in ,

Carahsoft’s Alex Whitworth on Updated DOD Cybersecurity Certification Program, How Companies Can Prepare for Compliance

Carahsoft's Alex Whitworth on Updated DOD Cybersecurity Certification Program, How Companies Can Prepare for Compliance - top government contractors - best government contracting event

Alex Whitworth, director of sales at Carahsoft Technology, said companies should review their security practices to identify and address gaps as the Department of Defense is finalizing the second version of its Cybersecurity Maturity Model Certification program.

Whitworth wrote in a blog post published Tuesday that DOD’s CMMC 2.0 model has three maturity levels that defense contractors will aim to achieve through different methods of assessment.

He noted the department plans to require an annual self-evaluation and leadership affirmation for the first maturity level and divide the next level into two categories, one of which applies to vendors that will handle data critical to national security missions.

The initial CMMC iteration, according to Whitworth, required contractors to undergo an independent third-party audit at each of the five maturity levels for cybersecurity preparedness.

DOD previewed changes to the program in November 2021 after senior agency leaders completed an internal review in a move to ensure that industry partners have the capacity to safeguard defense information against cyberattacks.

“Ultimately, the CMMC guidelines will continue to evolve based on community feedback,” Whitworth said.

“While the program is finalized, organizations should press forward with security enhancements and preparing for compliance with the new standards.”

ExecutiveBiz Logo

Sign Up Now! ExecutiveBiz provides you with Daily Updates and News Briefings about Industry News

mm

Written by Mary-Louise Hoffman

is a writer of news summaries about executive-level business activity in the government contracting sector. Her reports for ExecutiveBiz are focused on trends and events that drive the GovCon industry to include commercial technologies that private companies are developing for federal government use. She contributes news content to ExecutiveBiz’s sister sites GovCon Wire and ExecutiveGov.

Google Cloud to Help VA Deploy Application Programming Interface Management Platform; Mike Daniels Quoted - top government contractors - best government contracting event
Google Cloud to Help VA Deploy Application Programming Interface Management Platform; Mike Daniels Quoted
DARPA Picks 10 Research Teams for Night Vision Tech Development Program - top government contractors - best government contracting event
DARPA Picks 10 Research Teams for Night Vision Tech Development Program