• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
Major Changes for DFARS Cyber

Major Changes for DFARS Cyber

July 11, 2019 Posted by Nick DeLena Cybersecurity, DFARS, IT Security

This has been an action-packed year in the world of the Defense Federal Acquisition Regulation Supplement (DFARS) cybersecurity requirements.

We first saw an announcement at the beginning of the year that the Department of Defense Office of Inspector General would be conducting audits of defense contractors’ adherence to the NIST SP 800-171 control set.

Somewhat more recently we learned of the first prosecution of a defense contractor under the False Claims Act. Aerojet Rocketdyne Inc. is being prosecuted for attesting that they were fully compliant with NIST SP 800-171 when in fact they were in a state of significant non-compliance.

Most recently we have seen the release of a draft version of the new NIST 800-171 standard, Revision 2, along with a companion publication, NIST SP 800-171B. The Department of Defense has also announced the Cybersecurity Maturity Model Certification (CMMC).

The introduction of NIST SP 800-171B is particularly interesting. The publication, titled “Enhanced Security Requirements for Critical Programs and High-Value Assets” includes 35 new security requirements designed to help defense contractors protect against Advanced Persistent Threats (APTs) like those seen from state-sponsored hackers. It’s unclear at this point when the requirements of this publication will be scoped into contracts.

The CMMC is designed to address complaints from contractors and subcontractors that the existing requirements represent too broad of a brush for the widely varied defense industrial base. As of today, the same requirements apply to both Raytheon and Joe’s Machine Shop. The current framework allows for organizations to do some level of customization of the implementation of the requirements, but compliance is still rather binary. The CMMC seeks to change that by adding a maturity scale on top of the requirements, allowing contracting officers to decide which levels are required for certain contracts, and establishing strata to provide a roadmap for organizations to graduate to a higher level of security.

The DoD is establishing plans to allow third-party auditors to perform the Cybersecurity Maturity Model Certification.

The last bit of news relevant for DoD contractors is that the DoD will now consider cybersecurity an allowable cost for certain types of contracts. That means contractors can potentially submit the costs of their DFARS cybersecurity compliance efforts for reimbursement by the DoD.

We are tracking all of these issues and will be posting updates as they unfold.

As always, don’t hesitate to reach out to our experts here at OCD Tech for any questions on your IT security and IT compliance needs.

Tags: cybersecurityDoDNISTnist 800-171
Share
0
Avatar photo

About Nick DeLena

Nick leads engagements across the division’s primary practice areas, including audit, security, and advisory services. He’s a 19-year veteran of IT and IT risk management, having audited, consulted, and managed IT teams in a variety of industries. He holds several leading certifications, including CISSP, CISA, CRISC, and Security+, among others, and has an MBA from Brown University.

You also might be interested in

OCDTECH.COMMONONLINESCAMS

Most Common Online Scams

Nov 15, 2023

🌐The online world is teeming with opportunities, but it’s also[...]

OCD TECH CYBERSECURITY MONTH

October, Cybersecurity Month

Oct 2, 2023

Empowering Individuals and Businesses with Digital Safety Practices  October is[...]

WPA3: Next Generation Wireless Security

WPA3: Next Generation Wireless Security

Jul 24, 2018

For the first time in over a decade, the current Wi-Fi security standard is receiving an upgrade.

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next