Contacts
Schedule a Demo
Close

Contacts

11921 Freedom Dr Suite 730
Reston, VA 20190

(571) 497-5687

info@kovr.ai

Understanding CMMC 2.0 Requirements: A Team Guide

Announcing partnership with Fortreum to define the future of compliance

What is CMMC 2.0?

The Cybersecurity Maturity Model Certification (CMMC) 2.0 is the Department of Defense’s (DoD) framework designed to protect sensitive information within the defense industrial base (DIB). As our organization works with DoD contracts, understanding these requirements is crucial for our continued partnership with the Department.

What to Expect: Contract Modifications

DoD customers have begun signaling that starting in 2025, they will be invoking DFARS clause 252.204-7021 (Cybersecurity Maturity Model Certification Requirements). This clause formally introduces CMMC 2.0 requirements into the federal regulatory framework. Companies will be required to meet CMMC 2.0 Level 1 and Level 2 standards, which involves protecting Controlled Unclassified Information (CUI) through 110 security practices derived from NIST SP 800-171.

Key Changes from Previous Requirements

CMMC 2.0 represents a streamlined approach from earlier versions:

  1. Simplified Structure: Reduced from 5 levels to 3 levels (Level 1, Level 2, and Level 3)
  2. Assessment Options: For Level 2, there are two assessment paths:
    • Level 2 (Basic): Self-assessment for select programs
    • Level 2 (Expert): Third-party assessment by a CMMC Third-Party Assessment Organization (C3PAO) for programs involving critical national security information
  3. Alignment with Standards: Directly aligned with NIST SP 800-171 controls
  4. Plan of Action & Milestones (POA&M): Limited use of POA&Ms now allowed for certain security requirements

Financial Implications

Consult audit and accounting professionals to understand whether costs associated with CMMC certification are considered “allowable.”

  1. Implementation costs likely won’t be a directly reimbursable expense
  2. You may need to include CMMC certification expenses as overhead (OH) or general and administrative (G&A) costs in your fully burdened rates, similar to other business expenses like utilities or ISO certifications
  3. While the DoD has discussed making initial certification costs an “allowable cost,” formal clarification is still pending
  4. Important distinction: Initial certification costs might potentially be allowable, but it remains unclear whether remediation costs to meet CMMC requirements will be allowable expenses

Timeline and Preparation Steps

  1. Gap Assessment: Conduct an internal assessment using Kovr to identify where your current security practices fall short of CMMC requirements
  2. Remediation Planning: Develop a detailed plan to address identified gaps
  3. Documentation: Ensure all security practices are thoroughly documented
  4. System Security Plan (SSP): Create or update our SSP to reflect CMMC 2.0 requirements
  5. Assessment Preparation: Prepare for either self-assessment or C3PAO assessment depending on contract requirements
  6. Budget Planning: Incorporate certification and maintenance costs into our financial planning

Team Responsibilities

Each department has specific responsibilities in achieving and maintaining compliance:

  • IT/Security Team: Implement technical controls, monitor systems, maintain documentation
  • Management: Ensure resource allocation, oversee compliance efforts, communicate with DoD clients
  • Procurement/Supply Chain: Ensure subcontractors meet appropriate CMMC requirements
  • HR: Facilitate security awareness training for all staff
  • All Staff: Maintain security awareness, follow procedures, report incidents

Why This Matters

CMMC 2.0 compliance is not just a contractual obligation—it represents sound security practices that protect both our organization and our nation’s security interests. Non-compliance could result in lost contract opportunities, financial penalties, and reputational damage. By proactively addressing these requirements, we position our organization for continued success in the defense contracting space.

Leave a Comment

Your email address will not be published. Required fields are marked *