By
Robbie Harriman
February 24, 2020
•
2
min read

As you may be aware, the Department of Defense (DoD) released the Cybersecurity Maturity Model Certification (CMMC) version 1.0 on January 31st, 2020. We have received many inquiries about what this means, and what we are currently recommending to our clients in the Defense Industrial Base (DIB).
Here is what we know as of today, including some key takeaways from the v1.0 release and the press release that followed:
While the CMMC Accreditation Body has been formed and board members elected, they have yet to define the criteria and process for training and accrediting C3PAO’s. OCD Tech aims to pursue and receive this accreditation once the process is formalized, but there are steps that can be taken in the interim, and we are currently helping clients move towards CMMC readiness.
So, what does all this mean for your organization? If you have CUI, are currently doing or intend to do business within the DIB, the best proactive course of action is to engage in a CMMC readiness exercise. Rely on OCD Tech’s expertise to identify your system boundaries, develop a system security plan, and assist in identifying and closing PoA&M’s based on the current CMMC 1.0 release for your targeted level of maturity.
Timing is key. CMMC requirements will be included in DoD RFI’s as early as June of 2020; the same CMMC requirements will start appearing within DoD RFP’s in September of 2020 so there is limited time to act. Conducting a CMMC readiness exercise comes with a dual-benefit – current compliance along with preparedness for bidding on future contracts. This will help your organization maintain a competitive edge in the DIB market.
It is also very important to note that DoD contractors and members of the DIB doing business with the DoD are still subject to existing DFARS regulations.
[wpforms id="10486"]

Audit. Security. Assurance.
IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.
Contact Info
OCD Tech
25 BHOP, Suite 407, Braintree MA, 02184
844-623-8324
https://ocd-tech.com
Follow Us
Videos
Check Out the Latest Videos From OCD Tech!
Services
SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®
IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review
IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO