federal_register: 2023-27280
Data license: Public Domain (U.S. Government data) · Data source: Federal Register API & Regulations.gov API
This data as json
| document_number | title | type | abstract | publication_date | pub_year | pub_month | html_url | pdf_url | agency_names | agency_ids | excerpts |
|---|---|---|---|---|---|---|---|---|---|---|---|
| 2023-27280 | Cybersecurity Maturity Model Certification (CMMC) Program | Proposed Rule | DoD is proposing to establish requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have, as part of the Cybersecurity Maturity Model Certification (CMMC) Program, implemented required security measures to expand application of existing security requirements for Federal Contract Information (FCI) and add new Controlled Unclassified Information (CUI) security requirements for certain priority programs. DoD currently requires covered defense contractors and subcontractors to implement the security protections set forth in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev 2 to provide adequate security for sensitive unclassified DoD information that is processed, stored, or transmitted on contractor information systems and to document their implementation status, including any plans of action for any NIST SP 800-171 Rev 2 requirement not yet implemented, in a System Security Plan (SSP). The CMMC Program provides the Department the mechanism needed to verify that a defense contractor or subcontractor has implemented the security requirements at each CMMC Level and is maintaining that status across the contract period of performance, as required. | 2023-12-26 | 2023 | 12 | https://www.federalregister.gov/documents/2023/12/26/2023-27280/cybersecurity-maturity-model-certification-cmmc-program | https://www.govinfo.gov/content/pkg/FR-2023-12-26/pdf/2023-27280.pdf | Defense Department | 103 | DoD is proposing to establish requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have, as part of the Cybersecurity Maturity Model Certification (CMMC) Program, implemented required... |