Immaturity of the Cybersecurity Maturity Model: Revisions Omit Higher-Level Updates
Client Alert | 1 min read | 11.13.19
Last week, the Defense Department (DoD) released Revision 0.6 to the Cybersecurity Maturity Model Certification (CMMC). Notably absent were revisions to Levels 4 – 5, which DoD promises in the next public release. While the final version of the CMMC is due in late January, Revision 0.6 updated CMMC Levels 1 – 3 by:
- Condensing the CMMC requirements;
- Modifying the practices and processes; and
- Providing clarifications and examples for CMMC Level 1 requirements.
Revision 0.6 also distilled the core requirements for Levels 1 – 3 into the following categories:
- Level 1 -- Basic cyber hygiene: Implementation of security controls in FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems;
- Level 2 -- Intermediate cyber hygiene: Implementation of select NIST SP 800-171 controls; and
- Level 3 -- Good cyber hygiene: Full implementation of NIST SP 800-171 controls.
Industry will benefit from reviewing this latest draft and preparing for DoD’s pending implementation of the CMMC.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 5 min read | 06.05.26
The Office of Management and Budget issued on May 29, 2026 a Proposed Rule that would significantly revise the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) at 2 C.F.R. Part 200, potentially impacting the full lifecycle of federal grants, cooperative agreements and other forms of financial assistance, from pre-award merit review through post-award administration and termination. These proposed changes are designed to implement the President’s policy priorities, executive actions related to diversity, equity and inclusion (DEI) activities, and Executive Order No. 14332, Improving Oversight of Federal Grantmaking (EO 14332).
Client Alert | 5 min read | 06.04.26
EU Pay Transparency Directive: The Transposition Deadline is Looming — What Now?
Client Alert | 4 min read | 06.04.26
Surveillance Pricing Update: California’s Sweeping AB 2564 Passes Assembly and Heads to Senate
Client Alert | 4 min read | 06.04.26
USTR Proposes Sweeping Tariffs as Part of Section 301 Forced Labor Import Enforcement Investigation

