Changes Coming to DOD’s Cybersecurity Maturity Model Certification under CMMC 2.0

DOD’s proposal of changes to the CMMC program is responsive to concerns raised by the defense industrial base in several ways, including its simplification of five levels into three, a greater reliance on existing federal sources of cybersecurity guidance (i.e., NIST standards), and—at least in some circumstances—continued allowance of self-attestations of compliance by many defense contractors.

🔒 Members Only · Cyber & AI BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every Brief, six days a week.