NIST 800-171

CMMC Timeline Update: DoD Submits CMMC Program to Office of Management and Budget for Review

CMMC Timeline Update: DoD Submits CMMC Program to Office of Management and Budget for Review

On July 24th, the Department of Defense submitted the Cybersecurity Model Maturity Certification (CMMC) Program to the Office of Management and Budget (OMB) for review. So, what exactly does this mean for Defense contractors and when would a CMMC certification requirement start to show up in contracts solicitations?

DOJ’s False Claims Act and why it matters to Defense Contractors

DOJ’s False Claims Act and why it matters to Defense Contractors

On April 27, 2022, Aerojet Rocketdyne agreed to pay roughly $9 million to settle a False Claims Act complaint relating to overstated levels of cybersecurity compliance and controls. The case is significant because it is the first time that a whistleblower has successfully used the False Claims Act to hold a defense contractor accountable for cybersecurity fraud. The case also sets an important precedent for future whistleblowers who are trying to hold defense contractors accountable for cybersecurity violations.

An FAQ Guide to the CMMC (Pilot) Joint Surveillance Program

An FAQ Guide to the CMMC (Pilot) Joint Surveillance Program

With news that the Cybersecurity Maturity Model Certification (CMMC) implementation is being pushed back (again) to 2024, the CMMC pilot program (called Joint Surveillance) becomes ever more important as it is the only option for organizations that desire to be a first mover in receiving their CMMC certification. At last check, there have been a total of seven completed assessments under the pilot program, and while that may seem low, interest is clearly high as our CMMC Third Party Assessor Organization (C3PAO) teams continue to receive questions about the program from Organizations Seeking Certification (OSC). This blog post addresses the most common questions we have seen.

What CMMC can and should learn from FedRAMP

What CMMC can and should learn from FedRAMP

In our role as NIST 800 series and Risk Management Framework (RMF) subject matter experts, we’ve worked closely with both third-party assessment organizations (3PAO) and companies at different points of the packaging process for Federal Risk and Authorization Management Program (FedRAMP) authorization.

CMMC – The Cyber Compliance Standard We’ve Been Waiting For?

CMMC – The Cyber Compliance Standard We’ve Been Waiting For?

Is the DoD’s new Cybersecurity Maturity Model Certification (CMMC) the future, or just another compliance initiative in the long line of competing cyber standards across a fragmented landscape. One thing is certain, this is a different approach.