Into the Unknown: DoD’s Long-Awaited Cybersecurity Rule Leaves Critical Questions Unanswered

On September 29, 2020, the US Department of Defense (DoD) published its long-awaited interim cybersecurity rule that includes (1) an assessment and reporting system to evaluate contractors’ current compliance with NIST SP 800-171, as required by DFARS 252.204-7012; and (2) the rollout of the Cybersecurity Maturity Model Certification (CMMC) Framework into DoD solicitations.

🔒 Members Only · Cyber & AI BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every Brief, six days a week.