Eight years, multiple pauses, and still no cyber protection to show for it — maybe it's time to move past CMMC, not review it again, writes former PSC President David Berteau.
Citing prohibitive costs for small and mid-size contractors, the Defense Department will keep Phase 1 self-assessments in place while a new task force studies the cyber and supply chain security program's future.
Federal contractors have less than six months to get their cybersecurity houses in order — or risk losing access to government work, writes immixGroup’s Amanda Mull.
Iran-linked intrusions targeting defense software suppliers are a wake-up call for agencies and contractors, writes Gary Barlet, public sector CTO at Illumio.
The implications of GSA's new IT security guidance are significant and is a different approach to protecting controlled unclassified information than DOD's CMMC standard, writes Summit7's Jacob Horne.
A new survey finds two-thirds of contractors prepared for the cybersecurity certification over many years, while nearly 40% have not yet completed required self-assessments.
With only 366 certficiations completed and mandatory rollout beginning in less than two weeks, defense firms need smarter tools to meet cybersecurity requirements without breaking the bank, writes Steven Hess, CEO, Deep Fathom.
COMMENTARY | Stricter government cybersecurity requirements present elevated risk to companies due to increased enforcement pressure and additional bases for allegations of cybersecurity fraud.
By Moriah Daugherty, Ryan Burnette, Ashden Fein, Susan Cassidy and Peter Hutt II
Jacob Horne, chief cybersecurity evangelist at Summit 7, writes that the defense industry is wrong to believe the bedtime story about a 12-month certification delay. Here's what program manager discretion really means.
Full implementation of the standard takes effect in a month. In the meantime, a new study shows a compliance gap that could lock unprepared contractors out of defense contracts while cyber vulnerabilities persist.
CMMC is not the holy grail of supply chain risk management, but it is one of the most effective tools for validating that information security vulnerabilities are being addressed, writes CMMC expert Aron Freitag.
With mandatory third-party audits now in effect, government contractors must act quickly to meet stricter cybersecurity standards or risk losing DoD contracts, writes Aprio’s Raj Raghavan.
The defense industry is mourning the loss of a legal expert, widely known as the "Godfather of CMMC," whose work on supply chain security helped shape national standards.
Arrington, who was once accused of disclosing classified data, was a major proponent of the Cybersecurity Maturity Model Certification program used for DOD contractors.
Quantum computing is on the horizon bringing with it a new set of cybersecurity challenges. Government contractors must prepare now for encryption and other concerns.
The cybersecurity certification will move forward even as companies continue to have questions about what defines controlled but unclassified information, cloud services and other requirements.