if you intend to stay in the defense contracting arena.
*New update since this was posted! On October 15th the DoD published the final rule for the Cybersecurity Maturity Model Certification (CMMC) Program. The DoD’s follow-on DFARS rule change to implement CMMC will be published in early to mid-2025 at which time the DoD will include CMMC requirements in solicitations and contracts.
Stay Positioned to Win Defense Contracts
With the CMMC rule expected to become law in Q4 and enter into contracts in early 2025, the law requires contractors to prove their CMMC compliance at the time of award. It will also require verification by contracting officers that all defense contractors have their CMMC compliance posted in the Supplier Performance Risk System (SPRS).
Subcontractor Requirements: Be aware that DFARS 7012/ DFARS 7020 mandates that defense contractors pass all CMMC requirements onto their subcontractors. This means every subcontractor that you engage is required to be CMMC compliant if included on a defense contract.
One of the most notable implications of the CMMC is the gradual phase-in period, which is anticipated to begin as early as summer 2025. During this phase-in, the Defense Federal Acquisition Regulations Supplement (DFARS) clause 252.204-7021 will be incorporated into all solicitations, regardless of whether the procurement involves commercial items or services. This means that even for commercial items and services that are not considered Commercial Off-the-Shelf (COTS), CMMC security protections will be required.
Failure to meet these CMMC requirements will have serious consequences for contractors. Organizations that do not comply will be ineligible for new contracts and may even face the termination of existing contracts. To ensure compliance, contractors must flow down the CMMC requirements to their subcontractors and vendors at all tiers, based on the level of sensitive information they will be handling.
What’s are the Details of the New Proposed Rule?
The proposed changes aim to:
- Add references to the upcoming CMMC 2.0 regulation.
- Define key terms like Controlled Unclassified Information (CUI) and DoD Unique Identification (DoD UID).
- Set new rules for contracting officers to include in contracts.
- Update existing DFARS clause language and descriptions.
- Increase the need for subcontractor/vendor screening and proof of compliance.
Key Requirements for Contractors
Some of the requirements for contractors will include:
- Obtaining and maintaining the requisite CMMC level for the life of the contract.
- Submitting the DoD UIDs issued by SPRS for applicable contractor information systems to the Contracting Officer (CO).
- Requiring a senior company official to affirm continuous compliance with the CMMC level security requirements to be implemented at 32 CFR part 170.
- Notifying the CO of any changes in the contractor or subcontractor information systems that possess, store, or transmit Federal Contract Information (FCI) or CUI.
How Applied Technology Academy (ATA) Supports You
Implementing CMMC will necessitate a significant shift in cybersecurity practices for many DIB organizations. Contractors will need to invest in tools, training, and processes to achieve the required level of maturity. Additionally, they must establish robust supply chain security measures to ensure that their subcontractors and vendors meet CMMC standards.
Navigating the complexities of CMMC 2.0 compliance can be daunting, but Applied Technology Academy (ATA) is here to support you every step of the way. ATA offers authorized Cyber AB training programs designed to help you understand, implement and comply with the DoD’s CMMC requirements, led by industry experts who provide practical insights and hands-on experience.
Best in Class Cyber AB CMMC Training
We reviewed all of the approved Licensed Publishing Partner (LPP) course materials, vetted and assigned the best instructors, implemented our own CMMC compliance assessment (we walked the talk first) and launched our first CMMC courses almost 3 years ago. We have been on the journey with the DoD since inception of the CMMC initiative! Learn more about our Authorized Cyber AB courses:
Certified CMMC Professional (CCP)
Becoming a Certified CMMC Professional (CCP) can significantly enhance your career in cybersecurity. The certification demonstrates your expertise in the Cybersecurity Maturity Model Certification (CMMC) framework, which is crucial for organizations working with the U.S. Department of Defense. As a CCP, you’ll be equipped to help companies meet stringent cybersecurity requirements, making you a valuable asset in the industry. Additionally, this certification can open doors to new job opportunities, higher salaries, and greater professional recognition. If you’re looking to advance your career and make a meaningful impact in cybersecurity, the CCP certification is a great step forward. Learn more about Certified CMMC Professional (CCP)
Delivery Options: 5-Day Boot Camp, 10-Night Evening Course or On Demand
Certified CMMC Assessor (CCA)
Pursuing the Certified CMMC Assessor (CCA) certification can elevate your career by positioning you as an expert in evaluating and certifying organizations against the CMMC standards. As a CCA, you’ll play a critical role in ensuring that companies meet the necessary cybersecurity requirements to protect sensitive information. This certification not only enhances your credibility and professional standing but also opens up opportunities to work with a variety of organizations, including those in the defense sector. By becoming a CCA, you’ll be at the forefront of cybersecurity compliance, making a significant impact on the security landscape. Learn more about Certified CMMC Assessor (CCA)
Delivery Options: 5-Day Boot Camp, 10-Night Evening Course or On Demand
Key Course Differentiators
- Cyber AB Licensed Training Provider: We are proud to offer the Cyber AB Authorized Certified CMMC Professional and Certified CMMC Assessor training courses.
- Expert Instructors: All our instructors are active practitioners and subject matter experts, focused on ensuring you receive superior education and guidance.
- Authorized Courseware: We vetted all of the Authorized LPP courseware and chose the best, guaranteeing that our training meets the highest standards of excellence.
- Flexible Scheduling: Our flexible scheduling options that allow you to choose the best training format for you. We offer daytime and evening courses for Online Live or Onsite deliveries. We also have On Demand resources for learning at your own pace.
- On-Demand Course Videos: Follow up with on-demand videos to reinforce your learning and provide continuous support.
- 5-Star Rated Student Support: Our student support is rated 5-stars across Google, ensuring you have the help you need whenever you need it.
Take Action Now
With the proposed rule changes, it’s crucial to start preparing for CMMC 2.0 compliance now. ATA is here to support you every step of the way. Start with the CPP course to make sure you have your internal subject matter experts in place!
Stay ahead of the curve with ATA! Contact us today to learn more about how we can support your cybersecurity needs and help you navigate the complexities of CMMC 2.0 compliance.