Government Regulations

Pentagon weighs CMMC reforms after industry feedback

An aerial view of the Pentagon, Washington, D.C., May 15, 2023. (DoD photo by U.S. Air Force Staff Sgt. John Wright)

DefenseScoop reports that the Pentagon is reviewing significant industry feedback regarding the Cybersecurity Maturity Model Certification (CMMC) program as it considers reforms. Defense Department CIO Kirsten Davies stated on Wednesday that the department is processing over 1,100 responses, totaling more than 10,000 pages, from contractors affected by the program.

The CMMC program, particularly its Phase 2 requirements, faced criticism for being overly burdensome and costly for small and medium-sized businesses. In response, the Defense Department suspended these requirements and established a CMMC Reform Task Force. The department also issued a request for information, receiving substantial input favoring the pause and reform efforts. Davies noted that over 50% of respondents supported the hold, with negative feedback highlighting the program's disproportionate impact on smaller businesses.

While the CMMC pause is in effect, the department will enforce cybersecurity compliance through self-assessments and government-led evaluations based on NIST Special Publication 800-171 Revision 2. Davies emphasized that cybersecurity remains critical, especially with advanced AI threats, but the CMMC framework needs to be more dynamic and less focused on point-in-time assessments. The Pentagon is also considering operational technology resilience and addressing industry concerns about inconsistent controlled unclassified information (CUI) marking practices, which have caused operational friction.

Source: DefenseScoop

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds