Contracts

CMMC's Phase 2 suspension locked in with binding regulation

A new class deviation moves the pause on third-party assessments for this security standard from policy to an enforceable rule.

Opinion

CMMC phase II is paused, but the adversary threats are not

Contractors still holding sensitive defense data need visibility, segmentation, and containment — CMMC or not.

Contracts

CMMC's paradox: Scores are up, but confidence is down

As the cyber standard's third-party assessments are on pause, new research shows contractors’ self-reported scores are climbing even as their confidence in those ratings is sliding fast.

Opinion

CMMC works. Now let’s sharpen it.

Katie Arrington, who led the creation of the Cybersecurity Maturity model Certification, writes that the requirements behind the cyber and supply chain security standard should not change.

Opinion

CMMC’s pause isn’t a cancellation

Contractors still have obligations, self-assessments and False Claims Act exposure aren't going anywhere, writes Perry E. Keating, president of Protiviti Government Services.

Opinion

CMMC Phase 2 is suspended but the requirements are not

Contractors supporting the department’s most sensitive missions still must be prepared to prove their cybersecurity posture, writes Jason Sproesser of Summit 7.

Podcasts

WT 360: Our breakdown of the federal CIO’s departure, OneGov’s future and whatever CMMC will look like

NextGov/FCW’s executive editor Jessie Bur joins Nick and Ross to go around the world of Fed Tech, starting with the federal chief information officer’s pending exit and ending with the CMMC security standard’s murky future.

Contracts

CMMC suspension caught industry off guard, but the reasons did not

The Pentagon's move to pause the cybersecurity program was a surprise, but the cost and burden concerns behind it have been known for years.

Opinion

Not again! CMMC's comprehensive review is déjà vu all over again

Eight years, multiple pauses, and still no cyber protection to show for it — maybe it's time to move past CMMC, not review it again, writes former PSC President David Berteau.

Contracts

DOD suspends CMMC Phase 2, launches 60-day ‘reform’ review

Citing prohibitive costs for small and mid-size contractors, the Defense Department will keep Phase 1 self-assessments in place while a new task force studies the cyber and supply chain security program's future.

Opinion

The real reason CMMC costs are shocking companies

It's not the certification. It's the years of delayed compliance finally coming due, writes Redspin’s Thomas Graham.

Contracts

Army's NCODE pilot takes shape with eight-company cyber pool

The $49 million contract gives defense small businesses a secure, Pentagon-funded cloud environment to work on CMMC and other security requirements.

Opinion

FedRAMP and CMMC compliance deadlines are looming

Federal contractors have less than six months to get their cybersecurity houses in order — or risk losing access to government work, writes immixGroup’s Amanda Mull.

Opinion

Stop trying to prevent every cyberattack. Start planning to survive one.

Iran-linked intrusions targeting defense software suppliers are a wake-up call for agencies and contractors, writes Gary Barlet, public sector CTO at Illumio.

Opinion

What you need to know about GSA's new CUI security framework

The implications of GSA's new IT security guidance are significant and is a different approach to protecting controlled unclassified information than DOD's CMMC standard, writes Summit7's Jacob Horne.

Opinion

The CMMC compliance gap is now a competitive risk

As enforcement ramps up and primes tighten supplier requirements, contractors face a choice: prepare now or lose access to DOD work.

Contracts

CMMC enforcement begins with mixed industry readiness

A new survey finds two-thirds of contractors prepared for the cybersecurity certification over many years, while nearly 40% have not yet completed required self-assessments.

Contracts

CMMC enforcement begins after eight years of warnings

"There is no excuse for industry to not be ready," observers say as enforcement begins.

Opinion

The CMMC bottleneck: When compliance demand outpaces capacity

With only 366 certficiations completed and mandatory rollout beginning in less than two weeks, defense firms need smarter tools to meet cybersecurity requirements without breaking the bank, writes Steven Hess, CEO, Deep Fathom.

Opinion

Risks of cyber fraud allegations remain high for companies subject to government requirements

COMMENTARY | Stricter government cybersecurity requirements present elevated risk to companies due to increased enforcement pressure and additional bases for allegations of cybersecurity fraud.