Now Offering full CMMC Consulting Services
Get CMMC Consulting Services From a Team of Compliance Experts and Cybersecurity Engineers Trained to Get You Over the CMMC Finish Line.
It’s been an interesting year and a busy few months with plenty of updates for the CMMC assessment requirements process. For some background, the CMMC (cybersecurity maturity model certification) was created by the DOD and requires that its 300,000 supplier, primes, and subs (i.e., the Defense Supply Chain (DSC)) become compliant with defined cybersecurity practices and processes at various levels needed for compliance.
In late September, the DOD published an interim rule amending requirements for both DFARS and CMMC compliance. As described here, the interim rule will go into effect on November 30, 2020, so DSC providers should be aware.
The DOD has overhauled the NIST SP 800-171 assessment methodology in which contractors are already required to be compliant per DFARS 252.204-7012. Going forward, the DOD will require the contractor to self-certify and verify compliance before new contracts will be awarded. The assessment methodology has three levels for basic, medium, or high in which the basic assessment can be completed prior to contract award and medium/high after award completion. DSC providers need to be careful to ensure compliance and implementation requirements or the company might be subject to a False Claims Act violation. DSC providers can get started with NIST recommendations for self-assessment of the DFARS requirements provided here.
Another big result of the interim ruling going into effect is that the DOD plans to fully commit and move forward with the CMMC as re-affirmation to companies that part of the DSC begins the process of getting certified immediately. The DOD has provided a timeline starting in 2021 and going forward with the number of new DOD contracts per year having clauses that state the contractor must be compliant with the CMMC requirements to that contract at award time. The DSC contractor is [not required]{.underline} to be compliant at the stated CMMC level when bidding on the contract but must be at the required level by award time. The DOD will also require by FY 2026 all DOD contracts will have a CMMC compliance requirements clause. Once certified at the chosen CMMC level, the DSC contractor will need to be re-certified every three years or per significant change to the infrastructure or organization.
The CMMC-AB is actively working with the DOD on ensuring a proper rollout of CMMC assessment procedures and requirements. At this time, it is highly encouraged for DSC contractors to begin getting their company and IT environments ready for CMMC compliance.
Have questions regarding CMMC requirements or the process? Need help in getting your organization ready for the assessment with security architecture and be compliant with the applicable practices and processes for your needed CMMC Level? See how Grove can help you prepare for your assessment and properly secure your environment. Grove is currently seeking RPO status with the CMMC-AB to be certified in helping clients prepare for CMMC assessments.
Now Offering full CMMC Consulting Services
Get CMMC Consulting Services From a Team of Compliance Experts and Cybersecurity Engineers Trained to Get You Over the CMMC Finish Line.
AI Usage Transparency Report
Pre-AI Era · Written before widespread use of generative AI tools
AI Signal Composition
Score: 0.04 · Low AI Influence
Summary
The CMMC (cybersecurity maturity model certification) was created by the DOD and requires that its 300,000 supplier, primes, and subs become compliant with defined cybersecurity practices and processes at various levels needed for compliance.
Related Posts
Clamshell iBook G3 Restoration, Part 1: From Broken Screen to Board-Level Repair
Part one of a Clamshell iBook G3 restoration: a broken screen, a charger detour, a blinking system folder, a full teardown, and the backlight connector mistake that paused the project.
Bromure Gives Codex a Room of Its Own
I installed Bromure Agentic Coding, watched it build the Linux VM, authenticated Codex, and followed a real Codex task through the workspace.
Claude Code Auto Mode Changes Approval Flow, Not the Safety Boundary
Claude Code Auto mode changes how approval decisions are handled. It does not expand the boundary of what the coding agent should be allowed to do.
Amnesia Stealer Shows the Next Stage of ClickFix on macOS
Amnesia Stealer shows how ClickFix-style social engineering is adapting on macOS, while a public malware sample gives defenders an opportunity to study the behavior behind the campaign.
Reporting on Microsoft 365 DLP Overrides with PowerShell
DLP overrides are not automatically bad. They are a business process that needs visibility. This walkthrough covers a Microsoft Purview DLP policy, a custom sensitive information type, user override behavior, and a PowerShell report that exports override events from Activity Explorer.
PowerBook 140 BlueSCSI Install: Cable Fixed, Battery-Bay Power, and Wi-Fi Setup
The PowerBook 140 project moved from preparing a BlueSCSI card in Basilisk II to installing the repaired internal SCSI cable, powering the BlueSCSI Pico externally from the battery bay, booting System 7.1, and fighting through DaynaPORT Wi-Fi setup.
Move Entra Users Off SMS and Voice Before Microsoft Retires Them
Microsoft is retiring Microsoft-provided SMS and voice authentication in Entra ID. The migration is not passkeys for everyone; it is removing weak telecom MFA and choosing supported replacement methods such as Microsoft Authenticator, FIDO2 keys, certificate-based authentication, OATH hardware tokens, or customer-managed telecom.
Fixing a Broken Apple Cinema Display Stand with a 3D Printed Leg
A 22-inch Apple Cinema Display arrived with a broken acrylic easel stand, so I used a 3D printed replacement leg instead of sending the monitor back.
macOS Tahoe 26.6.1 Fixes a High-Severity Screen Sharing Authentication Bypass
macOS Tahoe 26.6.1 fixes CVE-2026-65400, a high-severity Screen Sharing authentication issue where an attacker on the network may be able to authenticate without valid credentials.
Three Mac Update Helpers That Fit Below a Patch Platform
Latest, Applite, and an all-in-one macOS update script each solve a different part of lightweight Mac maintenance: app update visibility, Homebrew-backed app management, and command-line package updates that can be wrapped carefully for small teams or basic MDM.