Lessons for State and Local Governments from CMMC

Share

Understanding the Cybersecurity Landscape of the Department of Defense

The importance of safeguarding the hardware, software, and systems relied on by the Department of Defense (DoD) needs no explanation. Just as state and local governments walk a tightrope of cybersecurity vulnerabilities, the DoD’s reliance on a diverse array of vendors amplifies the critical concern surrounding third-party cybersecurity practices. High-profile breaches, such as the Change Healthcare incident, serve as stark reminders of how myriad industries can be thrown into disarray when even one vendor is compromised.

To combat these risks, the DoD has adopted stringent compliance standards like NIST SP 800-171, which is specifically designed to protect controlled unclassified information (CUI). Building on these established principles, the Cybersecurity Maturity Model Certification (CMMC) program was introduced. CMMC is a compliance framework that assesses how well vendors’ cybersecurity practices align with the necessary requirements to participate in DoD contracts. This structured approach not only clarifies expectations but also instills confidence that cybersecurity best practices are being uniformly understood, met, and maintained.

Interestingly, the requirements of the CMMC are not limited to DoD contractors. A significant June 2025 executive order extended many core tenets of CMMC to all federal agencies, indicating a broader cultural shift towards rigorous cybersecurity accountability. While it’s yet to be determined whether CMMC will morph into a statewide or local initiative, clearly, cybersecurity professionals across various sectors should familiarize themselves with CMMC requirements. Doing so could prove invaluable for any organization eager to shield itself from threats stemming from third parties.

The Tiered Approach: Customizing Cybersecurity Levels

One noteworthy aspect of the CMMC framework is its recognition that not all data, systems, hardware, and software require uniform levels of security. Instead, it structures compliance into tiers, each introducing additional requirements and stricter controls for contractors. This tiered approach is particularly applicable for state and local governments striving to sharpen their cybersecurity measures.

  • Level 1: This foundational tier is designed for contractors handling federal contract information (FCI) and requires only a self-attestation of CMMC compliance.

  • Level 2: A step up, this level is aimed at vendors managing more sensitive CUI and FCI, incorporating 110 requirements along with an audit every three years by a Certified Third-Party Assessor Organization.

  • Level 3: Reserved for vendors managing the most critical systems, this highest level enforces the strictest requirements, with compliance audits conducted by the Defense Industrial Base Cybersecurity Assessment Center.

An annual affirmation is required across all tiers, and penalties for providing inaccurate information are strictly enforced by the Department of Justice (DOJ) under the False Claims Act. This rigorous compliance model is one that state and local agencies can adopt, requiring all their vendors to meticulously document their cybersecurity efforts. For vendors involved in sensitive operations, such as those handling constituents’ personal information or financial systems, an independent expert assessment can go a long way in ensuring thorough vetting.

Practical Implications: Lessons for State and Local Governments

The CMMC framework offers several practical implications for state and local governments that transcend its originally intended military application:

  • Cybersecurity as a Non-negotiable Priority: No longer can cybersecurity be treated as an afterthought. Government agencies, alongside their vendors, must now demonstrate solid cybersecurity practices. The fines imposed for noncompliance serve as a robust incentive for adherence. This principle is one that state and local governments can easily replicate, making cybersecurity an integral aspect of partnership agreements.

  • Documentation of Readiness: CMMC does not just demand a one-time demonstration of sound cybersecurity practices; it enforces continuous monitoring through regular assessments. Simple log-keeping is no longer adequate; a similar approach by local governments would send a powerful message about the necessity of diligent cybersecurity practices.

  • Designated Ownership: The scale of CMMC compliance necessitates that vendors identify specific individuals responsible for oversight. This reflects a broader need within government structures to assign explicit roles dedicated to cybersecurity, ensuring that safeguarding measures are managed as core responsibilities rather than as ancillary tasks for overburdened IT teams.

  • Addressing Cost Concerns: Concerns regarding the costs of compliance should be mitigated by the recognition that the financial implications of a breach can be astronomical. Segmenting networks to confine sensitive data to designated areas represents an effective and manageable cost containment strategy—one that even smaller municipalities can implement without jeopardizing community trust or fiscal integrity.

Embracing the CMMC Philosophy for Enhanced Cyber Resilience

In an ever-evolving landscape of cybersecurity threats, engaging proactively with frameworks like CMMC is no longer optional; it’s a necessity. The principles embodied in CMMC serve as a comprehensive blueprint for resilience, enhancing trust, competitiveness, and operational readiness among government entities.

Recognizing this, state and local governments should harness these lessons to safeguard their operations effectively, rising to meet the expectations of constituents and partners alike.

Expertise Behind the Insights

Mike Lipinski and Justin Heck, both pivotal figures in Plante Moran’s cybersecurity practice, offer extensive experience and insights into the complexities of cybersecurity. With backgrounds steeped in consultative and leadership roles, they emphasize the ongoing need to address the full scope of security, governance, risk, and compliance challenges showcased by frameworks like CMMC.

Read more

Local News