Call Us: 415.956.2828

Overview & Analysis of DOD’s CMMC Proposed Rule

by Robert S. Metzger, Stephen L. Bacon, Deborah Norris Rodin and Cindy Lopez

On December 26, the Department of Defense (DOD) published its long-awaited Cybersecurity Maturity Model Certification (CMMC) proposed rule in the Federal Register, along with associated guidance documents. The rule describes the CMMC 2.0 program, which includes assessment and certification requirements for 220,000 companies in the DOD supply chain. 

The proposed rule requires DOD suppliers at all tiers to follow specified security requirements depending on the type of government information they handle. More than 75,000 companies will be subject to “Level 2” requirements, which will involve a mandatory third-party assessment and eventually require certification to be eligible to receive DOD contract awards. The DOD is accepting comments until February 26.

For more detailed analysis and insights, read a full report from RJO’s Cybersecurity and Privacy Practice Group on the DOD’s proposed CMMC rule here.

San Francisco, CA
  • Robert Dollar Building
    311 California Street, 10th Floor
    San Francisco, CA 94104-2695
  • Phone: 415.956.2828
  • Fax: 415.956.6457
Washington, DC
  • 1500 K Street, NW, Suite 800
    Washington DC 20005-1227
  • Phone: 202.777.8950
  • Fax: 202.347.8429