Immaturity of the Cybersecurity Maturity Model: Revisions Omit Higher-Level Updates
Client Alert | 1 min read | 11.13.19
Last week, the Defense Department (DoD) released Revision 0.6 to the Cybersecurity Maturity Model Certification (CMMC). Notably absent were revisions to Levels 4 – 5, which DoD promises in the next public release. While the final version of the CMMC is due in late January, Revision 0.6 updated CMMC Levels 1 – 3 by:
- Condensing the CMMC requirements;
- Modifying the practices and processes; and
- Providing clarifications and examples for CMMC Level 1 requirements.
Revision 0.6 also distilled the core requirements for Levels 1 – 3 into the following categories:
- Level 1 -- Basic cyber hygiene: Implementation of security controls in FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems;
- Level 2 -- Intermediate cyber hygiene: Implementation of select NIST SP 800-171 controls; and
- Level 3 -- Good cyber hygiene: Full implementation of NIST SP 800-171 controls.
Industry will benefit from reviewing this latest draft and preparing for DoD’s pending implementation of the CMMC.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 8 min read | 04.27.26
Deadlock Broken: EU Adopts 20th Russia Sanctions Package
The EU has adopted its 20th package of sanctions in connection with Russia's ongoing war against Ukraine, resolving a prolonged internal political deadlock that had been caused by vetoes from Hungary and Slovakia. The package amends Regulations 833/2014, 269/2014, and 765/2006 and the respective Council Decisions and Implementing Regulations. The texts entered into force on 24 April 2026. They are available through this link.
Client Alert | 5 min read | 04.27.26
Drift Protocol Exploit: Why “Social Trust” Is the Newest Cybersecurity Gap
Client Alert | 11 min read | 04.27.26
EU Pharma Package: Access Conditionalities and Shortage Measures Compromise Proposal
Client Alert | 4 min read | 04.27.26
Gaming Addiction Litigation: Turner v. Epic Games & Roblox and What It Means for the Industry

