Department of Defense Moves up Timeline for CMMC Compliance

July 22, 2022
In 2021, the Department of Defense announced a new strategic effort to provide enhanced cybersecurity efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards to protect sensitive data during the design, build and operations of DoD facilities. Through research grants by the John R. Gentille Foundation and Electri Foundation, a video series has been produced by MCAA’s Chief Security Fanatic, Nick Espinosa to provide an update on the process. Recently, the DoD has updated their timeline for CMMC and plan on publishing their initial requirements in March 2023 for the 60-day review and comment period. Once completed, the first phase of CMMC compliance will go into effect with a self-assessment that must be completed by every contractor working on a DoD project.

In 2021, the Department of Defense announced a new strategic effort to provide enhanced cybersecurity efforts for their building projects going forward. The Cybersecurity Maturity Model Certification (CMMC) will ensure accountability for companies to implement cybersecurity standards to protect sensitive data during the design, build and operations of DoD facilities. Through research grants by the John R. Gentille Foundation and Electri Foundation, a video series has been produced by MCAA’s Chief Security Fanatic, Nick Espinosa to provide an update on the process.

Recently, the DoD has updated their timeline for CMMC and plan on publishing their initial requirements in March 2023 for the 60-day review and comment period. Once completed, the first phase of CMMC compliance will go into effect with a self-assessment that must be completed by every contractor working on a DoD project. The second phase, which requires third-party auditing of a contractor’s cybersecurity practices has not yet been established, but projected to take place in 2025. 

The CMMC program includes cyber protection standards for companies in the defense industrial base (DIB). By incorporating cybersecurity standards into acquisition programs, CMMC provides the Department assurance that contractors and subcontractors are meeting DoD’s cybersecurity requirements. For plumbing, mechanical and service contractors working on DoD projects, this means that they will have to document and upgrade safe data practices, increase the security level of their software and certify that these standards have been met through third-party auditors. 

Eleven new cybersecurity best practices videos have been added to the series and as the standard develops, the John R. Gentille Foundation will provide additional videos and materials. These are practical for all contractors, not just those working on DoD projects in order to protect your business and your customers. This includes:

Related Articles
Emergencies, disasters, accidents and injuries can occur at any time, usually without warning. MCAA’s Emergency Procedures will help you develop an emergency action plan to enable you and your employees to act quickly and decisively in the event of an emergency. It’s just one of MCAA’s educational resources that are free to MCAA members as a benefit of membership.…
More than 10,000 serious construction-related eye injuries happen each year, yet these injuries are preventable with proper eye protection. Help workers to understand why eye protection is critical. To celebrate 20 years of safety excellence, MCAA is releasing five impactful videos in 2023 to help improve safety & health across the entire industry.…
Did you take MCAA’s ASSE 12020: Environment of Care, Infection Control and Construction Risk Assessment Professional Qualification Standard certification class in April 2020? If so, your certification is set to expire, and MCAA has prepared a free 2-hour recertification course through ASSE International. The goal of the ASSE 12020 personnel certification is to provide end users with contractors and technicians who can work as valuable members of construction risk assessment teams. You can assist in protecting building occupants from pathogens and other potential construction hazards while at the same time preventing outbreaks. Following the course, attendees will need to pass a recertification exam. The cost of the exam is $110. ASSE will provide additional details during the webinar. Join MCAA and ASSE on Thursday, April 13 from 1:00 PM – 3:00 PM Eastern to take the first step toward your recertification.…
MCAA’s Virtual Trade Show connects our contractor members with the members of MCAA’s Manufacturer/Supplier Council.…

Time is running out! f you want to stay informed & involved in the legislative & regulatory policy issues that impact your construction business, register for the Construction Employers of America (CEA) National Issues Conference! http://ow.ly/RCQY50NcwGa

Take the first step toward your ASSE 12020 recertification. Join MCAA and ASSE on Thursday, April 13 from 1:00 PM – 3:00 PM Eastern for a free recertification course. Follow the link to learn more and register.

https://register.gotowebinar.com/register/4440938889373353816

Looking for the latest from @DEWALTtough and Harris Products Group? Find it in MCAA’s Virtual Trade Show!

http://ow.ly/sYuo50NmEtX

REGISTRATION OPEN – MCAA's WiMI Conference will be held June 12-14 in Nashville, TN and is an excellent opportunity for all women to DISCOVER  their potential. Learn more and register today http://ow.ly/CCw250NnbaC

Load More...