Blog

4
Feb
CMMC Compliance

CMMC compliance is not designed to be a one-size-fits-all system. CMMC offers five different levels of compliance and contract requirements will dictate what is required for a project. The levels rise in complexity and requirements from Level 1 through Level 5. Level 1 represents the same requirements as FAR 52.204-21, Basic Safeguarding of Covered Contractor […]

29
Jan
CMMC Compliance

The Cybersecurity Maturity Model Certification regime from the Department of Defense is now a required threshold for defense contractors and contains five distinct levels of compliance. Compliance must be certified by a third party auditor — self-attestation isn’t enough — and there are five separate levels of compliance. Level III, the most common level that […]

27
Jan
CMMC Compliance

Right now, the Department of Defense says that CMMC certifications will remain valid for three years. So, there will be a need for re-assessment and new certification at three year intervals. There is the possibility that this period for required renewals will change as DoD sees the system work in practice.

22
Jan
CMMC Compliance

No. CMMC (Cybersecurity Maturity Model Certification) is solely a Department of Defense initiative. Many of the CMMC requirements will, of course, overlap with other non-Defense federal cybersecurity hygiene requirements. But the CMMC model and testing is a purely Defense oriented protocol.

20
Jan
CMMC Compliance

The Department of Defense is planning a phased rollout of CMMC requirements over the next several years. As CMMC requirements are issued on a per-contract basis, the phased rollout is defined as a steady increase in yearly prime contracts requiring a CMMC certification for contractors. The number of contracts scheduled to have CMMC requirements in […]

16
Jan
CMMC Compliance

CMMC (Cybersecurity Maturity Model Certification) compliance is causing many defense contractors to feel overwhelmed. The cybersecurity space is filled with jargon, the model presents different levels of security for different vendors and there appear to be a lot of specific requirements. The first step is simply to figure out where you currently stand. And the […]