Immaturity of the Cybersecurity Maturity Model: Revisions Omit Higher-Level Updates
Client Alert | 1 min read | 11.13.19
Last week, the Defense Department (DoD) released Revision 0.6 to the Cybersecurity Maturity Model Certification (CMMC). Notably absent were revisions to Levels 4 – 5, which DoD promises in the next public release. While the final version of the CMMC is due in late January, Revision 0.6 updated CMMC Levels 1 – 3 by:
- Condensing the CMMC requirements;
- Modifying the practices and processes; and
- Providing clarifications and examples for CMMC Level 1 requirements.
Revision 0.6 also distilled the core requirements for Levels 1 – 3 into the following categories:
- Level 1 -- Basic cyber hygiene: Implementation of security controls in FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems;
- Level 2 -- Intermediate cyber hygiene: Implementation of select NIST SP 800-171 controls; and
- Level 3 -- Good cyber hygiene: Full implementation of NIST SP 800-171 controls.
Industry will benefit from reviewing this latest draft and preparing for DoD’s pending implementation of the CMMC.
Contacts

Partner and Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 7 min read | 06.26.26
Federal Roundup: Updates for PBMs and Medicare Advantage Organizations
In June 2026, federal regulators and lawmakers continued their efforts to improve drug affordability through targeted reforms. These recent developments will primarily impact pharmaceutical manufacturers, managed care organizations, and pharmacy benefit managers (PBM) serving Medicare Part D program members. PBMs, Medicare Advantage organizations, and Part D sponsors should monitor these changes in the interest of maintaining compliance and providing input on regulatory proposals that may influence their business operations or compensation structures in the future.
Client Alert | 6 min read | 06.26.26
Client Alert | 4 min read | 06.25.26
Twin Executive Orders Seek to Spur Quantum Leap in Technology and Cybersecurity
Client Alert | 7 min read | 06.24.26

