Cybersecurity Maturity Model Certification 2.0 Updates and Way Forward

AGENCY: Office of the Under Secretary of Defense for Acquisition and Sustainment, Department of
Defense (DoD).

ACTION: Advanced

Way Forward
The changes reflected in the CMMC 2.0 framework will be implemented through the rulemaking process. DoD will pursue rulemaking in both: (1) Title 32 of the Code of Federal Regulations (CFR); and, (2) title 48 CFR, to establish CMMC 2.0 program requirements and implement any needed changes to the CMMC program content in 48 CFR. Both rules will have public comment periods. Publication of title 32 and title 48 CFR rules will implement DoD’s requirements for the updated CMMC version 2.0, which include various modifications from CMMC 1.0. These modifications include:

• Eliminating levels 2 and 4, and renaming the remaining three levels in CMMC 2.0 as follows:
Level 1 (Foundational) will remain the same as CMMC 1.0 Level 1;
Level 2 (Advanced) will be similar to CMMC 1.0 Level 3;
Level 3 (Expert) will be similar to CMMC 1.0 Level 5.

• Removing CMMC-unique practices and all maturity processes from all levels;

• For CMMC Level 1 (Foundational), allowing annual self-assessments with an annual affirmation by DIB company leadership;

• Bifurcating CMMC Level 2 (Advanced) assessment requirements: Prioritized acquisitions involving CUI will require an independent third party assessment; Non-prioritized acquisitions involving CUI will require an annual self-assessment and annual company affirmation;

• For CMMC Level 3 (Expert), requiring Government-led assessments.

• Developing a time-bound and enforceable Plan of Action and Milestone process; and,

• Developing a selective, time-bound waiver process, if needed and approved. The title 32 CFR rulemaking for CMMC 2.0 will be followed by additional title 48 CFR rulemaking, as needed, to implement any needed changes to the CMMC program content in 48 CFR. DoD will work through the rulemaking processes as expeditiously as possible. Until the CMMC 2.0 changes become effective through both the title 32 CFR and title 48 CFR rulemaking processes, the Department will suspend the CMMC Piloting efforts and will not approve inclusion of a CMMC requirement in DoD solicitations. The CMMC 2.0 program requirements will not be mandatory until the title 32 CFR rulemaking is complete, and the CMMC program requirements have been implemented as needed into acquisition regulation through title 48 rulemaking.

Further information can be found at: https://www.acq.osd.mil/cmmc/

SHARE THIS POST