<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Cybersecurity Maturity Model Certification &#8211; Technology for Learners</title>
	<atom:link href="https://technologyforlearners.com/tag/cybersecurity-maturity-model-certification/feed/" rel="self" type="application/rss+xml" />
	<link>https://technologyforlearners.com</link>
	<description>Learn to use Technology and use Technology to Learn</description>
	<lastBuildDate>Sat, 30 Jul 2022 17:14:35 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>

<image>
	<url>https://technologyforlearners.com/wp-content/uploads/2022/12/cropped-Logo-symbol-32x32.jpg</url>
	<title>Cybersecurity Maturity Model Certification &#8211; Technology for Learners</title>
	<link>https://technologyforlearners.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>The Cybersecurity Maturity Model Certification (CMMC): Everything You Need to Know</title>
		<link>https://technologyforlearners.com/the-cybersecurity-maturity-model-certification-cmmc-everything-you-need-to-know/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-cybersecurity-maturity-model-certification-cmmc-everything-you-need-to-know</link>
					<comments>https://technologyforlearners.com/the-cybersecurity-maturity-model-certification-cmmc-everything-you-need-to-know/#respond</comments>
		
		<dc:creator><![CDATA[Will Fastiggi]]></dc:creator>
		<pubDate>Thu, 06 Jan 2022 12:37:36 +0000</pubDate>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[CMMC]]></category>
		<category><![CDATA[CMMC Compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Cybersecurity Maturity Model Certification]]></category>
		<guid isPermaLink="false">http://technologyforlearners.com/?p=3616</guid>

					<description><![CDATA[<img width="150" height="150" src="https://technologyforlearners.com/wp-content/uploads/2022/01/Cybersecurity-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="" decoding="async" />The Cybersecurity Maturity Model Certification (CMMC) procedure has seen several changes since its launch in early 2020 and is currently evolving. At its foundation, CMMC is intended to guarantee that all defence contractors adhere to a minimum degree of cybersecurity hygiene to secure sensitive defence information.  As part of CMMC compliance, all DOD contractors will [&#8230;]]]></description>
										<content:encoded><![CDATA[<img width="150" height="150" src="https://technologyforlearners.com/wp-content/uploads/2022/01/Cybersecurity-150x150.jpg" class="attachment-thumbnail size-thumbnail wp-post-image" alt="" decoding="async" /><p><span data-contrast="auto">The Cybersecurity Maturity Model Certification (CMMC) procedure has seen several changes since its launch in early 2020 and is currently evolving. At its foundation, CMMC is intended to guarantee that all defence contractors adhere to a minimum degree of cybersecurity hygiene to secure sensitive defence information.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">As part of CMMC compliance, all DOD contractors will need to go through independent cybersecurity evaluations. The CMMC Accreditation Body, a non-profit organisation distinct from the Department of Defence, is responsible for training and certifying Certified Third-Party Assessor Organisations (C3PAOs), who will subsequently assess contractors’ cybersecurity. CMMC compliance is cover</span><span data-contrast="auto">ed in detail here, as this </span><span data-contrast="auto">post discusses CMMC in general and the processes required to attain the appropriate CMMC level.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 20">What is CMMC Compliance?</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Cybersecurity Maturity Model Certification primarily protects DoD supply chain CUI (</span><a href="https://www.epa.gov/cui/controlled-unclassified-information-cui-program-frequently-asked-questions-faqs#:~:text=Controlled%20Unclassified%20Information%20(CUI)%20is,Atomic%20Energy%20Act%2C%20as%20amended." target="_blank" rel="noopener"><span data-contrast="none">Controlled Unclassified Information</span></a><span data-contrast="auto">). All information or data developed or owned by the government or another organisation on the government’s behalf is referred to as CUI under DoD definitions of CUI.  </span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">The range of data in this analysis includes financial, legal, intelligence, infrastructural, export regulations, and a slew of other considerations. The CMMS framework evaluates a DoD vendor’s capabilities, comprising standard evaluation methods and processes.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 20">Why Is CMMC Important?</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Cybercrime is predicted to cost the world economy more than $600 billion each year. By relying on a broad network of contractors to carry out its task, the Department of Defence enhances the overall risk profile of the DIB by entrusting each of them with important information. That’s because they know how much harm cybercrime poses to their subcontractors, many of which are little firms without the financial wherewithal to fight back.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">In light of this, the Department of Defence (DoD) has launched </span><a href="https://makeiteffortless.com/%20" target="_blank" rel="noopener"><span data-contrast="none">CMMC compliance</span></a><span data-contrast="auto"> to help its worldwide contractor embrace industry standards in cyberspace with the best strategies.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 20">What are the CMMC Levels?</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">For an organisation to perform work for the Department of Defence, the CMMC maturity level depends on what information it will be working with. Here is an overview of the CMMC methodology and standards for each level to assist you in determining the right CMMC level for your firm.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 30">CMMC Level 1 &#8211; Basic Cyber Hygiene</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Level 1 demands that an organisation implement the prescribed procedures. There is no assessment of process maturity for Level 1 because these activities may be performed solely on an ad-hoc basis without documentation.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Additionally, level 1 includes FCI protection, but only per the minimum safeguarding criteria of 48 CFR 52.204-21.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 30">CMMC Level 2 &#8211; Intermediate Cyber Hygiene</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">A company must have established and documented methods and policies to lead its CMMC initiatives at Level 2. Repetitive practice is made possible through recording procedures. When an organisation’s procedures are codified and put into practice, it matures its capabilities.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Level 2 is a stepping stone between NIST SP 800-171 and Level 3 and incorporates various standards and guidelines. Due to the transitory nature of this level, a subset of activities refers to CUI protection.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 30">CMMC Level 3 &#8211; Good Cyber Hygiene</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Managing practice implementation efforts requires Level 3 organisations, which means creating, maintaining, and allocating resources per a plan. It’s possible to incorporate everything from the project’s objectives, goals, resources, training, and involvement of key stakeholders in the plan.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">NIST SP 800-171 security requirements are included at this level, and 20 additional practices reduce risk. Any contractor must meet level 3 requirements with a DFARS clause in their contract. In addition to the security standards outlined in NIST SP 800-171, DFARS clause 252.204-7012 specifies additional requirements.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 30">CMMC Level 4 &#8211; Proactive Cybersecurity</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">At this level, an organisation is obliged to review and assess the efficacy of its procedures. Additionally, companies can take helpful action when necessary and communicate with upper-level  management regularly about their present status or issues.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">This level incorporates a portion of the improved security standards from Draft NIST SP 800-171B and other industry practices in the cyber security field. Companies adopt various strategies, approaches, or procedures since APTs are difficult to recognise and respond to</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="auto">CMMC Level 5 &#8211; Advanced Cybersecurity</span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">An organisation must standardise and improve processes across the board to reach level 5. Level 5 establishes a secure CUI against APTs. These extra procedures enhance cybersecurity’s scope and efficiency.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 20">Who is Required to Adhere to CMMC?</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Any defence firm that conducts business with the Department of Defence will have to meet one of the five CMMC levels in the near future. All prime contractors, subcontractors, and suppliers in the supply chain must meet this standard.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">The DoD contract specifies the level of compliance each contractor must satisfy. Other subcontractors may have to fulfil CMMC Level 1 requirements while the contractor must meet CMMC Level 3.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">CMMC Accreditation Body is currently working with the DoD to guarantee that impartial third-party assessments are accessible for contractors at each CMMC level.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 20">What is the Process for Attaining CMMC Certification?</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">The CMMC does not permit self-certification by companies. Third-party certification will be required for government contractors and individuals working with government agencies. A third party will assess their present security procedures and processes to determine their maturity and degree of preparation.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">To get certified by the CMMC standard, most firms will conduct a complete audit before starting the process. As part of the CMMC framework, managed services providers may assist companies in determining whether or not changes can be made and organising the certification process itself. Upon completion of the certification process, a managed services provider can also devise a strategy for enhancing the certification level, should this be necessary.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Due to recent changes in standards, CMMC certification is one of the most popular </span><a href="https://www.coursera.org/articles/popular-cybersecurity-certifications" target="_blank" rel="noopener"><span data-contrast="none">forms of security certification</span></a><span data-contrast="auto"> that an organisation may obtain. The firm will be allowed to bid on federal contracts and deal with classified material if it receives CMMC accreditation.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><b><span data-contrast="none"><span data-ccp-parastyle="heading 20">Who is Directly Impacted by CMMC?</span></span></b><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:40,&quot;335559739&quot;:0,&quot;335559740&quot;:259}"> </span></p>
<p><span data-contrast="auto">Anyone who does business with the Department of Defence (DoD) will eventually be obliged to get CMMC accreditation. This definition includes all suppliers from small enterprises to large corporations and those from countries throughout the world, and those that manufacture commercial goods.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">The CMMC Accreditation Body supervises the certification process with the Department of Defence. Accrediting third-party CMMC assessment organisations and assessors to evaluate and certify CMMC levels has been a joint effort by these organisations.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">All new contracts given to DIB vendors or subcontractors must show CMMC compliance under the revised guidelines. Basically, this applies to every entity that deals with CUI in any way.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Commercial-off-the-shelf product manufacturers are the only ones free from CMMC certification requirements.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">The Cybersecurity Maturity Model Certification (CMMC) is becoming more important for contractors seeking to conduct business with the United States Department of Defence (DoD). In the near future, CMMC criteria will begin to emerge in DoD contracts and will be a component of all contracts by 2025. Contracting companies must begin the process of gaining CMMC as soon as possible in order to be eligible for future DoD contracts.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Before CMMC certifications are available, contractors processing sensitive DoD information must now establish, monitor, and certify their own security standards.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Protocols for safeguarding CUI and disclosing security incidents fall under this category.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Much like Dfars, it has several stages of maturity, however in order to be certified by a third-party assessor organisation as having achieved conformity with the various stages of maturity, the Dfars standard must be met first (C3PAO). On the other hand, contractors can evaluate their own cybersecurity compliance posture under DFARS.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
<p><span data-contrast="auto">Certification by an independent third party agency confirms a contractor has put in place all of the necessary safeguards for the protection of sensitive data.   When CMMC is fully implemented on DoD contracts, it will totally replace DFARS, although the DoD is currently working out the finer details. This post discusses CMMC in general and the processes required to attain the appropriate CMMC maturity level.</span><span data-ccp-props="{&quot;201341983&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:120,&quot;335559740&quot;:360}"> </span></p>
]]></content:encoded>
					
					<wfw:commentRss>https://technologyforlearners.com/the-cybersecurity-maturity-model-certification-cmmc-everything-you-need-to-know/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
