Monday, December 15, 2025

Federal News Network: More companies may have to get a CMMC assessment after all

“The Pentagon’s revamped Cybersecurity Maturity Model Certification program is moving forward under the Defense Department chief information officer, but DoD is rolling back an aspect of the plan that would have allowed some 40,000 companies to self-attest to their cybersecurity practices.

When the Pentagon initially announced the ‘CMMC 2.0’ changes late last year, DoD planned on ‘bifurcating’ requirements for the approximately 80,000 contractors that handle controlled unclassified information (CUI)…”

“But during a Feb. 10 town hall, Deputy DoD CIO David McKeown said further analysis has shown all 80,000 will require third-party assessments.

‘Unfortunately, it looks like pretty much everybody falls into the category of either being a clear defense contractor or having some critical industry tie, that pretty much all of those are going to end up being very important CUI,’ he said…”

“The Government Accountability Office recently found the majority of defense contractors who have been audited in recent years are failing to fully implement the cybersecurity standards that form the basis of the CMMC requirement.

Moreover, additional companies will need to secure a third-party assessment, and the market for CMMC assessors is nascent. McKeown said DoD is working with the CMMC Accreditation Body, which accredits third-party assessment organizations, to ramp up the ‘assessment ecosystem.’…” Read the full article here.

Source: More companies may have to get a CMMC assessment after all – By Justin Doubleday, February 10, 2022. Federal News Network.

[related-post]

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Innovation in Action: Advancing Government Health with Philips

FORUM is proud to partner with Philips for a series of articles on their groundbreaking innovations in health technology that serve public- and private sector citizens and service members. Please take a look to learn more about how Philips is advancing modern and efficient health care, while improving lives for generations to come.

Don’t Miss A Thing

Jackie Gilbert
Jackie Gilbert
Jackie Gilbert is a Content Analyst for FedHealthIT and Author of 'Anything but COVID-19' on the Daily Take Newsletter for G2Xchange Health and FedCiv.

Subscribe to our mailing list

* indicates required