Cybersecurity Maturity Model Certification (CMMC v2.0)
Simplifying CMMC Compliance
Defense Industrial Base (DIB) contractors and organization seeking compliance(OSCs)that handle CUI must act now to ensure compliance with the new CMMC v2.0
WHAT IS CMMC v2.0?
What does CMMC mean for your business?
|
Who must comply with CMMC guidelines?
ALL FEDERAL CONTRACTORS foreign and domestic delivering DoD products and services.
Primes and subcontractors.
With CMMC, rolling out in expedited fashion-
Why the Interim Rule and why NOW?
|
DFARS Interim Rule
"CMMC certification is your Driver’s License on the Information Superhighway." |
Coming lay-in of CMMC 2.0 has added new contracting requirements: Three New Provisions:
SPRS
|
CMMC 2.0 - WHAT WE KNOW
|
Cybersecurity Maturity Model Certification v2.0
Cybersecurity Maturity Model Certification 2.0
- Self-assessment at CMMC Maturity Level 1; this is self-attestation
- Self-assessment allowed annually for CMMC ML2 contractors, but a formal 3rd party assessment by a C3PAO is required every 3-years.
- Limited Plan of Action and Milestones (POAMs) and Waivers allowed
- These will only be temporary waivers and will be difficult to attain.
- The parameters for POAMS and waivers will be defined during the rulemaking stage, but OSCs will not be allowed to POAM the “heavily-weighted” controls.
- POAMs are allowed under CMMC 2.0, for a 180-day period.
- DoD certifications at CMMC Maturity Level 3 –an increased responsibility/role
- Contractors are encouraged to comply with “heavily-weighted” NIST controls as soon as possible to be positioned for deluge of CUI being released under coming procurements
Benefits of NIST and CMMC Compliance
|
|
|
CMMC 2.0 Takeaways
- POAMs have changed DRAMATICALLY; now good for 180 days.
- Most “heavily- weighted of the 110 controls” cannot be part of a POAM. Suggest identify these and commence maturity!
- Prescription to comply with NIST SP 800-171 is found in almost 100 % of DoD Prime & Subcontracts
- If so when you sign your contract you are self-attesting compliance with both FAR 52.204-21 and DFARS 252.204-7012.
- Controlled Unclassified Information (CUI) will become routine in most procurements; expect a “flood” of CUI.
- To gain access to CUI it will likely require the right Maturity Level or SPRS Score.
- DOD primes will be the Strictest enforcers of NIST SP 800-171, latest revision. (per DFARS cites)..
- If you rely on a 3rd Party MSP, that does not relieve you of compliance in any manner; suggest early meetings with MSP to discuss responsibilities and roles. MSPs must be DFARS, CMMC, NIST conversant!
To learn more about What is CMMC, The Guidelines and Certification
Learn how you can secure your government contract and become CMMC v2.0 certified: CMMC v2.0 Preparedness with CMMC Certified Petronella Tech (RPO) The price of the formal CMMC v2.0 audits is not currently known, here at PTG, we have extensive experience implementing other similar requirements for contractors; requirements that are the backbone of the CMMC maturity levels, including NIST SP 800-171, NIST SP 800-172, NIST SP 800-53, DFARS 252.214-7012, 252.214-7019, 252.214-7020, etc. |
PTG has developed a unique approach in helping your company get 80% of the work done to prepare for the upcoming CMMC audits. |
PTG offers multiple options to fit every defense contractor's needs and budget. |