The Contracting Education Academy

Contracting Academy Logo
  • Home
  • Training & Education
  • Services
  • Contact Us
You are here: Home / Government Contracting News / CMMC update: Details on certification infrastructure and COTS products

June 12, 2020 By cs

CMMC update: Details on certification infrastructure and COTS products

The framework for the DoD’s Cybersecurity Maturity Model Certification (CMMC) process continues to move forward.

Here’s an update on what’s currently happening with the CMMC that includes a few more details the DoD and the independent CMMC Accreditation Body have recently released about the nuts and bolts of the certification process.

As explored in Koprince Law’s prior posts (such as this one), the CMMC standards were put in place to protect Controlled Unclassified Information held by defense contractors to reduce loss of data and “risk to national security.” The standards will require a third-party audit of all defense contractors and will be proportional to the magnitude of the contract and what data the contractor is handling for the DoD.

CMMC Accreditation Body and C3PAOs

DoD’s partners have been hard at work on fleshing out the details of the certification process.  The CMMC Accreditation Body (or CMMC-AB) is a non-profit, independent organization that will accredit CMMC Third Party Assessment Organizations (C3PAOs) and the assessors themselves.  This means the CMMC-AB is not part of the government, although it operates under an agreement with the DoD.  The C3PAOs are the organizations that will help “train the trainers”–meaning they will provide skills to and assist the assessors, but the CMMC-AB will actually license the assessors. A C3PAO must be certified by the CMMC AB and then the C3PAO will train and monitor the CMMC assessors who provide the certifications.

The CMMC AB is taking steps to carry out its goals. The training program for CMMC assessors has not started yet and there is no timeline on the AB’s website. As a consequence, no assessors have been licensed yet.

However, as part of its mission, the AB is conducting market research to develop “a scalable and extensive partner-centric training and educational model to effectively equip professionals, students, and other stakeholders within the CMMC ecosystem.” The organization will provide training content and providers for certification.  The AB is also doing market research for an entity to develop a CMMC certification exam.

Keep reading this article at: https://smallgovcon.com/statutes-and-regulations/cmmc-update-details-on-certification-infrastructure-and-cots-products

Filed Under: Government Contracting News Tagged With: C3PAO, CMMC, CMMC AB, CMMC accreditation, CMMC Accreditation Body, commercial item, commercial products, controlled unclassified information, COTS, Cybersecurity Maturity Model Certification. DoD

Popular Topics

abuse acquisition reform acquisition strategy acquisition training acquisition workforce Air Force Army AT&L bid protest budget budget cuts competition cybersecurity DAU DFARS DHS DoD DOJ FAR fraud GAO Georgia Tech GSA GSA Schedule GSA Schedules IG industrial base information technology innovation IT Justice Dept. Navy NDAA OFPP OMB OTA Pentagon procurement reform protest SBA sequestration small business spending technology VA
Contracting Academy Logo
75 Fifth Street, NW, Suite 300
Atlanta, GA 30308
info@ContractingAcademy.gatech.edu
Phone: 404-894-6109
Fax: 404-410-6885

RSS Twitter

Search this Website

Copyright © 2023 · Georgia Tech - Enterprise Innovation Institute