Connect with us

Politics

DoD addresses two big challenges to make CMMC a reality

Published

on


The Defense Department feels better than ever about the future of the Cybersecurity Maturity Model Certification program.

DoD is close to solving two big obstacles to get CMMC off the ground more than six years after first introducing the data security program.

After finalizing the first rule related to CMMC last summer, which established the formal program, DoD now believes its path is clear to get the second regulation finalized in the coming months.

Stacy Bostjanick is the DoD’s chief of the Defense Industrial Base Cybersecurity in the CIO’s office.

Stacy Bostjanick, DoD’s chief of the Defense Industrial Base Cybersecurity in the CIO’s office, said the rule to change the Defense Federal Acquisition Regulations (DFARs) is close to going to the Office of Management and Budget’s Office of Information and Regulatory Affairs (OIRA) for final processing.

“They’re [DoD] working on the final edits to get it back to OMB OIRA, so it is moving, and we really expect to keep it close to the original timeline that we expected of later this summer it become in full and published and ready to roll,” Bostjanick said at the Professional Services Council’s Acquisition conference last Thursday.

DoD issued that proposed rule last August. It would do several things including defining controlled unclassified information (CUI) and establish a solicitation provision and prescription for CMMC.

The challenge for DoD came when the Trump administration imposed a 60-day regulatory freeze on its first day in office. While that freeze recently lifted, President Donald Trump also issued an executive order requiring agencies to repeal at least 10 rules, regulations or guidance documents for every new rule. The CMMC DFARS rule got caught up in the regulatory freeze and 10-for-1 exchange requirement.

Bostjanick said she definitely wants to end any rumors that CMMC is going away due to the regulatory freeze.

Pilot shows ways to reduce cost of CMMC

The second big change for DoD is the successful pilot with cloud service providers (CSP) and a managed service provider (MSP) to provide an easier path for companies to meet CMMC requirements.

DoD estimates that there are 220,000 to 300,000 companies in the defense industrial base, roughly 80,000 will need to achieve CMMC level 2, and another 1,500 will need to achieve CMMC level 3.

Additionally, there are only 50 to 60 certified third party assessment organizations (3CPAOs), meaning DoD has to help find a way to deal with a potential backlog.

Bostjanick said the test with the managed service provider showed that this shared service approach could reduce the time and cost for certification.

“We saw one company, I can’t mention the name, but they from zero to 110 controls in two months, and it cost them about $1,300 a seat, and $32,000 for their assessment,” she said. “The same company that got them compliant and got them to their 110 controls can’t do the assessment, so you have to work with another company come and do that assessment. It was two months’ worth of work and not that much money.”

By working with a MSP or CSP, Bostjanick said companies would inherit between 80% and 90% of the controls from the platform.

“The customer responsibility matrix is going to be wildly important for a company to understand and follow because there are certainly things in the NIST SP-800-171 that require you to do work in your spaces. Now, a lot of these MSPs are providing templates and guidance and help to get the company there, but that customer responsibility matrix where you are aware and know exactly your part that you have to play to get to the 110 controls and you know most of the MSPs that are working with you will help hold the hand all the way through,” she said. “I’ve been very heartened by the capabilities that have been born out of this requirement. Industry has definitely risen to the challenge to help us, and they’ve definitely found affordable solutions for small and medium companies.”

Phased rollout coming

The CSPs — including Microsoft, Google, Amazon Web Services and Oracle — have partnered with managed service providers to provide capabilities, mostly through virtual desktops, to contractors.

Bostjanick said one or two of the CSP’s approach protects the data in a way if it gets downloaded to another system, it would automatically move into continuous monitoring mode.

DoD is also working with the industry advisory group the Cyber AB on an online marketplace to list these types of CMMC related services.

“We’re working right now with the Cyber AB on what the website, what would the criteria be for ingesting a company and hosting them on that website? So more to come. But we have seen some wonderful capabilities that have been out there that are definitely low cost, and they provide an environment for companies to operate in,” Bostjanick said.

While vendors already are expected to meet the requirements under NIST 800-171, the CMMC standards are more than a year from being part of a contract award.

Bostjanick said DoD will oversee a phased rollout of the requirements.

“We originally had the first phase of six months where you could continue focusing on that self-attestation, but it would be self-attestation under the CMMC rules, which means you no longer can have a plan of action and milestones (POA&M) that goes out to 2099 before you’d complete it. So now, your POA&Ms will have to be closed within six months, and you’ll have to do your annual affirmation that you are compliant with the NIST 800-171,” she said.

The post DoD addresses two big challenges to make CMMC a reality first appeared on Federal News Network.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Politics

Victor Reacts: This Is Almost Too Stupid to Be True – NYC Transgender Homeless Shelter (VIDEO)

Published

on

By

Democrats continue to somehow subvert the lowest of expectations as they fight their woke crusades.

In a first ever virtue signal, New York City is set to open a transgender only homeless shelter.

The Gateway Pundit reported,

The city of New York is opening the nation’s first transgender-only homeless shelter.

The shelter, a partnership between a local LGBTQ nonprofit and the city government, will cost the city an extraordinary $65 million and will be the first transgender homeless shelter in the nation.

“ We’ve watched so many other corporations and foundations and businesses just like completely turn their back on the community and the city didn’t do it,” said Sean Ebony Coleman, founder and CEO of Destination Tomorrow, the nonprofit that will manage the shelter for the city.

“The city is keeping in line with what New York City has always been, a sanctuary city, a safe haven, but more importantly, a trendsetter when it comes to LGBTQ rights.”

The opening comes amid a broader homelessness crisis in New York City, where more than 100,000 people are estimated to be without stable housing on any given night.

The city’s shelter system is already stretched thin, with demand rising due to a combination of economic hardship, an influx of illegal aliens ,and a severe shortage of affordable housing.

Who cares about all the other homeless people in New York City each night, the transgender homeless come first.

Truth has become stranger than parody. With any luck, Democrats will continue down this path of self destruction that has been so thoroughly rejected by the American people.

The post Victor Reacts: This Is Almost Too Stupid to Be True – NYC Transgender Homeless Shelter (VIDEO) appeared first on The Gateway Pundit.

Continue Reading

Politics

Suspect in Deadly Montana Bar Shooting Captured After a Weeklong Manhunt

Published

on

By

A weeklong manhunt has come to a close with the apprehension of Michael Paul Brown, a 45-year-old Army veteran, following a fatal mass shooting at The Owl Bar in Anaconda.

On August 1, 2025, at approximately 10:30 a.m., Brown entered The Owl Bar, where he lived next door, and opened fire with a rifle, killing four local residents: bartender Nancy Lauretta Kelley (64) and patrons Daniel Edwin Baillie (59), David Allen Leach (70), and Tony Wayne Palm (74).

A multi-agency effort, including state law enforcement, the U.S. Marshals Service, and federal resources, scoured the mountainous terrain surrounding Anaconda. Helicopters, K9 units, and tactical teams were deployed across the region.

A reward of $7,500 to $10,000 was offered for information leading to Brown’s capture.

On Friday, Montana Governor Greg Gianforte confirmed Brown’s arrest via social media, acknowledging the rapid and resolute law enforcement response.

“The Anaconda shooter Michael Brown has been apprehended. Incredible response from law enforcement officers across Montana. Thank you to all partners for your commitment to the search. May God continue to be with the families of the four victims still grieving their loss,” Gianforte.

CNN reported:

Brown had been on the run since the “biggest” shooting in the state of Montana in a decade. He was arrested around 2 p.m. local time Friday near the search area in Anaconda and is now in the custody of Anaconda-Deer Lodge County authorities, according to the Montana Department of Justice.

Brown, an Army veteran, was seen on security footage fleeing The Owl Bar, where the fatal shooting occurred, investigators said. Since then, he had been sought by authorities representing at least 38 local, state and federal agencies traversing challenging terrain in the western Montana wilderness.

“I am proud of the unrelenting law enforcement effort this week to find and arrest Michael Paul Brown. The support we’ve seen for the community of Anaconda from across the state and the nation has also been remarkable,” Montana Attorney General Austin Knudsen said in a statement following the arrest. “The families and friends of the victims remain in my prayers.”

[…]

Brown served as an armor crewman in the US Army from January 2001 to May 2005 and was deployed to Iraq from February 2004 to March 2005, Lt. Col. Ruth Castro, a spokesperson with the US Army, previously told CNN.

Brown’s niece, Clare Boyle, previously told CNN he struggled with his mental health during his time in the Army and was never the same after his service. Brown’s mental health got progressively worse with the passing of both of his parents, Boyle said.

The post Suspect in Deadly Montana Bar Shooting Captured After a Weeklong Manhunt appeared first on The Gateway Pundit.

Continue Reading

Politics

WATCH: Fire Ravages World-Famous Mosque-Cathedral in Cordoba, Spain

Published

on

By

Fire breaks out in the Cathedral of Our Lady of the Assumption in Cordoba.

More than a tourist attraction, more than an architectural treasure, the Mosque-Cathedral in the Andalusian city of Cordoba, Spain is a historical monument and a spiritual center – so, all around the world, both the faithful and the history lovers are mourning as a massive fire consumes the building complex.

Newsweek reported:

“Firefighters are responding to the blaze at the major tourist attraction and UNESCO-listed heritage site in Andalusia. Footage shows thick smoke billowing out from the millennia-old building as flames lapped at its roof.

Firefighters from the city of Córdoba are still battling to extinguish the fire at the Mosque-Cathedral of Córdoba but local reports say the blaze is mostly contained as of 10 p.m. local time. The extent of damage is not yet clear.”

Being simultaneously one of the most significant buildings both in Islamic and in Christian architectural history, it began as a grand mosque in the 8th century and was transformed into a cathedral in 1236.

“The Mosque–Cathedral of Córdoba, officially called the Cathedral of Our Lady of the Assumption, was built as a mosque over 200 years starting 785 CE. The mosque opened in 988 CE, and remained a Muslim site for nearly 300 years before the Christian conquest of Cordoba in 1236 CE.

The structure converted to a cathedral, undergoing additional modifications and building until one final, major addition in 1607 CE.”

Read more, from November 2024:

‘The Virgin of Paris’: Medieval Statue of the Virgin Mary With Baby Jesus, That Survived the 2019 Fire, Is Returned to the Notre Dame Cathedral Ahead of December Grand Reopening

The post WATCH: Fire Ravages World-Famous Mosque-Cathedral in Cordoba, Spain appeared first on The Gateway Pundit.

Continue Reading

Trending