Dod Cmmc Certification
The department of defense is drafting a new standard called the cybersecurity maturity model certification.
Dod cmmc certification. The department of defense dod recently announced the development of the cybersecurity maturity model certification cmmc a framework aimed at assessing and enhancing the cybersecurity posture of the defense industrial base dib particularly as it relates to controlled unclassified information cui within the supply chain. The maturity levels for nist 800 171cmmc compliance. 1 good for certification up to cmmc level 3 and there is currently not a self assessment handbook for nist sp 800 171 rev. Katie arrington special assistant to the assistant secretary of defense for acquisition for cyber gave a presentation to small dod contractors on may 23 2019 to announce a new program which will require cyber security audits and certification for all dod contractors.
This standard will replace nist 800 171 on dod rfis and rfps beginning in mid 2020 1the cmmc contains five levels ranging from basic hygiene to state of the art. Come back for updates. This shortcoming has led to the devising of the cybersecurity capability model certification which will. The cybersecurity maturity model certification or cmmc is the next stage in the department of defenses dod efforts to properly secure the defense industrial base dib.
Some questions have been answered some are still to come but we should see more clarity with the cmmc model version 10 which is to be released in late january 2020. Exostar a leader in supply chain cybersecurity has compiled a well stocked repository for related information. The department of defense is launching a new certification for the defense industrial base dubbed cmmc cybersecurity maturity model certification. Updated 112919 how will the cybersecurity maturity model certification cmmc affect those who do business with the department of defense dod.
Dod contractors who provide products and services for the department of defense. Welcome to the official website of the office of the under secretary of defense for acquisition and sustainment ousdas. Unfortunately this handbook only covers nist sp 800 171 rev. This handbook was created by nist with the intention of assisting us.
The department of defense currently mandates that its contractors meet the requirements of nist special publication 800171 but there is no audit and accountability for protecting cui. Dod contractors will need to coordinate directly with an accredited independent commercial certification organization to request and schedule a cmmc assessment.