[ad_1]
The White House Office of Information and Regulatory Affairs had some surprises planned for the fall.
One surprise is that instead of one rule, DOD is planning two rules to enforce how government contractors and their subcontractors protect controlled unclassified information in their systems. According to the OIRA agenda, DOD expects to release the final proposed rules in June.
Those eagerly awaiting the next steps for DOD’s Cybersecurity Maturity Model Certification standard may come as a surprise to see two rules instead of one.
But two lines isn’t a bad thing, according to Cyber Accreditation Body CEO Matthew Travis.
The Cyber AB organization oversees the third-party entities and assessors responsible for certifying contractors’ compliance with the CMMC rules after they become final.
Travis and the rest of the CMMC ecosystem expected DOD to announce the time frame for a Title 48 rule, which would add CMMC requirements to DOD’s procurement and acquisition rules. Title 48 refers to the section of the Code of Federal Regulations.
In addition to Part 48, OIRA also announced DOD’s intention to add a Title 32 line that Travis says is a major change. Title 32 is the portion of federal regulation that governs how the Department of Defense operates.
What DOD is saying with Part 32 is that they want to permanently integrate CMMC into defense policy in this country, Travis said. With Part 48, it was just a contractual condition to work with the Pentagon, not an investment in national security.
As Travis sees it, that’s resounding confirmation of CMMC’s purpose and value.
But one possible downside is how the Cyber AB and others expected an interim final rule to come out in March, which would turn into a final rule in about 60 days. OIRA’s agenda now says the proposed regulations for Part 32 and Part 48 will come out in May.
With a proposed regulation, DOD will need to collect and respond to comments, which will add at least six months and perhaps more than a year to the timing of a final rule, he said.
Travis said the lengthy regulatory process of a proposed regulation was disappointing as it now looks like 2024 will be the year CMMC becomes operational.
But these are consistent rules and they will certainly impact how the industry does business, so the department wants to get it right. We want to get it right, Travis said.
Travis is also concerned about the economic viability of the ecosystem of external assessment organizations, trainers, assessors and others who have invested in CMMC over the years.
We want to make sure that all the people who are going to make CMMC make it through this lengthy regulatory process, Travis said.
One possible lifeline is for DOD to recognize the investments made and allow the third-party assessor organizations to conduct joint assessments with the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), which is part of the Defense Contract Management Agency.
The Joint Surveillance Voluntary Assessment program validates compliance with the National Institute of Standards and Technology 800-171 standard, which is the core of CMMC.
While we can’t legally do CMMC assessments, the 3PAOs have been able to do assessments along with DIBCAC, Travis said.
Travis understands that DIBCAC will record the scores from the assessments, which will be converted to CMMC level two once the rules become final.
Travis advises companies to look into the Joint Surveillance Assessment program and not wait for CMMC to become final.
Taking these early steps shows your government customers that you talk and walk, and it shows your employees how much you care about cybersecurity, Travissaid.
So far, 60 companies have signed up to go through the process and seven have completed it.
I expect more to follow, Travis said.
|
Sources 2/ https://washingtontechnology.com/contracts/2023/02/dod-eyes-june-final-cmmc-proposed-rule-release/382938/ The mention sources can contact us to remove/changing this article |
[ad_2]