Now Offering full CMMC Consulting Services
Get CMMC Consulting Services From a Team of Compliance Experts and Cybersecurity Engineers Trained to Get You Over the CMMC Finish Line.
It’s been an interesting year and a busy few months with plenty of updates for the CMMC assessment requirements process. For some background, the CMMC (cybersecurity maturity model certification) was created by the DOD and requires that its 300,000 supplier, primes, and subs (i.e., the Defense Supply Chain (DSC)) become compliant with defined cybersecurity practices and processes at various levels needed for compliance.
In late September, the DOD published an interim rule amending requirements for both DFARS and CMMC compliance. As described here, the interim rule will go into effect on November 30, 2020, so DSC providers should be aware.
The DOD has overhauled the NIST SP 800-171 assessment methodology in which contractors are already required to be compliant per DFARS 252.204-7012. Going forward, the DOD will require the contractor to self-certify and verify compliance before new contracts will be awarded. The assessment methodology has three levels for basic, medium, or high in which the basic assessment can be completed prior to contract award and medium/high after award completion. DSC providers need to be careful to ensure compliance and implementation requirements or the company might be subject to a False Claims Act violation. DSC providers can get started with NIST recommendations for self-assessment of the DFARS requirements provided here.
Another big result of the interim ruling going into effect is that the DOD plans to fully commit and move forward with the CMMC as re-affirmation to companies that part of the DSC begins the process of getting certified immediately. The DOD has provided a timeline starting in 2021 and going forward with the number of new DOD contracts per year having clauses that state the contractor must be compliant with the CMMC requirements to that contract at award time. The DSC contractor is [not required]{.underline} to be compliant at the stated CMMC level when bidding on the contract but must be at the required level by award time. The DOD will also require by FY 2026 all DOD contracts will have a CMMC compliance requirements clause. Once certified at the chosen CMMC level, the DSC contractor will need to be re-certified every three years or per significant change to the infrastructure or organization.
The CMMC-AB is actively working with the DOD on ensuring a proper rollout of CMMC assessment procedures and requirements. At this time, it is highly encouraged for DSC contractors to begin getting their company and IT environments ready for CMMC compliance.
Have questions regarding CMMC requirements or the process? Need help in getting your organization ready for the assessment with security architecture and be compliant with the applicable practices and processes for your needed CMMC Level? See how Grove can help you prepare for your assessment and properly secure your environment. Grove is currently seeking RPO status with the CMMC-AB to be certified in helping clients prepare for CMMC assessments.
Now Offering full CMMC Consulting Services
Get CMMC Consulting Services From a Team of Compliance Experts and Cybersecurity Engineers Trained to Get You Over the CMMC Finish Line.
AI Usage Transparency Report
Pre-AI Era · Written before widespread use of generative AI tools
AI Signal Composition
Score: 0.04 · Low AI Influence
Summary
The CMMC (cybersecurity maturity model certification) was created by the DOD and requires that its 300,000 supplier, primes, and subs become compliant with defined cybersecurity practices and processes at various levels needed for compliance.
Related Posts
Why Apple's iPhone Financing Lock Change Matters for Business Buyers
Apple's U.S. carrier financing change makes locked versus unlocked iPhones an operational buying decision for small businesses, BYOD users, and Apple fleet planners.
The CMMC Pause Does Not Make a Level 2 Audit Worthless
The July 2026 CMMC Phase II pause changes the timing of third-party assessment requirements, but it does not erase DFARS, NIST SP 800-171, SPRS, or the value of a completed Level 2 audit.
How We Structured and Hashed CMMC Evidence for Auditor Review
How folder naming, control-level artifact names, spreadsheet hyperlinks, and evidence hashing made a CMMC evidence package easier for the auditor to validate.
Preparing a BlueSCSI Card for My PowerBook 145 with Basilisk II
A step-by-step walkthrough for preparing a BlueSCSI v2 PowerBook card image with Basilisk II: download the pieces, configure the emulator, boot a working classic Mac image, mount the target System 7.1 image, stage tools, and shut down cleanly before moving the image to the card.
How I Keep Up With ISC2 CPE Credits Without Making It a Second Job
Keeping up with ISC2 CPE credits is easier when you treat it like a normal professional habit instead of a renewal emergency. Here is the system I use across CISSP, CCSP, SSCP, and CSSLP, with free and low-friction sources for webinars, books, training, and work-based credits.
When AI Agents Trust the Wrong Tool Description
Microsoft's MCP tool-poisoning research shows why AI agent security has to treat tool descriptions, schemas, and metadata as part of the control plane instead of harmless documentation.
Jamf Was My Mac Evidence Layer for CMMC
How Jamf Compliance helped support the Mac portion of a CMMC assessment, and why I added a small read-only CSV summary script for auditor-ready failed-result evidence.
How a Floppy Disk Turned My PowerBook 145 Around
A replacement adapter finally brought my PowerBook 145 back to life, but the storage bay had a stranger problem than I first thought: the drive inside was an IDE drive, not the SCSI storage this machine needs. The surprise was that 6 MB of RAM made a System 7.1 RAM Disk boot possible while I wait on a replacement cable and BlueSCSI.
What I Check Before I Trust a Homebrew Formula or Cask
Homebrew gives Mac admins a useful first-pass inspection workflow before trusting a formula or cask: check the source, checksum, version, tap state, availability, and upstream maintenance story.
When a Local AI Tool Belongs in My Workflow and When It Stays in the Lab
Running AI locally on a Mac has become a real part of my workflow, but only once I stopped treating local models like general-purpose answers and started treating them like constrained components inside a system I can still inspect.