Published
In a stunning policy shift, the Department of War (DoW) suspended forthcoming contractual requirements under the Cybersecurity Maturity Model Certification (CMMC) program for defense contractors to obtain third party assessment and certification of their implementation of security protections on the respective information systems of the contractors. As part of that pause, DoW established a CMMC Reform Task Force to conduct a comprehensive review of the program between now and mid-September. The Chief Information Officer for DoW (Kirsten Davies) initiated the review stating that CMMC imposes bureaucratic barriers and red tape on the Defense Industrial Base (DIB) that impede speed to capability delivery.
Author