Navigating the Cybersecurity Maturity Model Certification (CMMC): Ensuring Compliance in the Defense Supply Chain

The Cybersecurity Maturity Model Certification (CMMC) is a streamlined and centralized cybersecurity framework created by the U.S. Department of Defense to support contractors in defense supply chain compliance and security efforts.

Based on the types of data they manage—which is determined in part by the agency they work with—defense contractors have to have certain kinds of IT security and privacy controls in place, and if relevant, certain clearance levels. However, some types of data don’t require special security clearance but still serve an essential purpose for the DoD and associated agencies.

Federal Contract Information (FCI): This information is created as part of the working relationship between contract vendors and defense industries. While it isn’t protected by security clearance, it is still considered an important part of defense operations.

Controlled Unclassified Information (CUI): Defense agencies use or create this information as part of their operations. While it also isn’t classified, it is a critical part of defense operations (more so than FCI) and is deemed subject to cybersecurity control.

The CMMC 2.0 model is currently just a publication and undergoing review and rulemaking processes. It is expected to finish that process in 9 to 24 months. In the meantime, the CMMC-AB still honors and operates under version 1.0 audits and certifications.

 

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Lancez-vous.

Il est facile de commencer à garantir la conformité réglementaire et à gérer efficacement les risques avec Kiteworks. Rejoignez les milliers d'organisations qui ont confiance dans la manière dont elles échangent des données privées entre personnes, machines et systèmes. Commencez dès aujourd'hui.

Jetzt loslegen.

Es ist einfach, mit Kiteworks die gesetzliche Vorgaben einzuhalten und Risiken effektiv zu managen. Schließen Sie sich den Tausenden von Unternehmen an, die sicher sind, wie sie vertrauliche Daten zwischen Personen, Maschinen und Systemen austauschen. Beginnen Sie noch heute.

Comienza ahora.

Es fácil comenzar a asegurar el cumplimiento normativo y gestionar eficazmente los riesgos con Kiteworks. Únete a las miles de organizaciones que confían en cómo intercambian datos confidenciales entre personas, máquinas y sistemas. Empieza hoy mismo.

まずは試してみませんか?

Kiteworksを使用すれば、規制コンプライアンスの確保とリスク管理を簡単に始めることができます。人、機械、システム間でのプライベートデータの交換に自信を持つ数千の組織に参加しましょう。今すぐ始めましょう。

Share
Tweet
Share
Explore Kiteworks