BETHESDA, Md .– (BUSINESS WIRE) – The CMMC Accreditation Body (CMMC-AB) has expressed its support for the proposed changes to the implementation of the Cybersecurity Maturity Model Certification (CMMC) initiative, announced today by the Department of Defense after a six-month internal program review.
The Pentagon has announced significant changes to the technical CMMC standard, in particular by deleting two levels (formerly CMMC levels 2 and 4) from the maturity model framework and naming CMMC level 1 only as a self-certification requirement. In addition, the removal of new CMMC maturity practices from the standard and the inclusion of Limited Action Plans and Milestones (POAMs) as an acceptable form of remedy for certain CMMC practices will have a significant impact on how Defense Industrial Base (DIB) companies prepare for and implement CMMC.
Matthew Travis, Chief Executive Officer of the CMMC Accreditation Body, welcomed the arrival of these decisions. “We congratulate the Department of Defense leadership and the CMMC Executive Steering Group on formulating what we believe to be meaningful and compelling improvements in the implementation of CMMC,” said Travis. “The DOD approached this from an appropriate risk management perspective and delivered what the internal review wanted to achieve: clarify the standard, reduce the cost burden, improve scalability and increase confidence in the CMMC ecosystem.”
“There will be some short-term challenges to face,” Travis continued, “such as curriculum adjustments that our training providers are now required to make and the time needed for another round of federal legislation. But now that there is a definite way forward, I hope all parties willingly move forward. Additionally, as we continue our exclusive partnership with DOD in this endeavor, I am greatly encouraged by the division’s commitment to the interim program, which authorizes, promotes, and honors CMMC certifications for those DIB companies that apply for certification Decide on formal implementation The CMMC mandate is codified. We want to start doing this soon and I expect the market demand for CMMC certification will be substantial. ”
CMMC-AB will host a special CMMC Town Hall on Tuesday, November 9, 2021 at 6:00 p.m. EST to discuss the changes in CMMC 2.0. To register for the City Hall, please visit: https://us06web.zoom.us/webinar/register/WN_JPkQvEmDQrq1ZvoweTQsWg
About the CMMC Accreditation Body (CMMC-AB)
The CMMC Accreditation Body (CMMC-AB) was incorporated as a non-public company in the state of Maryland in January 2020 with an application pending for a tax exemption through the Internal Revenue Service under Section 501 (c) (3). The CMMC-AB is an independent accreditation body responsible for the establishment, administration, control and administration of CMMC assessment, certification, training and accreditation processes for the defense supply chain under a contract signed with the Department of Defense.