1. Home
  2. |Insights
  3. |Cybersecurity Maturity Model Matures: DoD Adds New Requirements to Draft Cybersecurity Certification

Cybersecurity Maturity Model Matures: DoD Adds New Requirements to Draft Cybersecurity Certification

Client Alert | 1 min read | 09.10.19

The Defense Department has released Revision 0.4 of its Cybersecurity Maturity Model Certification (CMMC) that, starting next year, independent auditors are to use to certify contractor compliance with DoD cybersecurity requirements.  Revision 0.4 more than doubles the number of cybersecurity controls across the CMMC’s five maturity “Levels.”  But the DoD emphasizes that it will further down-select these controls and that mature contractor processes may counteract gaps in the final controls’ implementation.  In addition to NIST SP 800-171 (the default standard under DFARS 252.204-7012), Revision 0.4 now incorporates requirements from the NIST Cybersecurity Framework, ISO 27001, and CIS Critical Security Controls, as well as from “additional DIB inputs.”  Notably missing is NIST SP 800-171B, which remains under review.

The DoD is requesting feedback on Revision 0.4 through September 25, 2019, and plans on releasing Revision 0.6 for comment in November 2019.   The final CMMC is expected in January 2020. 

Contacts

Insights

Client Alert | 5 min read | 06.05.26

Grants Overhauled: What the Proposed Rewrite of 2 CFR Part 200 Means for Federal Financial Assistance Award Recipients

The Office of Management and Budget issued on May 29, 2026 a Proposed Rule that would significantly revise the Uniform Administrative Requirements, Cost Principles, and Audit Requirements for Federal Awards (Uniform Guidance) at 2 C.F.R. Part 200, potentially impacting the full lifecycle of federal grants, cooperative agreements and other forms of financial assistance, from pre-award merit review through post-award administration and termination. These proposed changes are designed to implement the President’s policy priorities, executive actions related to diversity, equity and inclusion (DEI) activities, and Executive Order No. 14332, Improving Oversight of Federal Grantmaking (EO 14332)....