DoD’s CMMC 2.0 Cybersecurity Rule: Striking Balance Between Security and Regulation

The Defense Department’s recently released rule for its Cybersecurity Maturity Model Certification (CMMC) program sparks a debate about the fine line between necessary security measures and regulatory burden. The new regulations detail specific security prerequisites for defense contractors and subcontractors.

The new rule, launched on last December, follows an announcement of CMMC 2.0 in 2019, which is an elevated version of the cyber certification program designed to bolster the cybersecurity of the defense industrial base. It allows self-assessment for specific requirements and stresses the importance of a cooperative approach between the DoD and the industry in tackling evolving threats.

A crucial aspect of CMMC 2.0 is the requirement for defense contractors and subcontractors with access to controlled unclassified information (CUI) to prove the ‘maturity’ of their cybersecurity programs against a progressively complex capabilities set.

The proposed rule reconfirms that companies handling CUI need to adhere to controls established by the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171.

Despite the emphasis on heightened security, there is some skepticism about the proposed regulations. For example, the new rule also introduces a requirement for contractors and subcontractors to annually attest their compliance with prescribed security requirements for each level of CMMC 2.0. This provision has raised concerns among industry professionals about potential risks under the False Claims Act.

Ultimately, the balancing act between ensuring national security and maintaining a reasonable regulatory environment continues to be a point of discussion and refinement as organizations adapt to a new era of digital threats.

Comments can be submitted until February 26 and the final rule is anticipated to come into effect early 2025.

For more in-depth coverage, read the full article here.