CMMC News Update for October 2023
CMMC is definitely a work in progress. However, like all works in progress, there is progress being made. Here is the update for October.
CMMC is definitely a work in progress. However, like all works in progress, there is progress being made. Here is the update for October.
NIST has released a draft version of the next update to the core standard behind CMMC. If you do work for the US, Canadian or Australian defense departments or are a vendor to one of these organizations or if you are a vendor to a large US corporation, this standard and these changes are important…
CMMC or the Cybersecurity Maturity Model Certification passed a huge milestone this week when the Pentagon handed of the proposed rule to the Office of Management and Budget. After they approve the package, it gets published in the Federal Register for comment and implementation. Learn more about the remaining steps below.
800-171 is the government’s chosen cybersecurity standard for protecting controlled unclassified information (CUI) and is the standard is required by a number of government departments and by private industry as a matter of contract for protecting sensitive unclassified information. Learn more about this new version of the standard here.
Okay, that is a bit of alphabet soup. CUI stands for Controlled Unclassified Information. While technically, it only refers to government agencies and government contractors, think of it as information you might prefer that the Russians, Chinese and your competitors don’t have. GPT stands for generative pretrained transformers like ChatGPT, Bard and many others. It…
The ban now prohibits having any Bytedance software even installed on any device used in furtherance of a contract, even employee owned devices. Learn more below.
Up until now, CMMC has been a US federal government standard for companies doing business in the public sector. Canada has now joined the group and you should expect more countries to be added to the list. Learn more below.
Over the last couple of years we have talked a lot about what is required for CMMC Level 2 certification, but a lot more companies will need to be CMMC Level 1 certified. What is required for this?
Most defense contractors have been complaining about the lack of specificity of how to protect controlled technical information or CTI. DoD has just released instructions clarifying the rules around protecting CTI. Learn more here.
CMMC is an ever changing target. Here is the newest information on it that we have.