Connect with us

Hi, what are you looking for?

Cyber Security

Pentagon Preps for First CMMC Pilots in 2021


The Pentagon’s Cybersecurity Maturity Model Certification program will begin including security requirements in select solicitations starting next year.

The Defense Department, worried about potential cybersecurity risks from its vendors, is in the midst of implementing a new supply chain security certification and announced the first pilots set for the coming year.

The Pentagon has been working on the Cybersecurity Maturity Model Certification program since 2018. While other programs like the Federal Risk and Authorization Management Program, or FedRAMP, look at the security of products purchased by government agencies, CMMC is designed to look at the companies that supply those products to ensure sensitive DOD data is safe with those vendors.

The risks are not imagined. For years, DOD officials have pointed to Chinese espionage efforts and a plane that looks a lot like the U.S.-built F-35, among others. And, just this week, news broke of a critical vulnerability purposely inserted into a commercial software product used across government and the private sector.

When fully implemented, every solicitation for products or services coming out of the DOD and military branches will include some form of CMMC requirement, based on the security level required for the sensitivity of the data involved.

But before the full rollout, the Pentagon wants to run some tests to see how it will all work in practice. The plan includes a phased rollout over five years—from 2021 through 2025.

CMMC officials are considering pilots for pending solicitations at two service branches and a support agency:

  • Three from the Navy: Integrated Common Processor, F/A-18E/F Full Mod of the SBAR and Shut Off Valve, and DDG-51 Lead Yard Services/Follow Yard Services.
  • Three from the Air Force: Mobility Air Force Tactical Data Links, Consolidated Broadband Global Area Network Follow-On, and Azure Cloud Solution.
  • One from the Missile Defense Agency: Technical Advisory and Assistance Contract.

“For approved pilots, all offerors will undergo the appropriate CMMC assessment, and awardee must achieve the required CMMC level at time of contract award, and flow down the appropriate CMMC requirement to subcontractors,” the department said in a release.

The initial pilots will cover the lower tiers of CMMC requirements: Levels 1, 2 and 3.

The release also notes the CMMC program office is working with “the Army and other defense agencies to identify and approve additional candidate CMMC pilots, to ensure they fit within the criteria.” The office promised additional pilots and updates “in the weeks to come.”

Source: https://www.nextgov.com/cybersecurity/2020/12/pentagon-preps-first-cmmc-pilots-2021/170814/

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Cyber Security

A top Defense Department official described the private sector as “absolutely essential” in implementing the agency’s new cyber strategy. A top Defense Department official...

Cyber Security

How a cornerstone cybersecurity program has evolved from information collection to active defense. The Cybersecurity and Infrastructure Security Agency has used its Continuous Diagnostics...

Cyber Security

Cybercriminals are increasingly leveraging extreme weather events to launch attacks on critical infrastructure sectors. Cybersecurity experts say critical infrastructure operators can leverage a set...

Cyber Security

A new report says a cyber threat actor within Russia’s military intelligence service leveraged a novel malware campaign targeting Android devices used by the...

Copyright © 2023 Newsworthy News | Global | Political | Local | All News | Website By: Top Search SEO