CliftonLarsonAllen
Understanding New CMMC Requirements for Organizations
Pages
22
Time to read
7 mins
Publication
Language
English
Pages
22
Time to read
7 mins
Publication
Language
English
This guide outlines the new requirements of the Cybersecurity Maturity Model Certification (CMMC) that contractors in the Defense Industrial Base must comply with to conduct business with the Department of Defense (DoD). It details the key changes in the CMMC framework, the impact on organizations, and the expected implementation timeline. The document emphasizes the importance of early preparation, as compliance may take up to a year. It explains the CMMC levels, which range from foundational to expert, and the necessary practices and assessments associated with each level. Additionally, it discusses the significance of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI), and the compliance obligations under the Defense Federal Acquisition Regulation Supplement (DFARS). The guide also provides strategies for organizations to prepare for the new standards, including self-assessment and documentation requirements, as well as the importance of understanding the flow of CUI and FCI within their systems.