On June 27, 2024 the CMMC Program Final Rule (32 CFR) has moved to the last step prior to finalization and publication. The rule is now in OIRA (Office of Information and Regulatory Affairs) review. This is the last step before publication in the federal register.
CMMC Timeline Update: DoD Submits CMMC Program to Office of Management and Budget for Review
On July 24th, the Department of Defense submitted the Cybersecurity Model Maturity Certification (CMMC) Program to the Office of Management and Budget (OMB) for review. So, what exactly does this mean for Defense contractors and when would a CMMC certification requirement start to show up in contracts solicitations?
DOJ’s False Claims Act and why it matters to Defense Contractors
On April 27, 2022, Aerojet Rocketdyne agreed to pay roughly $9 million to settle a False Claims Act complaint relating to overstated levels of cybersecurity compliance and controls. The case is significant because it is the first time that a whistleblower has successfully used the False Claims Act to hold a defense contractor accountable for cybersecurity fraud. The case also sets an important precedent for future whistleblowers who are trying to hold defense contractors accountable for cybersecurity violations.