• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
Cybersecurity Maturity Model Certification (CMMC) Version 1.0 – Key Takeaways & Recommendations

Cybersecurity Maturity Model Certification (CMMC) Version 1.0 – Key Takeaways & Recommendations

February 24, 2020 Posted by Robbie Harriman CMMC, DFARS

As you may be aware, the Department of Defense (DoD) released the Cybersecurity Maturity Model Certification (CMMC) version 1.0 on January 31st, 2020. We have received many inquiries about what this means, and what we are currently recommending to our clients in the Defense Industrial Base (DIB).

Here is what we know as of today, including some key takeaways from the v1.0 release and the press release that followed:

  • CMMC requires all companies doing business with the DoD to partner with a Certified Third-Party Assessment Organization (C3PAO) to perform an audit of the company’s cybersecurity practices and processes
    • This differs from the current DFARS model of self-attestation
  • A board has been established to identify, train, and accredit C3PAO’s. At this time, there are no accredited auditors. Beware of any firm that claims they can provide you the “audit/certification.”
  •  CMMC will not be retroactive, and therefore will not apply to existing contracts containing the DFARS clause
  • CMMC will be rolled out in stages, appearing in new contracts beginning in Fiscal Year 2021
  • Certification will be required upon time of reward, not at time of bid
  • DoD’s goal is to have the requirement fully implemented by Fiscal Year 2026
  • CMMC has five levels of maturity that organizations will be assessed against which range from basic cyber hygiene to advanced
  • The CMMC 1.0 model contains 17 domains, 14 of which draw “practices” (controls) from the same NIST 800-171 control families we have been assessing against under current DFARS
  • The remaining three domains have additional practices drawn from other control frameworks (e.g. CIS Critical Security Controls, NIST 800-53, NIST CSF)
  • The CMMC model eliminates the allowance of Plans of Actions & Milestones (PoA&M’s) for identified weaknesses

While the CMMC Accreditation Body has been formed and board members elected, they have yet to define the criteria and process for training and accrediting C3PAO’s. OCD Tech aims to pursue and receive this accreditation once the process is formalized, but there are steps that can be taken in the interim, and we are currently helping clients move towards CMMC readiness.

So, what does all this mean for your organization? If you have CUI, are currently doing or intend to do business within the DIB, the best proactive course of action is to engage in a CMMC readiness exercise. Rely on OCD Tech’s expertise to identify your system boundaries, develop a system security plan, and assist in identifying and closing PoA&M’s based on the current CMMC 1.0 release for your targeted level of maturity.

Timing is key. CMMC requirements will be included in DoD RFI’s as early as June of 2020; the same CMMC requirements will start appearing within DoD RFP’s in September of 2020 so there is limited time to act. Conducting a CMMC readiness exercise comes with a dual-benefit – current compliance along with preparedness for bidding on future contracts. This will help your organization maintain a competitive edge in the DIB market.

It is also very important to note that DoD contractors and members of the DIB doing business with the DoD are still subject to existing DFARS regulations. 

Contact Us

Share
0
Avatar photo

About Robbie Harriman

Robbie is the Senior IT Audit Manager at OCD Tech.  Robbie joined the firm in May of 2016. Prior to working at O’Connor & Drew, P.C., Robbie worked in IT for other companies, including the heavily regulated casino industry.  He currently travels locally and internationally working on some of OCD’s largest financial services companies.  He has a diverse range of experience in the IT field, with a deep background in IT systems administration and control areas.

You also might be interested in

ISO 27001 vs SOC

ISO 27001 vs SOC Standards: Which Should You Choose?

Apr 11, 2025

Organizations today have a wealth of options to choose from[...]

OCDTECH.QUALITIESOFEFFECTIVEITAUDITOR

Qualities of an Effective IT Auditor 

Feb 6, 2024

In the world of technology, the role of an IT[...]

DATA PRIVACY WEEK

DATA PRIVACY WEEK

Jan 23, 2023

OCD Tech joins forces with The National Cybersecurity Alliance and[...]

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next