Immaturity of the Cybersecurity Maturity Model: Revisions Omit Higher-Level Updates
Client Alert | 1 min read | 11.13.19
Last week, the Defense Department (DoD) released Revision 0.6 to the Cybersecurity Maturity Model Certification (CMMC). Notably absent were revisions to Levels 4 – 5, which DoD promises in the next public release. While the final version of the CMMC is due in late January, Revision 0.6 updated CMMC Levels 1 – 3 by:
- Condensing the CMMC requirements;
- Modifying the practices and processes; and
- Providing clarifications and examples for CMMC Level 1 requirements.
Revision 0.6 also distilled the core requirements for Levels 1 – 3 into the following categories:
- Level 1 -- Basic cyber hygiene: Implementation of security controls in FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems;
- Level 2 -- Intermediate cyber hygiene: Implementation of select NIST SP 800-171 controls; and
- Level 3 -- Good cyber hygiene: Full implementation of NIST SP 800-171 controls.
Industry will benefit from reviewing this latest draft and preparing for DoD’s pending implementation of the CMMC.
Insights
Client Alert | 2 min read | 07.31.25
A Greater Sum of Certainty: ASBCA Weighs in on when Sum Certain Defense Is Not Waived
A recent Armed Services Board of Contract Appeals decision provides useful guidance on when the government may (or may not) waive its defense that a contractor’s claim failed to state a sum certain. In GE Renewables US, LLC, the contractor had submitted a claim to the contracting officer for a determination that the contractor had the right to an economic price adjustment (EPA) due to an inflation-related price increase. Notably, the contractor did not provide the value of its requested adjustment in its claim. The contracting officer denied the claim, and the contractor appealed to the Board.
Client Alert | 7 min read | 07.31.25
Significant Changes Are in the Works for EU Environmental, Social, and Governance (ESG) Laws
Client Alert | 6 min read | 07.30.25
The new EU “Pharma Package”: Global (Orphan) Marketing Authorization
Client Alert | 4 min read | 07.29.25
Children first: How Ofcom’s Children’s code and age checks change the digital game