|
CMMC is here!
It’s official, on December 16, 2024, the federal rule that authorizes the CMMC program took effect.
From a regulatory perspective, CMMC requirements are covered by two Parts of the Code of Federal Regulations (CFR). Part 32 authorizes and implements the program; this is the rule that went into effect on December 16th. In addition to the Part 32 rule there is a Part 48 rule. Part 48 may be better known as the Federal Acquisition Regulations (FAR). The Part 48 rule addresses how CMMC will be incorporated into Department of Defense Contracts. The Part 48 rule is expected to go into effect early in 2025.
What does the Part 32 Final Rule do?
This final rule published in the federal register at Federal Register :: Cybersecurity Maturity Model Certification (CMMC) Program allows the DOD to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Additionally, the mechanisms discussed in the rule allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance.
CMMC Level - Assessment type and information type covered.
-
Level 1 (Assessment type: Self) required for FCI*
-
Level 2 (Assessment type: Self or C3PAO) required for CUI *
-
Level 3 (C3PAO and DIBCAC) required for highly sensitive CUI*
- *Assessment results are uploaded to the SPRS database.
Arguably, in today’s world, cybersecurity should be an active part of every business’ culture and operations. Cybersecurity should begin with senior staff acting as champions and supporting needed initiatives. Cybersecurity should be seen as a valuable business process rather than viewed as a necessary evil.
Unfortunately, general cybersecurity efforts have shown that they are not sufficient to provide adequate protection for DoD information such as FCI and CUI. CMMC applies to primes subcontractors and suppliers at any tier when either FCI or CUI information is generated, used or stored. Therefore, companies that are either actively part of the Defense Industrial Base (DIB) or considering entering the DIB must understand their responsibilities under the CMMC program and implement and maintain the required security measures.
|