Preparing for compliance audits, especially under the rigorous requirements of the Cybersecurity Maturity Model Certification (CMMC), can be exhausting.Audit fatigue
As the CMMC Final Ruling and Implementation progresses, many organizations are left wondering what to expect in the coming months, and 2025. Recently, it was confirmed that the CMMC Final Rule is near completion and was submitted for final review. In the waiting period for publication, we wanted to provide a quick guide on what organizations need to know and how to prepare for the upcoming developments!
The updates to the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, and SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, is a clear indicator the federal government has every intention of modernizing the security requirements developed to protect the confidentiality of CUI when this sensitive information resides within nonfederal organizations and organizational systems.
On December 26th, 2023, the DoD published a 60-day comment period for a proposed Cybersecurity Maturity Model Certification (CMMC) rule. Together, with contributions from the 60-day comment period, the DoD published a proposed final rule.
This rule addresses many concerns organizations had with the 2020 CMMC Legacy Model, CMMC Version 1.0, by allowing self-assessment for some programs and plans of actions and milestones (POA&Ms) for others, and further simplifying CMMC from five CMMC levels to only three (CMMC Level 1, 2, 3). This new model allows government officials to leverage a CMMC waiver request process for rare programs and offerors. The waiver can only be originated by the DoD Program Manager, not the DIB.
One of the proposed rule’s biggest wins is its direct alignment with NIST SP 800-171 and 800-172 (CMMC Level 3).
The CMMC final rule and its implementation timeline highlight the evolution and future direction of cyber risk management and governance for defense contractors. We further explore the critical historical and future milestones and updates in the journey toward enhanced cyber compliance within the defense sector.
CMMC Versions
The CMMC framework has undergone several iterations to refine its requirements. In November 2020, CMMC v1 was published, followed by significant changes announced in December 2021 with the introduction of CMMC v2.
Proposed Timeline for the CMMC Final Rule
The proposed timeline for the CMMC final rule includes several key milestones:
CMMC Phased Approach
The CMMC implementation will follow a phased approach:
Recently the DoD has officially submitted the 32 CFR CMMC program rule and all supporting documentation for final review. This means that once approved, the next step in the Final Rule Stage is publication. After publication and the prescribed adherence period, organizations will be expected to meet the requirements of the official, final CMMC Program Rule.
The CMMC framework and its phased implementation timeline reflect the DoD’s commitment to enhancing cybersecurity across the defense industrial base. Defense contractors must stay informed and prepared to meet these evolving requirements, ensuring their systems and practices are strong, tested, and nimble enough to adjust to the constant changes in the regulatory landscape and overcome the many complexities we have yet to face.
Sources:
Preparing for compliance audits, especially under the rigorous requirements of the Cybersecurity Maturity Model Certification (CMMC), can be exhausting.Audit fatigue