• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
CMMC Details Emerge

CMMC Details Emerge

July 31, 2019 Posted by Nick DeLena CMMC, DFARS, IT Security

The DoD is releasing more information about the upcoming CMMC standard. At the Department of the Navy Gold Coast Small Business Procurement Event in San Diego, more details emerged about the forthcoming Cybersecurity Maturity Model Certification (CMMC) which will be replacing the current DFARS 7012 compliance self-attestation.

OCD Tech Senior Manager Nick DeLena attended the event last week.

Katie Arrington, Special Assistant to the Assistant Secretary of Defense for Acquisition, ASD(A), for Cybersecurity, held the first of what is expected to be a “listening tour” on the emerging CMMC framework.

There will be five certification tiers which will correspond to the level of cybersecurity sophistication the DoD contractor is expected to have.

  • CMMC Level 1 corresponds to “basic cyber hygiene.”
  • CMMC Level 2 corresponds to “intermediate cyber level hygiene.”
  • CMMC Level 3 corresponds to “good cyber hygiene.”
  • CMMC Level 4 corresponds to “proactive.”
  • CMMC Level 5 corresponds to “advanced and progressive [security].”

The more advanced control requirements in the draft NIST SP 800-171B will comprise part of the conditions for CMMC Levels 4 and 5.

The CMMC level required for prime and subcontractors will be specified in RFP sections L &M in DoD contracts and will be considered a “go/no-go decision,” meaning compliance will be both enforced and mandatory for contract award.

Further detail was given on the framework itself, that it will not only incorporate the existing NIST SP 800-171 rev1 standard, but also DIB SCC TF WG Top 10, AIA NAS 9933, UK Cyber Essentials, AUS Essential Eight, and others. The CMMC is meant to be a unifying standard which may in the future see application beyond the Department of Defense to organizations currently doing business with any federal agency.

If you are a DoD prime or subcontractor wondering how you’ll be able to find a CMMC certifier, the DoD will maintain a registry and marketplace of approved firms. Strict independence rules, as seen in the FedRAMP program with third-party assessors, is expected as well. Certifying firms “cannot be problem solvers” according to Arrington, so companies will not be able to hire one firm to both implement the requirements and certify them to a CMMC level.

CMMC 1.0 is expected to be released in January 2020 alongside training programs for certifiers. Prime and subcontractors can expect to see the CMMC in RFPs starting in the fall of 2020.

OCD Tech, the IT Audit & Security division of O’Connor & Drew, is staying abreast of the developments to continue to provide key compliance services to the DoD prime and subcontractor community. Keep in touch with us to stay current.

Tags: compliancecyber securityDoD
Share
0
Avatar photo

About Nick DeLena

Nick leads engagements across the division’s primary practice areas, including audit, security, and advisory services. He’s a 19-year veteran of IT and IT risk management, having audited, consulted, and managed IT teams in a variety of industries. He holds several leading certifications, including CISSP, CISA, CRISC, and Security+, among others, and has an MBA from Brown University.

You also might be interested in

SSH Tunneling – Mr. Smith’s Hacker Insights

SSH Tunneling – Mr. Smith’s Hacker Insights

Jun 12, 2019

n this installment of Hacker Insights, we’ll take a deep dive into one of the mechanisms hackers....

Good People, Bad Clicks: Why You Should Think Before You Click

Good People, Bad Clicks: Why You Should Think Before You Click

Aug 7, 2024

Sometimes good people click bad links. We’re human. Recently someone[...]

Preparing for the 180-Day Plan of Action and Milestones (PoA&M) Deadline Under CMMC
Preparing for the 180-Day Plan of Action and Milestones (PoA&M) Deadline Under CMMC

Preparing for the 180-Day Plan of Action and Milestones (PoA&M) Deadline Under CMMC

Dec 5, 2024

The Cybersecurity Maturity Model Certification (CMMC) framework is pivotal for[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next