Well, the day(s) some people said would never come are here: 32 CFR Part 170, the Cybersecurity Maturity Model Certification (CMMC) Program, hit the Federal Register as a Final Rule on October 15 and is effective TODAY (December 16, 2024). It’s really happening. If you store, process, transmit, or generate Federal Contract Information (FCI) and/or Confidential Unclassified Information (CUI), the day is coming soon (as early as 2025, maybe a little later) when you will have to prove that you have the required security program and controls in place to protect that FCI and CUI. But, since you have had these controls in place since 2018 as required by the DFARS regulation, this should be a piece of cake, right…?
Now that the Program is formally established, all of the roughly 63 existing Certified 3rd-Party Assessor Organizations (C3PAOs), plus all the CMMC Certified Assessors (CCAs), have to be re-certified under the Final Rule. If you are an Organization Seeking Certification (OSC) needing a Level 2 assessment by a C3PAO, expect this to impact how quickly you can get your formal assessment on a C3PAO’s schedule. This is in addition to what we’ve been told is already a significant backlog due to the relatively small number of C3PAOs and CCAs relative to the large number of OSCs. Also, the Final Rule extended Phase 1 of the program rollout from six months to twelve months.
Here is the program rollout timeline as defined in 32 CFR Part 170.3. “Self,” “C3PAO,” and “DIBCAC” refer to the entity that will perform the associated assessment for the indicated CMMC Level.
Do you have FCI or CUI? Only your DoD Contracting Officer and Program Office (if you are a prime contractor) knows for sure and can make that determination. Are you exposed to FCI or CUI by a prime? If you’re not sure, get that definitive answer before you do anything else. If you are subject to CMMC, here is what you need to do right now:
As an RPO, GuidePoint Security can provide expert guidance with your CMMC compliance efforts. GuidePoint offers CMMC gap assessment and advisory services, delivered by Registered Practitioner(s) (RP) and Registered Practitioner Advanced (RPA) consultants with operations backgrounds who understand how to apply the CMMC controls to your environment, as well as advise on figuring out the in-scope environment and any changes/additions need to close compliance gaps. A gap assessment can be viewed as a “practice run” for formal CMMC certification by a C3PAO.
Dan Mengel
Practice Director, Compliance,
GuidePoint Security
Dan Mengel, Practice Director at GuidePoint Security, began his career in the security industry in 2000. He has delivered high-quality consulting services, directly and by leading others, in the areas of information security program architecture, security policy development, and security vulnerability, risk, and compliance assessments. He has developed sales and delivery processes and documentation templates for all of these engagement types. Dan is currently leading GuidePoint’s Compliance team in delivering assessment and advisory services for multiple information security standards. He also has significant prior experience designing and integrating security technology solutions from Cisco, Check Point, Websense, RSA, and others.
Dan earned a Bachelor of Science degree in Computer Information Systems from Goldey-Beacom College and holds several recognized information security industry certifications.