Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Government Technology

From NIST Information Security Guidelines to CMMC: What Do the New Regulations Entail?

by Sarah Sybert
July 17, 2020
in Government Technology, News, Press Releases
From NIST Information Security Guidelines to CMMC: What Do the New Regulations Entail?

From NIST Information Security Guidelines to CMMC: What Do the New Regulations Entail?

Table of Contents

  • You might also like
  • Navy to Reclassify Virginia Payload Module-Equipped Submarines as SSGNs
  • Space Force Activates 77th Surveillance Squadron for Space-Based Target Tracking
  • IonQ, Sandia National Laboratories Partner on Quantum Technology Development

You might also like

Navy to Reclassify Virginia Payload Module-Equipped Submarines as SSGNs

Space Force Activates 77th Surveillance Squadron for Space-Based Target Tracking

IonQ, Sandia National Laboratories Partner on Quantum Technology Development

With the Department of Defense’s (DoD) new security regulations around the corner, it is imperative for government contractors to stay up to date with how the guidelines and expectations have shifted from NIST SP 800-171 and NIST SP 800-53 to Cybersecurity Maturity Model Certification (CMMC).

As the threat landscape continues to evolve, systems used by the U.S. government, become increasingly popular and attractive targets for cyber attacks (due to the sensitive and critical nature of the information they store), organizations have been forced to take the steps needed to protect the integrity of their systems and the data within them.

The new CMMC will require all contractors that work directly or indirectly on DoD contracts to be certified. By meeting CMMC guidelines, it will prove the company’s IT systems are capable of protecting DOD-sensitive information and will help companies gain a competitive advantage.

The regulation will build upon existing frameworks from NIST. CMMC outlines a 5-tier certification model for government contractors to ensure they establish the controls needed to protect sensitive data including Federal Contract Information and Controlled Unclassified Information (CUI).

The 5 certification tiers in CMMC range from basic controls, likely appropriate for smaller subcontractors, to highly sophisticated, state-of-the-art controls, likely appropriate only for the largest, strategic contractors.

Level 1 indicates a contractor has basic cyber hygiene and can safeguard FCI, level 3 indicates a contractor has good cyber hygiene and is capable of protecting CUI in compliance with NIST SP 800-171 pursuant to the existing DFARS 252.204-7012.

For companies to attain a level 4 and 5 certification will require that are not only protecting CUI, but also reducing the risk of ATPs. CMMC will draw upon NIST’s new SP 800-171B’s enhanced cybersecurity requirements, which are intended for critical programs and high-value assets.

Regardless of the certification level, all government contractors and subs with access to sensitive data must be certified, with CMMC, there is no self-certification.

Full implementation of CMMC has been projected to take several years because it will not apply to contractors retroactively. The DoD has suggested it may be 2026 before CMMC is incorporated into all DoD contracts as many recently issued contracts will come up for renewal or recompetition. Going forward, the CMMC model will be updated at least annually to keep up with changing threat environments and technological capabilities.

Potomac Officers Club will host its CMMC Forum 2020 on April 2. Click here to register for the event.

From NIST Information Security Guidelines to CMMC: What Do the New Regulations Entail?

Katie Arrington, chief information security officer at the Office of the Assistant Secretary of Defense for Acquisition and a 2020 Wash100 Award recipient, will serve as a keynote speaker at the CMMC Forum 2020. She will address the CMMC’s timeline, how the certification process could change and will provide a memorandum of understanding with a newly established CMMC accrediting body.

A full expert panel will include Ty Schieber, senior director of executive education and CMMC-AB chairman of the University of Virginia and Richard Naylor of the Defense Counterintelligence and Security Agency (DCSA) among other members of the federal sector and industry.

Register here to join Potomac Officers Club for its CMMC Forum 2020 on April 2nd to learn about the impact DoD’s CMMC will have on cybersecurity practices, supply chain security and other aspects of the federal market.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

Smithsonian Gallery Features HawkEye 360’s Pathfinder in Air, Space Museum Exhibition; John Serafini, James David Quoted

Next Post

Roy Azevedo, President of Raytheon Space & Airborne Systems, Receives First Wash100 Award From Jim Garrettson, CEO of Executive Mosaic

Recommended For You

RTX Business Makes Progress on Navy Hypersonic Missile Project; Colin Whelan Quoted

by Ireland Degges
May 14, 2024
Colin Whelan_272x270

RTX’s Raytheon business has concluded a technical review and prototype fit-check in phase one of a U.S. Navy carrier-based high-speed missile development program. This milestone is a step forward...

Read moreDetails

Sen. Tom Carper Asks OMB for Info on Federal Cyber Defense Tech Acquisition Process

by Mary-Louise Hoffman
April 11, 2016
Sen. Tom Carper Asks OMB for Info on Federal Cyber Defense Tech Acquisition Process

Sen. Tom Carper has asked Office of Management and Budget Director Shaun Donovan to provide information about OMB's efforts to help agencies accelerate their procurement and implementation of cyber defense tools....

Read moreDetails

Mark Esper: Army Looks to Streamline Capability Delivery to Soldiers

by Scott Nicholas
December 8, 2017
Mark Esper: Army Looks to Streamline Capability Delivery to Soldiers

U.S. Army Secretary Mark Esper has said the service branch plans to streamline the process of delivering capabilities to warfighters in the field, Defense News reported Thursday. Esper...

Read moreDetails

Ashton Carter: US-Led Coalition Partners Reaffirm Commitment to Anti-IS Group Efforts

by Ramona Adams
July 26, 2016
Ashton Carter: US-Led Coalition Partners Reaffirm Commitment to Anti-IS Group Efforts

Ashton Carter Defense Secretary Ashton Carter has said the U.S.-led coalition against the Islamic State militant group has formed new plans and commitments to support counter-IS efforts during a meeting...

Read moreDetails

FCC Warns Anew Against Chinese Communications Gear Posing National Security Risks

by Arthur McMiler
October 15, 2025
FCC logo. Agency renewed its warning on communication gear and services posing national security risks

The Federal Communications Commission has renewed its warning against the use of communications equipment and services on its Covered List that pose risks to U.S. national security. Much of...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!