News

32 CFR Final Rule for CMMC Explained

January 21, 2025

In an increasingly connected world, protecting sensitive information from malicious actors has become paramount, especially for organizations that are involved with defending our nation. The Department of Defense (DoD) has introduced the Cybersecurity Maturity Model Certification (CMMC) as a requirement to ensure that defense contractors and subcontractors, who are part of the Defense Industrial Base (DIB), meet minimum cybersecurity standards. The recently finalized CMMC final rule, went into into effect on December 16, 2024, requires security measures to be implemented based on the sensitivity of the data being handled to elevate the standard of cyber defenses across the board.

Key Takeaways from the CMMC Final Rule

Tiered Certification Levels

  • The CMMC program consists of three levels of certification. These levels ensure that cybersecurity safeguards are implemented in a way that scale according to the risk associated with the type of information being processed or stored.
    • Level 1: Requires compliance with 15 basic security requirements aligned with FAR 52.204-21. It is a self-assessment by the contractor and must be renewed annually.
    • Level 2: Requires compliance with 110 security requirements specified in NIST SP 800-171. Contractors can either conduct a self-assessment or be required to be assessed by a CMMC Third-Party Assessment Organization (C3PAO) based on the contract requirements. Assessments must be renewed every three years.
    • Level 3: Applies to the highest security requirements, adding selected controls from NIST SP 800-172 on top of level 2 requirements. The Defense Contract Management Agency (DCMA) conducts this assessment to confirm the organization’s ability to protect critical national security information.

Assessment and Certification

Each CMMC certification level will require assessments to ensure compliance with the required security standards. Self-assessments are recorded and submitted to the DoD's Supplier Performance Risk System (SPRS), while third-party assessments are conducted by authorized assessors (C3PAOs) and recorded into the CMMC Enterprise Mission Assurance Support Service (eMASS).

Companies are required to provide affirmation of their compliance after each assessment and annually after that, with full re-assessments required every three years for level 2 and 3.

Implementation Timeline

The DoD has taken a phased approach to implement CMMC requirements. Starting with self-assessments, this phased implementation will gradually require higher levels of assessments based on contract requirements, concluding in full implementation within four phases. This gradual rollout allows companies to understand and implement CMMC requirements over time.

Scope and Flow-Down Requirements

The final rule specifies that CMMC requirements will not only apply to prime contractors but also to subcontractors who handle FCI or CUI. Subcontractors will have to satisfy minimum CMMC levels based on the type of information they process, and prime contractors will be responsible for ensuring their subcontractors are compliant. This "flow-down" requirement ensures that cybersecurity practices are maintained consistently throughout the supply chain.

What to expect next?

The CMMC final rule imposes a higher standard of security requirements on contractors, which requires greater accountability and consistency across the supply chain. Contractors must prepare for the assessment process by developing robust security programs and maintaining compliance appropriate to the required CMMC level. This means that maintaining CMMC compliance is now a business requirement and failure to meet the required level of certification will result in losing eligibility for DoD contracts.

If your organization is looking to comply with the latest standards for CMMC, Idenhaus is here to assist you in this endeavor. Our experts have successfully implemented CMMC for organizations of all sizes. Go ahead and contact us with any questions you may have.

More News

Subscribe To Our Newsletter

Please send me the following content from Idenhaus:*
Select as many boxes as you'd like!
Idenhaus needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at any time. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, please review our Privacy Policy.