The DFARS rule implementing the Cybersecurity Maturity Model Certification (CMMC) takes effect today, allowing CMMC requirements to be included in US Department of Defense solicitations and contracts.
Key points
- Phase 1 of the rollout begins, focused initially on Level 1 and Level 2 self-assessments.
- Contractors must have their CMMC status recorded in the Supplier Performance Risk System before award.
- Requirements flow down to subcontractors handling federal contract information or controlled unclassified information.
- Third-party Level 2 assessments will become a requirement in later phases.
UK organisations in the US defence supply chain should expect primes to ask for evidence of CMMC status and NIST SP 800-171 compliance.
Source: DFARS CMMC final rule (Federal Register)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.