As the cyber standard's third-party assessments are on pause, new research shows contractors’ self-reported scores are climbing even as their confidence in those ratings is sliding fast.
Katie Arrington, who led the creation of the Cybersecurity Maturity model Certification, writes that the requirements behind the cyber and supply chain security standard should not change.
Contractors still have obligations, self-assessments and False Claims Act exposure aren't going anywhere, writes Perry E. Keating, president of Protiviti Government Services.
Contractors supporting the department’s most sensitive missions still must be prepared to prove their cybersecurity posture, writes Jason Sproesser of Summit 7.
NextGov/FCW’s executive editor Jessie Bur joins Nick and Ross to go around the world of Fed Tech, starting with the federal chief information officer’s pending exit and ending with the CMMC security standard’s murky future.
Eight years, multiple pauses, and still no cyber protection to show for it — maybe it's time to move past CMMC, not review it again, writes former PSC President David Berteau.
Citing prohibitive costs for small and mid-size contractors, the Defense Department will keep Phase 1 self-assessments in place while a new task force studies the cyber and supply chain security program's future.
Federal contractors have less than six months to get their cybersecurity houses in order — or risk losing access to government work, writes immixGroup’s Amanda Mull.
Iran-linked intrusions targeting defense software suppliers are a wake-up call for agencies and contractors, writes Gary Barlet, public sector CTO at Illumio.
The implications of GSA's new IT security guidance are significant and is a different approach to protecting controlled unclassified information than DOD's CMMC standard, writes Summit7's Jacob Horne.
A new survey finds two-thirds of contractors prepared for the cybersecurity certification over many years, while nearly 40% have not yet completed required self-assessments.
With only 366 certficiations completed and mandatory rollout beginning in less than two weeks, defense firms need smarter tools to meet cybersecurity requirements without breaking the bank, writes Steven Hess, CEO, Deep Fathom.
COMMENTARY | Stricter government cybersecurity requirements present elevated risk to companies due to increased enforcement pressure and additional bases for allegations of cybersecurity fraud.
By Moriah Daugherty, Ryan Burnette, Ashden Fein, Susan Cassidy and Peter Hutt II
Jacob Horne, chief cybersecurity evangelist at Summit 7, writes that the defense industry is wrong to believe the bedtime story about a 12-month certification delay. Here's what program manager discretion really means.