Contracts
CMMC's Phase 2 suspension locked in with binding regulation
A new class deviation moves the pause on third-party assessments for this security standard from policy to an enforceable rule.
Opinion
CMMC phase II is paused, but the adversary threats are not
Contractors still holding sensitive defense data need visibility, segmentation, and containment — CMMC or not.
Contracts
CMMC's paradox: Scores are up, but confidence is down
As the cyber standard's third-party assessments are on pause, new research shows contractors’ self-reported scores are climbing even as their confidence in those ratings is sliding fast.
Opinion
CMMC works. Now let’s sharpen it.
Katie Arrington, who led the creation of the Cybersecurity Maturity model Certification, writes that the requirements behind the cyber and supply chain security standard should not change.
Opinion
CMMC’s pause isn’t a cancellation
Contractors still have obligations, self-assessments and False Claims Act exposure aren't going anywhere, writes Perry E. Keating, president of Protiviti Government Services.
Opinion
CMMC Phase 2 is suspended but the requirements are not
Contractors supporting the department’s most sensitive missions still must be prepared to prove their cybersecurity posture, writes Jason Sproesser of Summit 7.
Podcasts
WT 360: Our breakdown of the federal CIO’s departure, OneGov’s future and whatever CMMC will look like
NextGov/FCW’s executive editor Jessie Bur joins Nick and Ross to go around the world of Fed Tech, starting with the federal chief information officer’s pending exit and ending with the CMMC security standard’s murky future.
Contracts
CMMC suspension caught industry off guard, but the reasons did not
The Pentagon's move to pause the cybersecurity program was a surprise, but the cost and burden concerns behind it have been known for years.
Opinion
Not again! CMMC's comprehensive review is déjà vu all over again
Eight years, multiple pauses, and still no cyber protection to show for it — maybe it's time to move past CMMC, not review it again, writes former PSC President David Berteau.
Contracts
DOD suspends CMMC Phase 2, launches 60-day ‘reform’ review
Citing prohibitive costs for small and mid-size contractors, the Defense Department will keep Phase 1 self-assessments in place while a new task force studies the cyber and supply chain security program's future.
Opinion
The real reason CMMC costs are shocking companies
It's not the certification. It's the years of delayed compliance finally coming due, writes Redspin’s Thomas Graham.
Contracts
Army's NCODE pilot takes shape with eight-company cyber pool
The $49 million contract gives defense small businesses a secure, Pentagon-funded cloud environment to work on CMMC and other security requirements.
Opinion
FedRAMP and CMMC compliance deadlines are looming
Federal contractors have less than six months to get their cybersecurity houses in order — or risk losing access to government work, writes immixGroup’s Amanda Mull.
Opinion
Stop trying to prevent every cyberattack. Start planning to survive one.
Iran-linked intrusions targeting defense software suppliers are a wake-up call for agencies and contractors, writes Gary Barlet, public sector CTO at Illumio.
Opinion
What you need to know about GSA's new CUI security framework
The implications of GSA's new IT security guidance are significant and is a different approach to protecting controlled unclassified information than DOD's CMMC standard, writes Summit7's Jacob Horne.
Opinion
The CMMC compliance gap is now a competitive risk
As enforcement ramps up and primes tighten supplier requirements, contractors face a choice: prepare now or lose access to DOD work.
Contracts
CMMC enforcement begins with mixed industry readiness
A new survey finds two-thirds of contractors prepared for the cybersecurity certification over many years, while nearly 40% have not yet completed required self-assessments.
Contracts
CMMC enforcement begins after eight years of warnings
"There is no excuse for industry to not be ready," observers say as enforcement begins.
Opinion
The CMMC bottleneck: When compliance demand outpaces capacity
With only 366 certficiations completed and mandatory rollout beginning in less than two weeks, defense firms need smarter tools to meet cybersecurity requirements without breaking the bank, writes Steven Hess, CEO, Deep Fathom.
Opinion