Request Demo

Current CMMC Milestones For 2020

down-arrow

The Cybersecurity Maturity Model Certification (CMMC) framework is the upcoming revamp of the Department of Defense (DoD) cybersecurity requirements to secure the defense industrial base (DIB) and supply chain. The certification levels, tiers, will range from basic to advanced and adaptive cybersecurity programs in a greater effort to secure and protect controlled unclassified information (CUI). All members of the DIB and DoD contractors, ranging from small businesses to prime contractors, must meet the required CMMC level to maintain existing and win new contracts.

What Are The Current CMMC Milestones For 2020?

To provide some clarity around the Cybersecurity Maturity Model Certification (CMMC)'s milestones, we've written up a high-level outline of important dates from the release of V1 in January 2020 and probable deadlines you should consider when implementing and complying with CMMC. 

Disclaimer: Please note this information may change in accordance with the CMMC Accreditation Board (CMMC AB) CMMC decision making and information sharing process.

Q1 2020 - Version 1.0 of the Cybersecurity Maturity Model Certification description was published to the public on January 31, 2020.

Soon after CMMC V.1.0 was released, the independent CMMC Accreditation Board (CMMC AB) started coordinating assessor training and accreditation plans in partnership with CMMC stakeholders to release training for CMMC Levels 1, 2, and 3 by the end of Q1 2020 (March 31, 2020).

Q2 2020 - During June, the first set of RFIs reflecting CMMC will be released in time for the CMMC AB to start training independent CMMC Level 1, 2, and 3 auditors.

CMMC Milestones After 2020 and Beyond?

  • Vendors and suppliers should expect a significant amount of training, assessment, and audit activity in the third quarter.
  • CMMC Levels 4 and 5 certification training will begin in September 2020.
  • According to Pentagon Acquisition Chief Ellen Lord - Starting in Q4 2020, ALL contracts need to include the appropriate CMMC certification in their award criteria.
    • To phase in CMMC changes and related contracts, the DoD intends to limit the CMMC requirement to just 10 RFIs and RFPs in 2020. The remaining new contract requirements will roll out in 2021 with the goal being - ALL new DoD contracts beginning in FY 2026 will meet the CMMC requirement.

According to Arrington, the DoD expects CMMC third-party assessors to certify about 1,500 vendors in 2021, 7,500 more in 2022, and 25,000 more by 2023.

Your CMMC Compliance Needs

CyberSaint is here to support every step of your CMMC readiness journey in many ways, like keeping you updated on the latest CMMC news and providing CMMC readiness assessments and or training. See why leading compliance teams are choosing CyberStrong to prepare for CMMC

 

You may also like

Prioritizing Cyber Risk Management ...
on July 6, 2020

The risk posed to organizations by cybersecurity threats is large and increasing. COVID-19 related adjustments at home and at work, the move to a remote workforce, and increasing ...

Alison Furneaux
Critical Capabilities of IT Risk ...
on June 22, 2020

Risk management is rapidly becoming the foundation of organizational security efforts, replacing checklist compliance as a cornerstone of a successful security program. This shift ...

What is Cyber Risk Management
on June 21, 2020

Risk management is a fundamental component of any successful organization and has been since the dawn of corporations as we know them. The primary function of risk management as a ...

Cybersecurity Risks Have Changed ...
on June 10, 2020

CyberSaint will host a cybersecurity risk management webinar, live on June 17th, 2020at 12:00pm EST and available on-demand when you register to attend with this link.  The recent ...

Alison Furneaux
What is NIST SP 800 30
on June 10, 2020

The National Institute of Standards and Technology’s Cybersecurity Framework (CSF) is known in cybersecurity as the gold standard framework for computer security guidance, it can ...

Cybersecurity Maturity Model ...
on July 1, 2020

Why DFARS / NIST SP 800-171? A few years back, the United States Department of Defense (DoD) released a new regulation, a Defense Federal Acquisition Regulation Supplement, or ...