Don’t do SECURITY. Do business SECURELY.

US Cybersecurity Maturity Model Certification program rule takes effect

The CMMC Program rule is now in effect, establishing the certification framework for US Department of Defense contractors handling controlled information.

The Cybersecurity Maturity Model Certification (CMMC) Program rule, 32 CFR Part 170, takes effect today, formally establishing the US Department of Defense’s certification scheme for its supply chain.

Key points

  • CMMC has three levels: Level 1 (self-assessment), Level 2 (based on NIST SP 800-171) and Level 3 (additional NIST SP 800-172 controls).
  • Most Level 2 contractors will need an independent assessment by an accredited third-party assessment organisation.
  • Limited plans of action and milestones are permitted, with a 180-day close-out period.
  • Contract requirements will follow in a separate DFARS rule.

UK defence suppliers handling US controlled unclassified information, directly or through US primes, should assess their readiness against NIST SP 800-171 now.

Source: CMMC Program final rule, 32 CFR Part 170 (Federal Register)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights