Another big story I didn’t want to miss from the closeout of 2023 was the release of the final rule set for CMMC 2.0.
CMMC 2.0, the Cybersecurity Maturity Model Certification version, will consolidate maturity levels, align with NIST frameworks, and allow for flexible contractor security assessments. It aims to address the increasing cyberattacks on the Pentagon’s supply chain and improve the protection of sensitive information. Contractors that fail to meet CMMC 2.0 requirements will not be awarded DOD contracts.
The Defense Department has released a proposed rule outlining a four-phase approach to implement the Cybersecurity Maturity Model Certification (CMMC) program. The rule establishes requirements for assessing defense contractors’ implementation of security protections and aims to ensure compliance through independent third-party assessors certified by the DoD. The phased implementation plan will gradually introduce CMMC requirements, with full implementation expected by October 1, 2026. The proposed rule also introduces affirmation requirements and allows for conditional self-assessments and certifications through Plans of Action and Milestones (POA&Ms).
I also spotted an expert on Reddit offering insights.
The CMMC final rule has been submitted to the Federal Register, and several requirements need to be prepared for, including the need for external service providers to have their final assessment certification before the OSC they’re supporting can achieve their own certification. Additionally, tools should be FEDRAMP moderate certified, there will be effectively no POAMS, and the estimated cost of the C3PAO assessment process alone is around $35k. The DoD admits they’re roughly 70% compliant with the rule they demand others to follow. The post stresses the importance of understanding NIST 800-171 and the implications of FedRAMP Moderate equivalency.
I’ll observe for those not doing DoD work, this is a useful framework, although pretty stringent.
MSP tools being FEDRAMP certified is a big deal. We’re either going to see a move by vendors to get FEDRAMP certified, or a fracturing of the toolkits. I’m predicting that MSPs will go either in or out when it comes to DoD, in a serious way.
For MSPs serving the defense sector or considering entering this market, understanding the CMMC 2.0 framework is crucial. It may lead to increased demand for MSPs offering cybersecurity services and support to defense contractors striving for compliance. The rule’s phased implementation and certification process provide MSPs with a timeline to adapt and prepare their services to meet the evolving compliance needs of defense clients.

