June 10, 2024
CMCC 2.0 coming Q1-2025
Last week David McKeown, Deputy Chief Information Officer for Cybersecurity and Senior Information Security Officer at the Department of Defense, speaking at the Potomac Officer’s Club annual Cyber Summit, stated:
“We are moving forward, we’re hoping by the first quarter of calendar year [2025] we’ll be able to start enforcing this and putting this in contracts as we go forward."
That's big news! Many people have been saying spring 2025 was the earliest possible date, while others have been saying late 2025. According to this account of the same event, McKeown further stated that DoD has "adjudicated them all” -- referring to the public comments on the proposed rule gathered earlier this year. That would seem to indicate the final rule implementing CMMC is ready to go back to OMB by August, as many expect.
Are you ready? Most organizations require 12-18 months to fully implement 800-171 and be ready for an official L2 CMMC assessment, yet according to McKeown, we now have only 6-9 months before the program begins.
Need help? You know where to find me!
How old is your SPRS self-assessment score? Might want to review this. |
Sincerely,
Glenda R. Snodgrass, CCP/CCA
grs@theneteffect.com
The Net Effect, LLC
www.theneteffect.com
251-433-0196 x107
If you enjoy these updates, you might also enjoy my weekly newsletter "Cyber Security News & Tips" -- sign up now!