Now Offering full CMMC Consulting Services
Get CMMC Consulting Services From a Team of Compliance Experts and Cybersecurity Engineers Trained to Get You Over the CMMC Finish Line.
It’s been an interesting year and a busy few months with plenty of updates for the CMMC assessment requirements process. For some background, the CMMC (cybersecurity maturity model certification) was created by the DOD and requires that its 300,000 supplier, primes, and subs (i.e., the Defense Supply Chain (DSC)) become compliant with defined cybersecurity practices and processes at various levels needed for compliance.
In late September, the DOD published an interim rule amending requirements for both DFARS and CMMC compliance. As described here, the interim rule will go into effect on November 30, 2020, so DSC providers should be aware.
The DOD has overhauled the NIST SP 800-171 assessment methodology in which contractors are already required to be compliant per DFARS 252.204-7012. Going forward, the DOD will require the contractor to self-certify and verify compliance before new contracts will be awarded. The assessment methodology has three levels for basic, medium, or high in which the basic assessment can be completed prior to contract award and medium/high after award completion. DSC providers need to be careful to ensure compliance and implementation requirements or the company might be subject to a False Claims Act violation. DSC providers can get started with NIST recommendations for self-assessment of the DFARS requirements provided here.
Another big result of the interim ruling going into effect is that the DOD plans to fully commit and move forward with the CMMC as re-affirmation to companies that part of the DSC begins the process of getting certified immediately. The DOD has provided a timeline starting in 2021 and going forward with the number of new DOD contracts per year having clauses that state the contractor must be compliant with the CMMC requirements to that contract at award time. The DSC contractor is [not required]{.underline} to be compliant at the stated CMMC level when bidding on the contract but must be at the required level by award time. The DOD will also require by FY 2026 all DOD contracts will have a CMMC compliance requirements clause. Once certified at the chosen CMMC level, the DSC contractor will need to be re-certified every three years or per significant change to the infrastructure or organization.
The CMMC-AB is actively working with the DOD on ensuring a proper rollout of CMMC assessment procedures and requirements. At this time, it is highly encouraged for DSC contractors to begin getting their company and IT environments ready for CMMC compliance.
Have questions regarding CMMC requirements or the process? Need help in getting your organization ready for the assessment with security architecture and be compliant with the applicable practices and processes for your needed CMMC Level? See how Grove can help you prepare for your assessment and properly secure your environment. Grove is currently seeking RPO status with the CMMC-AB to be certified in helping clients prepare for CMMC assessments.
Now Offering full CMMC Consulting Services
Get CMMC Consulting Services From a Team of Compliance Experts and Cybersecurity Engineers Trained to Get You Over the CMMC Finish Line.
AI Usage Transparency Report
Pre-AI Era · Written before widespread use of generative AI tools
AI Signal Composition
Score: 0.04 · Low AI Influence
Summary
The CMMC (cybersecurity maturity model certification) was created by the DOD and requires that its 300,000 supplier, primes, and subs become compliant with defined cybersecurity practices and processes at various levels needed for compliance.
Related Posts
Three Mac Update Helpers That Fit Below a Patch Platform
Latest, Applite, and an all-in-one macOS update script each solve a different part of lightweight Mac maintenance: app update visibility, Homebrew-backed app management, and command-line package updates that can be wrapped carefully for small teams or basic MDM.
Natural Makes the macOS Scroll Direction Toggle Less Buried
Natural is a small macOS menu bar utility that makes the natural scrolling toggle easy to reach, but building it from source also shows why open-source desktop utilities need clear prerequisite checks before they become recommended tools.
ClaudeChat Makes Snow Leopard Feel Useful Again
ClaudeChat-Snow-Leopard is interesting because it brings a modern Claude API workflow back to Mac OS X 10.6.8 with Objective-C, Cocoa, Keychain storage, screenshot uploads, and a native installer built for an older white MacBook.
LibrePods Turns AirPods Into an Interoperability Question
LibrePods is interesting because it turns AirPods into an interoperability question: what happens when open-source software implements Apple's private AirPods protocol so Android and Linux users can reach features normally reserved for Apple's ecosystem?
Why Mac Performance Monitor Belongs in the Mac Admin Toolbox
Mac Performance Monitor belongs in the Mac admin toolbox because it records local performance history, helps Help Desk review slow-Mac reports after the moment has passed, and keeps process telemetry on the Mac instead of sending it to a cloud service.
Check Encrypted HFS+ Drives Before macOS 28
Apple says macOS 28 will not support encrypted Mac OS Extended volumes, so older encrypted HFS+ external drives need to be identified, backed up, decrypted, converted, or reformatted before that upgrade.
ClickLock Shows Why Terminal Paste Is a Mac Security Boundary
ClickLock Stealer shows why Mac security teams should watch for Terminal paste lures, fake AppleScript password prompts, command-line Keychain access, LaunchAgent persistence, and Jamf Protect alerts that can route suspected Macs into Jamf Pro response groups.
CrashStealer Shows the Gap Between Notarization and Detection
CrashStealer shows the security gap between Apple's Developer ID notarization path and App Store review, and why Jamf's behavioral detection mattered.
AppleCare One Just Became a Better AppleCare Deal
AppleCare One looks more valuable after AppleCare+ price increases for Macs and iPads, especially for people with several Apple devices and older eligible hardware.
Why Apple's iPhone Financing Lock Change Matters for Business Buyers
Apple's U.S. carrier financing change makes locked versus unlocked iPhones an operational buying decision for small businesses, BYOD users, and Apple fleet planners.