DoD’s Cybersecurity Maturity Model Certification Is Here: What Your Business Needs to Do to Prepare

Faegre Drinker Biddle & Reath LLP
Contact

Faegre Drinker Biddle & Reath LLP

As of September 2020, contractors with the Department of Defense (DoD) will be required to comply with the recently released Cybersecurity Maturity Model Certification (CMMC) requirements. The CMMC requirements are designed to ensure that suppliers, contractors and subcontractors working with the DoD’s Office of Acquisition and Sustainment have cybersecurity frameworks in place “to assess and enhance the cybersecurity posture of the Defense Industrial Base (DIB).”

The CMMC model delineates five “maturity” levels, with level one being the lowest level of maturity and level five being the most secure. Once the CMMC takes effect, DoD will assign all solicitations a maturity level that your company must meet if it wishes to bid on the solicitation.

To make matters more challenging, contractors and subcontractors also will have to meet 17 “security domains” within each of the five maturity levels of the CMMC. Depending on the level of maturity your business wants to achieve, it could be required to comply with up to 171 cybersecurity requirements in order to meet CMMC certification guidelines. These maturity levels are also cumulative, meaning that if you want to certify at level three under the CMMC requirements, you would also have to comply with the requirements of levels one and two. The level of maturity that you may wish to obtain will be based on the amount of sensitive data and “CUI” (Controlled Unclassified Information or unclassified data still requiring safeguarding) that your company works with or plans to work with as a DoD contractor or subcontractor. Through the creation of the CMMC, DoD seems to be enhancing the requirements of NIST 800-171 and other cybersecurity-related frameworks.

One of the biggest changes with the CMMC requirements is that they prevent contractors and subcontractors from “self-assessing” cybersecurity readiness. Under the CMMC, contractors will need to have an official, independent third-party assessment company (C3PAO) conduct on-site inspection to ensure that it is in strict compliance with the CMMC. Failure to comply with the requirements of the maturity level you wish to achieve renders the contractor unable to bid on new DoD solicitations. There are currently over 300,000 DoD contractors and subcontractors in the United States and abroad that will need to come into CMMC compliance with these new guidelines. Although the CMMC guidelines do not appear to be retroactive at this time, DoD solicitations will begin referring to CMMC requirements as early as June 2020, and the requirements will become mandatory in September 2020. The time for preparation is now.

If you are one of the affected contractors, experienced legal counsel can be instrumental in preparing for the C3PAO process. We have prepared an assessment and compliance tool to assist businesses in achieving maturity levels one through five. This tool helps contractors to develop the necessary policies, procedures and gap analysis required to comply with the DoD CMMC requirements and to pass C3PAO accreditation inspection.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Faegre Drinker Biddle & Reath LLP | Attorney Advertising

Written by:

Faegre Drinker Biddle & Reath LLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

Faegre Drinker Biddle & Reath LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide