July 20, 2021 By Kim Walsh Governance and Compliance, Industry News

The Cybersecurity Maturity Model Certification has been in development for a while and there has been enough uncertainty around the implementation timeline and the exact requirements that some organizations in the defense industrial base have been taking a wait-and-see approach. That approach is becoming less sustainable as the DoD moves toward making CMMC a contractual requirement and the assessor ecosystem develops around it.

Let me explain what CMMC actually is before getting into what it means for compliance professionals and the certifications that are relevant here.

CMMC is a unified cybersecurity standard for Department of Defense contractors and subcontractors. It was developed in response to persistent cybersecurity incidents affecting the defense supply chain, including well-documented cases of sensitive defense information being compromised through inadequately secured contractor systems. The framework builds on the existing NIST SP 800-171 requirements that contractors handling Controlled Unclassified Information were already supposed to be meeting, but adds a third-party assessment component that represents a significant change from the self-attestation model that many contractors had been operating under.

The tiered structure of CMMC maps roughly to the sensitivity of the information a contractor handles and the sophistication of the cybersecurity practices required to protect it. At the lower levels, basic cyber hygiene requirements. At higher levels, advanced practices and formal third-party certification by a CMMC Third Party Assessor Organization. The official details and current implementation guidance are available at the DoD CIO CMMC page.

For compliance and GRC professionals in organizations that contract with the DoD, there are a few things worth understanding about what CMMC readiness actually requires.

Gap assessment against NIST SP 800-171 is typically the starting point. Most organizations that are in scope for CMMC have existing obligations under DFARS 252.204-7012 that require them to implement the NIST SP 800-171 security requirements. Many of them have not fully done so, and the gap between their current state and the required state is the primary driver of their CMMC readiness work. Conducting that gap assessment rigorously, mapping findings to specific practice requirements, and developing a credible plan of action and milestones is foundational work that draws heavily on IT audit and GRC competencies.

Documentation is a substantial portion of the compliance burden. CMMC assessors are not going to take your word for it that practices are implemented. They need to see policies, procedures, system security plans, and evidence of implementation. The compliance professional’s ability to structure and manage that documentation process is directly applicable and genuinely valuable in a CMMC engagement.

CRISC and CISA holders are well-positioned for CMMC readiness work because the risk assessment and control evaluation skills those certifications validate translate directly to what assessors are looking for. If you are in GRC and you work with defense contractors or are considering that market, developing familiarity with the CMMC framework is a worthwhile professional development investment right now.

Kim Walsh

Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.