Critical Infrastructure Security, Government security, Government Regulations

GAO flags gaps in Pentagon planning for CMMC adoption

An aerial view of the Pentagon, Washington, D.C., May 15, 2023. (DoD photo by U.S. Air Force Staff Sgt. John Wright)

The U.S. Department of Defense was noted by the Government Accountability Office as not yet having fully accounted for outside factors that could influence the success of the Cybersecurity Maturity Model Certification program compliance within the defense industry, reports DefenseScoop.

Despite progress in developing a strategy to roll out the CMMC 2.0 cybersecurity framework, the Defense Department has not fully assessed external factors that could affect the program's success, according to the GAO report. The Pentagon has also not yet incorporated revised program standards released by the National Institute of Standards and Technology in May 2024. The GAO has also recommended that the Pentagon develop methods to mitigate identified hurdles to the CMMC program. Such recommendations have been agreed upon by DOD Chief Information Officer Kirsten Davies.

"The Department will also assess the fulsomeness of CMMC requirements to address the National Defense Strategy and Secretary priorities," said Davies in a letter to the GAO.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds