
By Sajid Shafique
Sensitive data exfiltration from defense contractors is a major problem that threatens the national and economic security of the United States. Malicious cyber actors, often backed by Nation-state adversaries, continue to target organizations in the Defense Industrial Base (DIB) sector. To improve cybersecurity practices and protect sensitive information, the DoD has developed the Cybersecurity Maturity Model Certification (CMMC) 2.0 program as a crucial update for defense contractors.
As organizations assess their compliance with CMMC 2.0, here are the top 10 questions they often ask:
1 - What is CMMC 2.0?
CMMC 2.0 is the updated version of the Cybersecurity Maturity Model Certification, developed by the U.S. Department of Defense (DoD), which aims to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) within the DIB sector. It introduces a streamlined version of the original CMMC model and focuses on aligning it with widely accepted cybersecurity standards like NIST SP 800-171.
2 - How is CMMC 2.0 different from CMMC 1.0?
CMMC 2.0 simplifies the certification model by reducing the number of levels from five to three compliance levels, which are:
3 - Who needs to comply with CMMC 2.0?
Once CMMC 2.0 takes effect, all contractors and subcontractors within the DIB that handle FCI or CUI will have to comply with CMMC 2.0. Companies at various levels of the supply chain working on contracts involving the DoD will also need to be compliant. The DoD will specify the required CMMC level in the contracts.
4 - What are the key requirements for each CMMC 2.0 level?
5 - How do organizations get certified under CMMC 2.0?
The certification requirements vary by CMMC Level and are defined below:
Once the assessment is complete, the results must be submitted to the CMMC Enterprise Mission Assurance Support Services (eMASS) database for evaluation.
6 - What is the timeline for CMMC 2.0 implementation?
The DoD will take a phased implementation approach for CMMC 2.0 over the next several years. Phased Rollout: The DoD plans to implement CMMC 2.0 in four phases over approximately 2 and a half years:
7 - What are the consequences of non-compliance with CMMC 2.0?
The consequences for non-compliance with CMMC can be severe for defense contractors, such as disqualification from bidding on DoD contracts. Additionally, the organization may suffer from security breaches, financial penalties, and reputational damage by failing to protect sensitive information.
8 - What is the relationship between NIST SP 800-171 and CMMC?
The CMMC and NIST standards are closely related, as meeting CMMC requirements involves adhering to NIST standards. DoD contractors will have to either conduct a self-assessment or undergo a third-party assessment to ensure that they comply with the applicable NIST standards specified by the DFARS clause 252.204-7012. Under CMMC 2.0, a Level 2 assessment will be based on the requirements of the NIST SP 800-171 standard. A Level 3 assessment will be conducted against the NIST SP 800-171 standard and a subset of NIST SP 800-172 requirements.
9 - How much will it cost to implement CMMC 2.0?
As part of the rulemaking process, the DoD will publish a detailed cost analysis associated with each level of CMMC 2.0. Compared to CMMC 1.0, costs associated with CMMC 2.0 are projected to be significantly lower due to the streamlined requirements at all levels, elimination of CMMC-unique practices and maturity processes, and the ability for companies to perform self-assessments at certain levels.
10 - How can organizations prepare for CMMC 2.0?
The DoD will require compliance with CMMC 2.0 as a condition of contract award for all contractors starting Q1 2025. Organizations are encouraged to start their compliance efforts as soon as possible to meet future contract requirements.
Preparation for compliance with CMMC 2.0 involves conducting a thorough gap analysis to identify areas needing improvement, implementing necessary cybersecurity practices, and ensuring ongoing compliance through regular self-assessments and training.
Contractors are strongly advised to begin preparing for compliance immediately. Many prime contractors are already requiring subcontractors to meet CMMC compliance requirements ahead of the official implementation.
Partnering with a cybersecurity firm specializing in CMMC compliance such as Idenhaus can provide valuable guidance and support during the preparation and certification process.