CMMC Enforcement Kicks Off Following Eight Years of Alerts

Share

CMMC Compliance: A New Era for the Defense Industry

The defense sector has long been forewarned about the necessity of safeguarding controlled unclassified information (CUI). Today, November 10, marks a significant turning point as companies must begin adhering to the government’s stringent cybersecurity standards. For nearly a decade, compliance with the National Institute of Standards & Technology’s (NIST) Special Publication 800-171 has been anticipated, yet the establishment of the Cybersecurity Maturity Model Certification (CMMC) kicks into high gear now.

The CMMC Framework

As of today, defense contracts will require at least a Level 1 certification, which necessitates self-certification for 15 basic cybersecurity controls. These controls, fundamental to maintaining cyber hygiene, mark the starting point for many contractors. It’s important to note that Level 1 is just the beginning; one year from now, on November 10, 2026, the Department of Defense (DOD) will advance the requirements to Level 2, which entails a third-party assessment of compliance with all 110 controls outlined in the NIST standard.

By the following year, November 10, 2027, contracting officers may begin to enforce Level 3 certifications, which often require assessments by the Defense Industrial Base Cybersecurity Assessment Center. This progression signals a clear pathway toward more stringent cybersecurity measures within an industry that is vital to national security.

The Road to Compliance and Readiness

Matthew Stern, Chief Security Officer at Hypori, emphasizes that there should be no excuses for companies not being prepared. Yet, there appears to be a notable divide in the mindset of contractors. Some view the implementation of CMMC as the natural evolution of existing compliance norms, while others harbor skepticism about its enforcement. Michael Greenman, a senior manager of cloud solutions at Deltek, shares that he has encountered both perspectives during discussions about CMMC.

Greenman recounted an instance where, despite presenting detailed regulations and legal citations, one audience member dismissed the likelihood of enforcement. This attitude could prove detrimental as companies now face a self-certification requirement, allowing some time to prepare for the impending Level 2 assessments.

The Risks of Non-Compliance

Self-attestation is not devoid of risks. Companies that falsify their compliance assertions could face severe repercussions under the False Claims Act, including both civil and potential criminal penalties. The Justice Department’s Civil Cyber Fraud Initiative further complicates matters, as whistleblowers—fellow competitors, even—can report false certifications for financial rewards. Therefore, it’s critical that companies take their compliance responsibilities seriously.

The Challenge of Third-Party Assessors

Looking toward the future, a pressing question arises: Will there be enough qualified third-party assessment organizations available to evaluate the estimated 70,000 contractors needing Level 2 certification? Currently, only about 450 entities hold this certification, with approximately 85 3PAOs available to conduct assessments. Notably, the Cyber AB, a private sector organization tasked with overseeing certification and approval of assessors, has faced challenges, including a backlog of individuals awaiting background checks to qualify as CMMC assessors.

Cyber AB’s monthly town halls reveal these challenges and underscore the urgency for defense contractors to progress on their compliance journeys.

A Shift in Enforcement Strategy

CMMC represents a paradigm shift in the enforcement of cybersecurity compliance within the DOD. Unlike previous methods where companies self-certified and faced inspections post-contract award, the current model requires certification upfront. “Oh, you want to win this contract and all the money. Let me check and see your CMMC score,” Greenman explains. If a contractor lacks certification, they will simply be ineligible for contract awards.

This new market-driven enforcement system fundamentally redefines how contractors engage with the DOD and sets a clear expectation that cybersecurity certification is now essential to participate in defense contracts.

Cybersecurity as a Business Imperative

Stern accurately notes that achieving Level 2 or 3 certification is no longer a competitive differentiator but rather a baseline requirement to operate within this space. “If you aren’t prepared for Level 2 and you’re protecting CUI data, you won’t be able to bid on the contract again. You’ll be on the outside looking in,” he warns. It is clear that companies must prioritize their cybersecurity posture not just for compliance, but as a fundamental aspect of doing business in the defense sector.

In this evolving landscape, grasping the intricacies of CMMC compliance is no longer optional; it is a survival strategy for businesses aiming to thrive in an increasingly regulated environment.

Read more

Local News