What is CMMC?


The days of NIST 800-171 self-attestation are gone.  CMMC requires an independent third-party audit and certification.

As Ms. Katie Arrington explains, the United States is losing $600 Billion a year in exfiltrations, data losses, and R&D losses to our adversaries.  Something had to change and that something was the creation of CMMC.

The DoD considers SECURITY to be the foundation of all acquisition practices.  Cost, performance, and schedule will only operate with a defense-in-depth foundation.  The DoD realized they required an agile and universal method for taking this idea and putting it into practice.  Cybersecurity is necessary for everyone doing business with the DoD, but this does not mean that all members of the Defense Industrial Base (DIB) will need the same level of security.  This is the beauty of the CMMC framework with its five levels of certification.

DoD CMMC calendar


DoD released CMMC v1.02 in March 2020.

DoD expects CMMC level requirements to begin appearing in RFIs in June 2020.

DoD expects CMMC level requirements to begin appearing in RFPs in September 2020.

Here are some more details about the DoD CMMC:

• The DoD vision for CMMC is that it be a unified cybersecurity standard for acquisitions to reduce exfiltration of CUI and Federal Contract Information (FCI).
• CMMC is a DoD certification process that measures a DIB company’s ability to protect FCI and CUI.
• CMMC combines various cybersecurity standards and maps these best practices and processes to maturity levels, ranging from basic cyber hygiene to highly advanced practices.
• Unlike NIST SP 800-171, CMMC will implement multiple levels of cybersecurity.  In addition to assessing the maturity of a company’s implementation of cybersecurity controls, the CMMC will also assess the company’s maturity/institutionalization of cybersecurity practices and processes.
• The required CMMC level (between 1 –5) for a specific contract will be contained in the RFP and will be a “go/no-go decision”.
• CMMC builds upon existing regulations (i.e. FAR 52, DFARS 252.204-7012) which are based on trust (self-attestation), but adds a verification component via the third-party audit, certifying one’s cybersecurity standards and maturity.
• The goal is for CMMC to be cost-effective and affordable for small businesses to implement, especially at the lower CMMC levels.
• The intent is for certified independent third-party organizations to conduct audits and inform risk [CMMC Third Party Assessment Organizations (C3PAOs)].
• The DoD established the Accreditation Body, which is the main monitor and controller of the CMMC framework and its implementation.
• The Accreditation Body will be in charge of training and monitoring the C3PAOs.
• The DoD is working with industry to create a tool for the C3PAOs to use in order to ensure uniformity across all certifications and certifiers.
• Certification will be a recurring requirement…the exact timeline is still unknown.
• CMMC is more than implementation, it is about process maturity.  DoD wants to see its industry partners grow and develop their security practices.

Check out the latest DoD Release here: Model v1.02 and Appendices

CMMC is more than just compliance - organizations should prepare now and not delay to avoid risking future contract opportunities. The first step is to assess current NIST implementation and fill any gaps that exist before the CMMC auditor arrives.

