Posts Tagged CMMC

CMMC Phase II Suspension and Reform Task Force

Share

The Department of War (DoW) is pausing the rollout of the Phase 2 implementation of CMMC while allowing Level 1 or Level 2 self-assessments to continue to be included in procurement requests. The cybersecurity NIST SP 800-171 Rev 2* requirements outlined in DFARS 252.204-7012 remain in effect. Cybersecurity compliance will continue to be enforced through self-assessments and select government-led assessments. See the press release here: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/ and news coverage: https://defensescoop.com/2026/07/13/dod-halts-cmmc-cybersecurity-requirements-phase-2/ 

DoW is seeking feedback from industry by establishing a Cybersecurity Maturity Model Certification (CMMC) Reform Task Force to gather feedback about reducing compliance costs and administrative burdens while protecting federal data and strengthening operational resilience. A Request for Information (RFI), distributed on July 13th, seeks responses before August 14th to help shape the future of cybersecurity and the operational resilience of the Defense Industrial Base (DIB). To see more about how to respond to the RFI, view the announcement on SAM.gov: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view

For more information on how to comply with CMMC and upload your SPRS Score (which still matters), leverage Project Spectrum training at https://www.projectspectrum.io/ and check out the DoW Chief Information Officer website for additional resources: https://dowcio.war.gov/

 

Footnote:

*NIST SP 800-171 Rev 3 will eventually be adopted into DFARS – learn more here: https://www.governmentcontractslaw.com/2025/04/the-prestige-dod-unveils-nist-sp-800-171-revision-3-organizationally-defined-parameters/

 

Posted in: News Feed, Uncategorized

Leave a Comment (0) →

Share Your Feedback on DoD Cybersecurity Requirements before November 9th

Share

The Department of Defense (DoD) Office of Small Business Programs (OSBP) is seeking input from small businesses like yours to better understand how companies are preparing for the implementation of Cybersecurity Maturity Model Certification (CMMC) requirements, which begin appearing in DoD contracts starting November 10, 2025.

Your voice is critical in helping the DoD keep informed about the real-time impact on small businesses so they can tailor the resources, support, and guidance during the transition. We encourage you to take just a few minutes to complete this short, anonymous survey:

Survey Link: https://forms.osi.apps.mil/r/Kj8RFat4A8

The survey explores your current readiness, concerns, challenges, and efforts related to CMMC compliance. Your responses will help ensure that the support small businesses receive is relevant, timely, and aligned with real-world needs. Feedback is due November 9.

Participation is completely voluntary, and you may choose to provide contact information if you’d like to stay informed or receive follow-up from the DoD OSBP team.

Thank you for taking the time to contribute to this important effort and for your continued role in supporting the defense industrial base.

Posted in: Uncategorized

Leave a Comment (0) →

Final DFAR Supplement Rule Implementing the CMMC Program Announced

Share

On September 9, the Department of War (DoW) released the final DFARS rule implementing the CMMC Program as described at 32 CFR 170.3 for public inspection in the Federal Register. The final rule will ensure DoW procurements will include CMMC assessment requirements that ensure defense contractors properly safeguard the Department’s Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The CMMC program will provide a consistent methodology for assessing compliance with DoW’s cybersecurity requirements.

The Federal Register Notice is available for public inspection at the following location: https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of

An introductory course about the CMMC program is available to both Government and industry at: https://www.dau.edu/courses/cyb-1010

Additional information on the CMMC Program can be found at: https://dodcio.defense.gov/CMMC/

Posted in: News Feed

Leave a Comment (0) →