Proposed CMMC rule contains no surprises, but raises some initial questions

The Defense Department packed a lot of detail into its proposed rule for the Cybersecurity Maturity Model Certification program, released just before the holiday break. But CMMC experts also see a lot of lingering questions that DoD will have to address in 2024 before finalizing the rule.

The Pentagon announced its plans for a revised “CMMC 2.0” more than two years ago, after it delayed an initial CMMC rule issued in late 2020. The goal of the program is to ensure contractors are following cybersecurity requirements for protecting sensitive but unclassified information.

Despite all the questions and controversy at times with CMMC, Bob Metzger, the head of the Washington office of law firm Rogers Joseph O’Donnell, doesn’t see any big surprises in the rulemaking released in late December.

“Clearly, DoD has put a huge amount of thought into it,” Metzger said during a Jan. 2 meeting of the Cyber Accreditation Body. “And undoubtedly they’ve read some or perhaps much of the commentary that has been swirling around the expected 2.0 rules for a couple of years. And yet, when you look at what they’ve actually done, there are no significant architectural changes. This is pretty much what we were told we were going to get.”

The Pentagon stuck with changes to split up the CMMC requirements into three different levels. DoD plans to fully institute those requirements across all solicitations by October 2026.

DoD projects that the program will affect about 220,000 companies across the defense industrial base. But the department projects that the majority of those companies — just short of 145,000 — will only be required to self-attest to meeting cybersecurity standards.

DoD still estimates that about 76,000 companies in the defense industrial base handle more sensitive information that will require them to get a third-party exam of their security practices.

Metzger says the rule shows DoD is not backing off contractor cybersecurity initiative.

“The rule communicates that DOD is serious about the cybersecurity of the defense industrial base,” he said. “They could have made life easier for small businesses, they might have truncated the requirements or extended the rollout period, or increased the opt outs or given contracting officers more latitude over a greater period of time so that it wouldn’t be as demanding for so many, but in the main, they did not. They kept the bar fairly high for almost everyone.”

The proposed rule carves out an important role for DoD’s prime contractors. It requires those companies to both comply with CMMC themselves and flow down the requirements to subcontractors throughout their supply chains.

“That reads to me that DoD is going to hold that prime contractor responsible for their entire supply chain,” Eric Crusius, a procurement attorney and partner at Holland and Knight, said during the Cyber AB meeting. “And you could bet that that will waterfall all the way down the supply chain from the prime contractor and may accelerate the requirements that some of these large primes have for getting a CMMC certification along the way”

But experts also say some important clarifications will be needed as DoD finalizes the rule. DoD is collecting comments on the proposed rule through February 26.

For instance, which version of the National Institute of Standards and Technology Special Publication 800-171 will contractors have to meet? The proposed rule says revision 2. But NIST is finalizing Revision 3 of the 800-171 publication with some important updates.

The rule raises questions about what version of the standards contractors will have to meet, and how DoD will ensure its contractor cybersecurity requirements keep up with evolving cyber threats.

Jacob Horne, the chief cybersecurity evangelist for Summit Seven, said DoD should clean up some of those needed clarifications. But Horne also pointed out that instituting major cybersecurity improvements to the defense industrial base will be a gradual process.

“Overall, I think that the best that we’re ever going to be able to accomplish is going to be incremental changes over time,” Horne said during the Cyber AB meeting. “I think that some sort of wholesale sea change, revolutionary, continuous monitoring, elite, high speed security revolution is just not going to happen via policy or politics or whatever. And if in this rule, specifying Rev Two is the first increment in that long series of increments, then I think that it is a reasonable compromise in a lot of ways.”

Another key question is how DoD will apply the CMMC requirements to companies that provide IT services to businesses in the defense industrial base, referred to as managed service providers or MSPs. Many defense contractors, especially small businesses, don’t manage every aspect of their IT networks. Instead, they outsource IT and cybersecurity to MSPs.

Metzger, who noted he sits on the board of an MSP firm, says the rulemaking needs to clarify how those external service providers should meet the CMMC requirements.

“We also need to be thinking about that often used word: reciprocity,” Metzger said. “If an MSP is deemed to sufficiently meet -171 for one client, we’d sure like it to apply for all clients that are using the same services, so that we don’t have each client of an MSP fighting its way over the hill to get essentially the same outcome. This proposed rule is better on MSPs. It avoids very, very bad outcomes that might have occurred. But it is not clear enough in my view.”

Crusius said CMMC Third-Party Assessment Organizations will also be strained to meet the demand of providing exams for more than 70,000 companies in the coming years.

“There’s no way that the C3PAO community will be able to get through them fast enough for the amount of companies that need them,” he said. “So I think this only works by having an MSP community that is able to get certified and is able to be kind of categorized in a way where DoD can look at them and say, ‘OK, if this company is using this MSP, we know that 30, 80, however many of these boxes can be checked.’ We have to verify, but we don’t do like investigate each new system like it’s a brand new system, which would make these exams a lot slower.”

Another critical question is when exactly the rule will be finalized. It typically takes an agency at least a year to adjudicate all the comments and finalize a complex rulemaking. But Horne and others pointed to a couple reasons why DoD may be able to finalize the rule by the end of calendar year 2024.

“Given the election, given the fact that DoD, against their desire, was forced to wait another three years, essentially, from the time they issued their 2020 rule, I would imagine they are exceptionally highly motivated to get this wrapped up before the end of this year,” Horne said. “That means, hey, maybe we’ll have another Christmas surprise at the end of this year.”

Copyright © 2024 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.


Saitech Inc, is VMware Advanced Level Virtualization Solution Provider

Saitech Inc, is VMware Advanced Level Virtualization Solution Provider serving our esteemed SLED Clients nationwide.

Datacenter virtualization is the process of creating a modern data center that is highly scalable, available, and secure. With data center virtualization products that are software-defined and highly automated, you can increase IT agility and create a seamless foundation to manage private and public cloud services alongside traditional on-premises infrastructure.

VMware: Data Center Virtualization:

VCS7-STD-C-L4

VS7-EPL-C-L4

It gives us immense pleasure to announce our recent milestone of attaining the VMware Advanced Level at Data Center Virtualization.

Understanding the End Customer environment, numerous client interactions, and multi calls on environmental exams brings in the strength of Saitech.

OEMs partnerships and End Customer relationships are the heart and soul of our team, our relationship begins with a handshake.

Recently, we have executed major VMware Data Center Virtualizations projects for a few of our major clients like Metra IT, Port of Authority Alleghany County, San Clemente, Florence Darlington Technical College.

Adding value to the customers is the only way we add value to ourselves. We are proud to say that our recent quarterly turnover in VMware Data Center Virtualization

Benefits of Data Center Virtualization with VMware.

Modernize for Cloud

Support future evolution with a consistent software stack on-prem that can expand into the public cloud and edge.

Eliminate Silos

Leverage existing investments for use in new cloud environments while eliminating vertical infrastructure silos.

Operate Efficiently

Reduce TCO with automated performance management, optimized capacity utilization, proactive planning, and reduced mean time to resolution (MTTR).

One-Stop Solution for your IT Technology needs. SAITECH INC

Our Greatest Asset is the Customer! Treat each customer as if they are the only ONE!!

About Saitech Inc

Saitech Inc is an innovative value-added supplier for information technology hardware, software, supply chain services to support cloud computing, data center management, data storage, rugged mobility devices, marine electronics, and office equipment. Saitech Inc provides a total solution to IT acquisitions by providing multi-vendor hardware and software along with significant pre-sale and post-sale services. We provide significant value-added services consisting of configuration consulting and design, systems integration, installation of multi-vendor computer equipment, customization of hardware, product technical support, maintenance, and end-user support.


 




While it is very hard task to choose reliable certification questions / answers resources with respect to review, reputation and validity because people get ripoff due to choosing wrong service. Killexams.com make it sure to serve its clients best to its resources with respect to exam dumps update and validity. Most of other's ripoff report complaint clients come to us for the brain dumps and pass their exams happily and easily. We never compromise on our review, reputation and quality because killexams review, killexams reputation and killexams client confidence is important to us. Specially we take care of killexams.com review, killexams.com reputation, killexams.com ripoff report complaint, killexams.com trust, killexams.com validity, killexams.com report and killexams.com scam. The same care that we take about killexams review, killexams reputation, killexams ripoff report complaint, killexams trust, killexams validity, killexams report and killexams scam. If you see any false report posted by our competitors with the name killexams ripoff report complaint internet, killexams ripoff report, killexams scam, killexams.com complaint or something like this, just keep in mind that there are always bad people damaging reputation of good services due to their benefits. There are thousands of satisfied customers that pass their exams using killexams.com brain dumps, killexams PDF questions, killexams practice questions, killexams exam simulator. Visit Our sample questions and sample brain dumps, our exam simulator and you will definitely know that killexams.com is the best brain dumps site.

Which is the best dumps website?
Yes, Killexams is 100 % legit and even fully good. There are several features that makes killexams.com authentic and respectable. It provides up to date and 100 % valid exam dumps containing real exams questions and answers. Price is suprisingly low as compared to a lot of the services online. The questions and answers are up to date on standard basis through most recent brain dumps. Killexams account make and product delivery is really fast. Document downloading is certainly unlimited and incredibly fast. Guidance is avaiable via Livechat and Netmail. These are the features that makes killexams.com a strong website which provide exam dumps with real exams questions.



Is killexams.com test material dependable?
There are several Questions and Answers provider in the market claiming that they provide Actual Exam Questions, Braindumps, Practice Tests, Study Guides, cheat sheet and many other names, but most of them are re-sellers that do not update their contents frequently. Killexams.com is best website of Year 2024 that understands the issue candidates face when they spend their time studying obsolete contents taken from free pdf download sites or reseller sites. Thats why killexams.com update Exam Questions and Answers with the same frequency as they are updated in Real Test. Exam dumps provided by killexams.com are Reliable, Up-to-date and validated by Certified Professionals. They maintain Question Bank of valid Questions that is kept up-to-date by checking update on daily basis.

If you want to Pass your Exam Fast with improvement in your knowledge about latest course contents and topics of new syllabus, We recommend to Download PDF Exam Questions from killexams.com and get ready for actual exam. When you feel that you should register for Premium Version, Just choose visit killexams.com and register, you will receive your Username/Password in your Email within 5 to 10 minutes. All the future updates and changes in Questions and Answers will be provided in your Download Account. You can download Premium Exam Dumps files as many times as you want, There is no limit.

Killexams.com has provided VCE Practice Test Software to Practice your Exam by Taking Test Frequently. It asks the Real Exam Questions and Marks Your Progress. You can take test as many times as you want. There is no limit. It will make your test prep very fast and effective. When you start getting 100% Marks with complete Pool of Questions, you will be ready to take Actual Test. Go register for Test in Test Center and Enjoy your Success.




A00-250 PDF Questions | HH0-220 mock exam | FortiSandbox sample test | 500-210 exam test | CIMAPRA17-BA2-1-ENG questions answers | NCP-MCI practice questions | CRNE exam tips | PB0-200 practice exam | 2B0-011 braindumps | AZ-700 test exam | OutSystems-ARDC test prep | C1000-010 practice exam | Google-AAD free pdf | NS0-162 PDF Braindumps | AZ-720 practice exam | H31-523 Latest Topics | 7495X exam preparation | BCB-Analyst online exam | APSCA braindumps | CPSA-F PDF Download |


5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Practice Questions
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 PDF Questions
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Exam Braindumps
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 study help
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 test
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 exam syllabus
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 certification
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 study help
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 boot camp
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 real questions
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Study Guide
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 course outline
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 education
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 PDF Download
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Exam Questions
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Dumps
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Exam Braindumps
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Study Guide
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 information source
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 PDF Download
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Study Guide
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Exam dumps
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Free Exam PDF
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Practice Test
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 testing
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Free PDF
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 study tips
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 PDF Braindumps
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Test Prep
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 exam syllabus
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Test Prep
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Latest Questions
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 test
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Exam dumps
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 study help
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Free Exam PDF
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 guide
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 exam format
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 exam success
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 course outline
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 teaching
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 dumps
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 guide
5V0-32-19 - VMware Cloud Provider Specialist Exam 2019 Test Prep

Other Vmware Exam Dumps


5V0-41.21 mock exam | 3V0-22.21N cheat sheet | 2V0-21.21 PDF Download | 2V0-01-19 Exam Cram | 1V0-41.20 Dumps | 3V0-21.21 cbt | 5V0-23.20 exam test | 1V0-61.21 test questions | 2V0-51.21 writing test questions | 5V0-32-19 braindumps | 2V0-51.23 exam answers | 5V0-31.22 download | 1V0-71.21 braindumps | 2V0-41.20 test prep | 1V0-31.21 past exams | 3V0-752 practice questions | 2V0-41.23 braindumps | 2V0-71.23 Practice test | 5V0-21.21 free pdf | 2V0-72.22 PDF Questions |


Best Exam Dumps You Ever Experienced


HPE6-A72 PDF Questions | FSMC Question Bank | CRT-251 dumps questions | Salesforce-Loyalty-Management braindumps | H12-311 Dumps | 4A0-116 Latest Questions | CIA-I PDF Braindumps | Servicenow-CIS-RC braindumps | MB-310 exam prep | NCIDQ-CID real questions | PSPO-I download | 200-301 cheat sheet | QAW1301 Study Guide | Nutanix-NCP real questions | SCNP-EN exam questions | ACT Exam Questions | CAU305 real questions | HD0-200 examcollection | ASWB braindumps | NS0-184 past bar exams |





References :


http://killexams-braindumps.blogspot.com/2020/06/are-you-looking-for-5v0-32-19-real-exam.html
https://killexams-posting.dropmark.com/817438/23644371
https://www.instapaper.com/read/1318710589
http://feeds.feedburner.com/SimplyRetainThese5v0-32-19QuestionsBeforeYouGoForTest
https://youtu.be/D-g1nL2TKy8
https://files.fm/f/adkz5kjav
http://killexams1.isblog.net/5v0-32-19-vmware-cloud-provider-specialist-exam-2019-2021-update-question-bank-by-killexams-com-14566780
https://sites.google.com/view/killexams-5v0-32-19-pdf-brain
https://drp.mk/i/ybx7fNY2v



Similar Websites :
Pass4sure Certification Exam dumps
Pass4Sure Exam Questions and Dumps




Back to Main Page