Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cloud

Navigating CMMC Compliance: The Essential Role of FedRAMP for Defense Contractors

by Kristen Smith
October 15, 2025
in Cloud, Cybersecurity, News
Deltek logo. Deltek outlines how FedRAMP standards simplify CMMC certification by strengthening cloud security.

Deltek outlines how FedRAMP standards simplify CMMC certification by strengthening cloud security.

The Department of Defense’s upcoming enforcement of the Cybersecurity Maturity Model Certification is reshaping how defense contractors approach cybersecurity.

Table of Contents

    • You might also like
    • SBA Unveils Sweeping Size Standard Reforms to Ease Small Business Classification
    • Defense Innovation Unit Unveils Bridge Program
    • Pentagon Memo Seeks Automated Access to Defense Contractor Financial Systems
  • Where FedRAMP and CMMC Meet
  • What FedRAMP Moderate Requires
  • When FedRAMP Becomes Critical
  • Preparing for Implementation

You might also like

SBA Unveils Sweeping Size Standard Reforms to Ease Small Business Classification

Defense Innovation Unit Unveils Bridge Program

Pentagon Memo Seeks Automated Access to Defense Contractor Financial Systems

According to software provider Deltek, Federal Risk and Authorization Management Program standards can simplify one of the most demanding pieces of CMMC compliance: cloud security. Contractors that rely on third-party cloud services to store, process or transmit controlled unclassified information should prioritize FedRAMP status to support CMMC assessments, the company added.

Where FedRAMP and CMMC Meet

CMMC verifies a contractor’s cybersecurity posture for DOD work, while FedRAMP evaluates cloud service providers for use across the federal government. The programs are distinct but connect where contractors use external cloud platforms. Under Defense Federal Acquisition Regulation Supplement 252.204-7012, cloud services handling CUI must have FedRAMP Moderate authorization or an approved equivalency to support CMMC Level 2 or Level 3 requirements.

What FedRAMP Moderate Requires

FedRAMP Moderate authorization entails implementation of extensive security controls, continuous monitoring and an external assessment. Providers unable to secure federal agency sponsorship can pursue FedRAMP Moderate equivalency, which requires the same technical controls and third-party verification but without an agency sponsor. The FedRAMP 20x initiative aims to shorten authorization timelines, though those process improvements remain in rollout.

When FedRAMP Becomes Critical

Deltek explained that FedRAMP requirements apply once CUI leaves internal systems and enters a third-party cloud environment. Contractors pursuing CMMC Level 2 or Level 3 certification must ensure their external providers hold FedRAMP Moderate authorization or equivalency and are listed on the FedRAMP Marketplace, verifying that the providers satisfy 325 security controls and maintain continuous system monitoring.

Deltek highlighted that CMMC and FedRAMP alignment has become a competitive necessity for the defense industrial base. Its Costpoint GovCon Cloud Moderate platform was developed to help contractors meet FedRAMP Moderate equivalency standards, supporting CMMC Level 2 certification and long-term cybersecurity maturity.

Preparing for Implementation

The DOD will finalize CMMC regulations on Nov. 10, setting in motion a phased rollout. Early phases permit self-assessments for some contractors, followed by mandatory third-party certifications. Deltek advises firms to start with a gap analysis against National Institute of Standards and Technology Special Publication 800-171, review their system security plans, confirm FedRAMP authorization for cloud services and ensure accurate reporting to avoid compliance risks.

Deltek has partnered with GovCon Wire for the CMMC Enforcement Starts in November: Why Compliance is Your Ticket to Success Webinar on Oct. 21. Register now!

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

White House, AstraZeneca Sign Agreement to Deliver Lower US Drug Prices

Next Post

Intelligent Waves, Signify Form IllumiConn to Advance Secure Optical Communications

Recommended For You

DOD FutureG Office, NPS Partner on Project to Develop 5G Expertise in Active-Duty Force; Tom Rondeau Quoted

by Jane Edwards
June 13, 2024
Thomas Rondeau_272x270

The Office of the Under Secretary of Defense for Research and Engineering’s FutureG Office and the Naval Postgraduate School have partnered on a project to advance the adoption...

Read moreDetails

Trump Eyes Ken Cuccinelli for Citizenship & Immigration Services Director Post

by Jane Edwards
May 28, 2019
Trump Eyes Ken Cuccinelli for Citizenship & Immigration Services Director Post

President Trump intends to nominate Ken Cuccinelli, former attorney general of Virginia, to serve as the new director of the U.S. Citizenship and Immigration Services within the Department...

Read moreDetails

DARPA, Research Firm Unveil Study on Blockchains & Related Cyber Vulnerabilities

by Christine Thropp
June 22, 2022
DARPA, Research Firm Unveil Study on Blockchains & Related Cyber Vulnerabilities

A Defense Advanced Research Projects Agency-funded study about blockchains and their cybersecurity risks has revealed that several blockchain immutability scenarios resulted from subverting the property of its implementation,...

Read moreDetails

Lawmakers Ask for Briefing on Domestic Violent Extremism-Related Threats to Critical Infrastructure

by Jane Edwards
February 23, 2023
Lawmakers Ask for Briefing on Domestic Violent Extremism-Related Threats to Critical Infrastructure

Three House lawmakers have asked the Department of Homeland Security’s Office of Intelligence and Analysis and the Cybersecurity and Infrastructure Security Agency for a briefing on threats posed...

Read moreDetails

DHS-FBI Report: Hackers Targeted Energy, Manufacturing Facilities

by Ramona Adams
July 7, 2017
DHS-FBI Report: Hackers Targeted Energy, Manufacturing Facilities

A joint report by the Department of Homeland Security and the Federal Bureau of Investigation says hackers have been launching cyber attacks against companies that run nuclear power stations,...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Australia
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • Middle East
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!