Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

What GovCons Need to Know About CMMC 2.0

by Pat Host
May 12, 2025
in Cybersecurity, News
What GovCons Need to Know About CMMC 2.0

CMMC 2.0 is moving forward at the Department of Defense despite a potentially high-ranking official promising to review the effort if confirmed.

Table of Contents

    • You might also like
    • Trump Signs Secure America Act Into Law
    • Jennifer Franks Appointed Acting Chief Technology Officer at GAO
    • Navy Seeks Participants for Software Hackathon
  • Who Is DOD’s Michael Duffey?
  • What Is SWFT?
  • Key CMMC 2.0 Impacts for GovCons

You might also like

Trump Signs Secure America Act Into Law

Jennifer Franks Appointed Acting Chief Technology Officer at GAO

Navy Seeks Participants for Software Hackathon

Cybersecurity Maturity Model Certification 2.0 is DOD’s framework for assessing contractor implementation of cyber requirements and improving their protection of unclassified information in the DOD supply chain. The program provides DOD with better assurance that government contractors and subcontractors are meeting the cybersecurity requirements for nonfederal systems processing controlled unclassified information—a.k.a. CUI—or federal contract information. The final CMMC 2.0 rule made it a requirement for bidding on defense contracts.

Katie Arrington, performing the duties of DOD chief information officer and a previous Wash100 Award winner, is pushing CMMC 2.0 forward after founding the program during the first administration of President Donald Trump. Contractors previously were only required to self-certify compliance with National Institute of Standards and Technology Standard 800-171, which provides federal agencies with recommended security requirements for protecting the confidentiality of CUI.

Get insights into how the Trump Administration will implement CMMC 2.0 at the Potomac Officers Club’s 2025 Cyber Summit on Thursday. Meet, learn and connect with DOD leaders, defense experts, research officials and industry executives at this can’t-miss event. Time is running out, sign up today!

Contractors are now required to use a third-party audit for CMMC 2.0 certification and many are unhappy about it.

“If you go on LinkedIn one more time and tell me how hard CMMC is, I’m going to beat you,” Arrington said, as reported by Washington Technology.

Who Is DOD’s Michael Duffey?

Contractors upset about CMMC 2.0 may receive relief from Trump nominee Michael Duffey, who was tabbed to be DOD undersecretary for acquisition and sustainment. Duffey told senators during his confirmation hearing that he would review CMMC 2.0 if confirmed. Redspin, a provider of cyber services involving CMMC 2.0, issued a report on GovCon preparedness for CMMC 2.0, saying most respondents did not feel ready for its requirements.

Duffey said in prepared remarks that it is important to improve cyber among defense GovCons without putting unnecessary requirements on small and medium-sized businesses. While these contractors, he said, can be more vulnerable to cyber attacks because of fewer financial resources, they play a pivotal role in supporting DOD.

“If confirmed, I will review the current requirements of the CMMC program and evaluate options to improve the requirements and implementation so that industry can affordably maintain pace with current cybersecurity best practices,” Duffey said.

What Is SWFT?

Arrington recently kicked off a new effort to improve how DOD acquires software that leverages CMMC 2.0. In a memo issued April 24, Arrington directed the development of the Software Fast-Track Initiative, or SWFT.

This will define clear and specific cyber and supply chain risk management requirements and stringent software security verification processes. It will also define secure information-sharing procedures and federal government-led risk determinations to accelerate cyber authorizations for faster software adoption.

Arrington said software providers will be required to provide her with DOD’s base risk scores on 12 characteristics of range, including CMMC 2.0. SWFT will use AI to evaluate contractor certifications for faster processing.

Key CMMC 2.0 Impacts for GovCons

CMMC 2.0 is a dramatic shift in how defense contractors must approach cyber compliance, according to a GovCon expert. Payam Pourkhomami, OSIbeyond president and CEO, said in GovCon Wire that contractors must meet one of three certification levels based on the sensitivity of the information they handle.

Level 1 requires annual self-assessments for federal contract information. Level 2 makes contractors either self-assess or provide third-party certification for CUI. The most strict, Level 3, requires DOD assessments for critical programs and high-value assets.

Non-compliance with CMMC 2.0, particularly when handling CUI, can lead to big consequences for GovCons. These include financial penalties, contract cancellations and long-term reputational damage. 

GovCons can learn more about consequences for CMMC 2.0 non-compliance at the Potomac Officers Club’s 2025 Cyber Summit. Held on Thursday at the Marriott Fairview Park in Falls Church, Virginia, the Cyber Summit is the best opportunity for GovCons to learn directly from federal cyber leaders from the CIA, DOD, U.S. Air Force and the DOD Cyber Crime Center, among others. Few tickets remain; don’t miss out!

What GovCons Need to Know About CMMC 2.0
Share5Tweet19

Recommended For You

Trump Signs Secure America Act Into Law

by Jane Edwards
June 11, 2026
White House logo. President Trump signed into law a measure that provides funding for ICE and CPB through FY 2029.

Trump has signed the Secure America Act into lawThe measure provides funding for DHS, ICE and CBP through fiscal year 2029The 2026 Homeland Security Summit will examine AI,...

Read moreDetails

Jennifer Franks Appointed Acting Chief Technology Officer at GAO

by Miles Jamison
June 11, 2026
Jennifer Franks. The IT leader has been named acting chief technology officer at the Government Accountability Office.

The Government Accountability Office has named Jennifer Franks as acting CTOFranks will help lead technology, data, innovation and cybersecurity initiatives across the agencyShe will bring nearly two decades...

Read moreDetails

Navy Seeks Participants for Software Hackathon

by Jane Edwards
June 11, 2026
Department of the Navy seal. DON has called on technical professionals to participate in a software hackathon in San Diego.

DON has announced a four-day software hackathon in San DiegoThe event seeks technical experts to develop software-centric, data-driven solutions to operational challengesThe 2026 Navy Summit will feature panel...

Read moreDetails

New DOE-Argonne Partnership Targets Faster Commercialization of US Manufacturing Technologies

by Kristen Smith
June 11, 2026
ANL logo. DOE and ANL have launched the National Science-at-Scale Collaborative.

DOE and ANL have launched the National Science-at-Scale Collaborative to help U.S. firms move critical materials and chemical manufacturing tech into domestic production fasterParticipating companies will get access...

Read moreDetails

White House Plans Meeting With Defense CEOs to Accelerate Weapons Production

by Miles Jamison
June 11, 2026
White House. White House has announced plans for a meeting with major defense companies to accelerate weapons production.

The White House is preparing to meet with defense industry leaders to discuss increasing weapons productionGrowing demand from overseas conflicts has intensified pressure on U.S. munitions inventoriesThe meeting...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!