The Cybersecurity Maturity Model Certification is being developed by Office of the Under Secretary of Defense for Acquisition & Sustainment to be used by the Department of Defense contractors.
As stated on their website, “The Department of Defense is planning to migrate to the new CMMC framework in order to assess and enhance the cybersecurity posture of the Defense Industrial Base (DIB). The CMMC is intended to serve as a verification mechanism to ensure appropriate levels of cybersecurity practices and processes are in place to ensure basic cyber hygiene as well as protect controlled unclassified information (CUI) that resides on the Department’s industry partners’ networks.”
What are CMMC objectives?
Specifics on CMMC compliance:
On January 31st, the Office of the Under Secretary of Defense for Acquisition & Sustainment published CMMC 1.0 which discusses maturity scoring based on processes and practices regarding cyber. It looks at how mature an organization is for both processes and what level they are implemented/practices in place.
There are 5 levels of certification. A company must document and prove their compliance at one level before advancing to the next. For specific details on each section, see their latest publication.
What does CMMC mean to DoD contractors and sub contractors?
If you do business with the DoD, you want to get ready for a CMMC audit now. Per the Office of the Under Secretary of Defense for Acquisition & Sustainment, “All companies conducting business with the DoD must be certified. The level of certification required will depend upon the amount of CUI a company handles or processes.” Contact us if you have questions about what level of compliance is necessary for you.
CyberCompass helps DOD contractors and subcontractors understand their CMMC maturity level and get you audit-ready. It is affordable, with its built-in expertise that does most of the heavy lifting along with the analysis and compliance documentation to streamline CMMC compliance. When you need to get certified, it can go quickly and smoothly.
Our automation can save your firm over 400 hours in twelve months on becoming and staying compliant.
- Answer one set of simple yes/no questions that meets CMMC regulations
- CyberCompass saves your survey progress, allowing you to start and stop as needed
- Prioritized risk report lets you decide where to focus time and resources for corrective actions
- Built in step-by-step guide teaching you how to fix vulnerabilities
- CyberCompass’ encrypted vault saves your “body of evidence” in one place
- Manage your third party/vendor compliance to track their compliance. Use our pre-built agreement templates to make record keeping easier.
- Monitor your compliance for 12 months with dashboards and reporting.
- Utilize our built-in employees cyber awareness training which is required by CMMC. CyberCompass allows to you schedule and track employee competency.