Description of the blog
On July 13, the U.S. Department of Defense removed its Cybersecurity Maturity Model Certification Program Phase II requirements, originally scheduled to go into effect Nov. 10.
Under the announcement, the department will temporality suspend the Phase II requirement for third-party CMMC assessments and will instead allow contractors to continue using Level 1 and 2 self-assessments while a comprehensive review of the program is conducted.
Additionally, the DOD published a Request for Information regarding CMMC. The purpose of the RFI is to obtain direct feedback from contractors to inform the newly established CMMC Reform Task Force during its review. Responses to the RFI are due by 12 p.m. ET on Aug. 14. ABC urges contractors to utilize this opportunity to provide feedback on challenges and opportunities associated with CMMC.
Department officials said the decision is intended to reduce unnecessary compliance costs, preserve competition and ensure innovative companies can continue supporting national defense.
ABC has consistently advocated for cybersecurity requirements that strengthen national security without creating unnecessary barriers for qualified contractors, including through comments on the first and second stages of rulemaking establishing CMMC.
For many merit shop construction firms performing work for the DOD and other federal agencies, particularly small businesses, the costs, administrative burden and limited availability of third-party assessors threatened to discourage participation in federal contracting opportunities.
ABC appreciates the Trump administration’s commitment to engaging industry during the review process and looks forward to working with policymakers to support cybersecurity initiatives that both protect sensitive information and preserve a strong, competitive and innovative construction workforce serving America’s defense needs.
Annual Partners