Posts Tagged CUI

Final DFAR Supplement Rule Implementing the CMMC Program Announced

Share

On September 9, the Department of War (DoW) released the final DFARS rule implementing the CMMC Program as described at 32 CFR 170.3 for public inspection in the Federal Register. The final rule will ensure DoW procurements will include CMMC assessment requirements that ensure defense contractors properly safeguard the Department’s Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The CMMC program will provide a consistent methodology for assessing compliance with DoW’s cybersecurity requirements.

The Federal Register Notice is available for public inspection at the following location: https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of

An introductory course about the CMMC program is available to both Government and industry at: https://www.dau.edu/courses/cyb-1010

Additional information on the CMMC Program can be found at: https://dodcio.defense.gov/CMMC/

Posted in: News Feed

Leave a Comment (0) →

DLA NOTICE TO SUPPLIERS

Share

Topic: NOTICE TO SUPPLIERS NIST 800-171 ASSESSMENTS EXPORT-CONTROLLED TECH DATA

Notice to DLA Suppliers: Export-controlled technical information is Controlled Unclassified Information (CUI)/Controlled Technical Information (CTI). DLA suppliers seeking export-controlled technical data for DLA procurement opportunities must have a current National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 cybersecurity assessment (i.e., not more than 3 years old unless a lesser time is specified in the solicitation) posted to the DoD Supplier Performance Risk System (SPRS) to be considered for award. DLA Suppliers who currently have an approved Enhanced Joint Certification (JCP) but have not posted their NIST SP 800-171 assessment to SPRS will not be able to access export-controlled technical data in DLA’s technical data repository after 16 August 2021. Instructions for posting an assessment on SPRS can be found at https://www.sprs.csd.disa.mil/. For additional information on NIST SP 800-171 assessments and other DoD requirements for safeguarding covered defense information please see DFARS Clause 252.204-7020 NIST SP 800-171 DoD Assessment Requirements. If you have any questions, please e-mail DLAJ344DataCustodian@dla.mil.  

Posted in: Uncategorized

Leave a Comment (0) →