DoD's Interim Rule on CMMC: Phased Rollout to Immediately Impact Many Federal Contractors

Oct 27, 2020 0 Replies
DoD's Interim Rule on CMMC: Phased Rollout to Immediately   Impact Many Federal Contractors open original image

On Sept. 29, 2020, the Department of Defense (DoD) issued an interim rule, Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041), that implements its "Cybersecurity Maturity Model Certification" (CMMC) program.1 While this implementing regulation has been long-awaited, it also contains an unexpected new cybersecurity assessment requirement that will be effective this coming Nov. 30. During the CMMC roll-out period, contractors not subject to the new CMMC requirement nonetheless will be required to self-assess (or have DoD assess) their current cybersecurity compliance and report that status to a DoD website prior to any new DoD contract award or DoD's exercise of any contract option or extension of contract performance.



formatting link


Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required