Immaturity of the Cybersecurity Maturity Model: Revisions Omit Higher-Level Updates
Client Alert | 1 min read | 11.13.19
Last week, the Defense Department (DoD) released Revision 0.6 to the Cybersecurity Maturity Model Certification (CMMC). Notably absent were revisions to Levels 4 – 5, which DoD promises in the next public release. While the final version of the CMMC is due in late January, Revision 0.6 updated CMMC Levels 1 – 3 by:
- Condensing the CMMC requirements;
- Modifying the practices and processes; and
- Providing clarifications and examples for CMMC Level 1 requirements.
Revision 0.6 also distilled the core requirements for Levels 1 – 3 into the following categories:
- Level 1 -- Basic cyber hygiene: Implementation of security controls in FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems;
- Level 2 -- Intermediate cyber hygiene: Implementation of select NIST SP 800-171 controls; and
- Level 3 -- Good cyber hygiene: Full implementation of NIST SP 800-171 controls.
Industry will benefit from reviewing this latest draft and preparing for DoD’s pending implementation of the CMMC.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 5 min read | 09.03.26
The U.S. Department of Transportation (DOT) published a final rule amending 14 CFR Part 234 that fundamentally changes how airlines report the causes of flight delays and cancellations. Effective October 19, 2026, the rule implements Section 511(b) of the FAA Reauthorization Act of 2024 by creating a new reporting category, the “Section 511(b) category,” for ten specific events that Congress determined are not attributable to airline control. The rule simultaneously narrows the existing "Air Carrier" reporting category by expressly excluding those same ten events.
Client Alert | 6 min read | 09.03.26
FDA Seeks Input for Regulating GenAI-Powered Medical Devices
Client Alert | less than 1 min read | 09.03.26
SBA Proposal to Overhaul Size Standards Would Transform Federal Government Contracting
Client Alert | 5 min read | 09.02.26
DOJ’s Civil Rights Fraud Initiative Claims Another DEI-Related FCA Settlement
