If you want to stay competitive, your best chance is to get CMMC ready before Q1 2025.
How long does it take to become compliant? We’ll cover that and other key questions in this blog.
By the end of this you should have a solid understanding of the CMMC rule and what you need to do to prepare your organization for compliance. We’ll cover what CMMC is, what's in the rule, the rulemaking timeline, the cost of compliance, and next steps to take.
The DoD has released the proposed version of the Cybersecurity Maturity Model Certification (CMMC) rule. This long-awaited assessment framework provides a clear path for defense contractors to protect controlled unclassified information (CUI) and meet the DoD's cybersecurity requirements.
Looking for a deeper dive? Watch our free CMMC Published Webinar walks will guide you through all we cover here, highlighting vital details with expert insight from Scott Edwards, Summit 7 CEO, CMMC Evangelist Jacob Horne, and Sam Stiles, our Marketing VP.
At the end, you’ll have the chance to download our free, comprehensive resource, the CMMC Readiness Brief, your roadmap to CMMC success with leadership support.
Expert Insight: "CMMC isn't making you do the requirements; it's making sure you did the requirements." - Jacob Horne
CMMC acts as a verification of a contractor's cybersecurity posture.
CMMC compliance is mandatory for all DoD contractors and subcontractors who handle CUI. By adhering to the controls outlined in NIST SP 800-171 and obtaining third-party certification of its implementation, organizations can achieve CMMC compliance.
CMMC explains what is required for each CMMC level. Knowing your level will help you know what is required of your organization. Your level is determined by what type of data you handle for the DoD.
Since the majority of Organizations Seeking Compliance (OSCs) will be CMMC Level 2, we will focus on takeaways for Level 2.
Key Question: If we are CMMC level 2, have we looked at both NIST SP 800-171 and NIST SP 800-171A to see if we have done all 320 assessment objectives?
Expert Insight: Any MSP/MSSP working with the organization must have a Level 2 final certification as well.
Key Question: Is my MSP/MSSP actively working to become certified at my CMMC level?
Expert Insight: If you want a shot at staying competitive, your best chance is to start NIST SP 800-171 implementation today.
With prime demands, market competition and limited assessors, most organizations are looking to Q1 of 2025, when the rule is published, to be assessment ready.
The average time it takes to implement NIST SP 800-171 is 12-18 months for a 50-500 person company starting from an average compliance posture.
If you want to stay competitive when certifications become available Q1 2025, and it takes 12-18 months for implementation, today is the day to start.
Key Question: When is my customer/prime contractor asking for CMMC?
Expert Insight: Getting CMMC certified takes about year of preparation, and easily could cost six figures to get there.
For Level 2, the cost of a CMMC Certification will include Assessment Costs (initial and every three years after) and Affirmation Costs (annually): estimated to be $104,670 total based on the CMMC proposed rule documentation.
Remember: the cost of CMMC does not include the cost of implementing NIST SP 800-171, which is assumed to have been already implemented.
Key Question: Is my staff and budget poised to engage on a year plus journey of NIST SP 800-171 implementation?
Need a roadmap to CMMC? Download the CMMC Readiness Brief.
This is a tool tailored for CISOs and IT professionals tasked with compliance to communicate a plan to the decision makers in their organizations with confidence.