The Cybersecurity Maturity Model Certification (CMMC) Program rule, 32 CFR Part 170, takes effect today, formally establishing the US Department of Defense’s certification scheme for its supply chain.
Key points
- CMMC has three levels: Level 1 (self-assessment), Level 2 (based on NIST SP 800-171) and Level 3 (additional NIST SP 800-172 controls).
- Most Level 2 contractors will need an independent assessment by an accredited third-party assessment organisation.
- Limited plans of action and milestones are permitted, with a 180-day close-out period.
- Contract requirements will follow in a separate DFARS rule.
UK defence suppliers handling US controlled unclassified information, directly or through US primes, should assess their readiness against NIST SP 800-171 now.
Source: CMMC Program final rule, 32 CFR Part 170 (Federal Register)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.