Office of the Secretary December 26, 2023 – Federal Register Recent Federal Regulation Documents

Cybersecurity Maturity Model Certification (CMMC) Program Guidance
Document Number: 2023-27281
Type: Notice
Date: 2023-12-26
Agency: Department of Defense, Office of the Secretary
The Department of Defense announces the availability of eight guidance documents for the CMMC Program. These documents provide additional guidance for the CMMC model, assessments, scoring, and hashing.
Cybersecurity Maturity Model Certification (CMMC) Program
Document Number: 2023-27280
Type: Proposed Rule
Date: 2023-12-26
Agency: Department of Defense, Office of the Secretary
DoD is proposing to establish requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have, as part of the Cybersecurity Maturity Model Certification (CMMC) Program, implemented required security measures to expand application of existing security requirements for Federal Contract Information (FCI) and add new Controlled Unclassified Information (CUI) security requirements for certain priority programs. DoD currently requires covered defense contractors and subcontractors to implement the security protections set forth in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev 2 to provide adequate security for sensitive unclassified DoD information that is processed, stored, or transmitted on contractor information systems and to document their implementation status, including any plans of action for any NIST SP 800-171 Rev 2 requirement not yet implemented, in a System Security Plan (SSP). The CMMC Program provides the Department the mechanism needed to verify that a defense contractor or subcontractor has implemented the security requirements at each CMMC Level and is maintaining that status across the contract period of performance, as required.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.