{"description":"Documents affecting 32 CFR 170","count":3,"total_pages":1,"results":[{"title":"Cybersecurity Maturity Model Certification (CMMC) Program","type":"Rule","abstract":"With this final rule, DoD establishes the Cybersecurity Maturity Model Certification (CMMC) Program in order to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The mechanisms discussed in this rule will allow the Department to confirm a defense contractor or subcontractor has implemented the security requirements for a specified CMMC level and is maintaining that status (meaning level and assessment type) across the contract period of performance. This rule will be updated as needed, using the appropriate rulemaking process, to address evolving cybersecurity standards, requirements, threats, and other relevant changes.","document_number":"2024-22905","html_url":"https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-10-15/pdf/2024-22905.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-22905.pdf?1728650732","publication_date":"2024-10-15","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"With this final rule, DoD establishes the Cybersecurity Maturity Model Certification (CMMC) Program in order to verify contractors have implemented required security measures necessary to safeguard Federal Contract Information (FCI) and Controlled..."},{"title":"Posting of Informational Video: Cybersecurity Maturity Model Certification (CMMC) Program","type":"Proposed Rule","abstract":"The Office of the Department of Defense Chief Information Officer (DoD CIO) has released an informational video to provide the public with an overview of the proposed rule for DoD's updated Cybersecurity Maturity Model Certification (CMMC) Program, which was published in the Federal Register on December 26, 2023 for public comment. The proposed rule establishes requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have, as part of the CMMC Program, implemented required existing security requirements for Federal Contract Information and Controlled Unclassified Information (CUI) and adds new CUI security requirements for certain priority programs. This document announces that a video file containing an overview briefing of the CMMC proposed rule, presented by leadership and staff from the Office of the DoD Deputy CIO for Cybersecurity, was posted on the internet on February 14, 2024.","document_number":"2024-03460","html_url":"https://www.federalregister.gov/documents/2024/02/21/2024-03460/posting-of-informational-video-cybersecurity-maturity-model-certification-cmmc-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2024-02-21/pdf/2024-03460.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2024-03460.pdf?1708436722","publication_date":"2024-02-21","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"The Office of the Department of Defense Chief Information Officer (DoD CIO) has released an informational video to provide the public with an overview of the proposed rule for DoD's updated Cybersecurity Maturity Model Certification (CMMC) Program,..."},{"title":"Cybersecurity Maturity Model Certification (CMMC) Program","type":"Proposed Rule","abstract":"DoD is proposing to establish requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have, as part of the Cybersecurity Maturity Model Certification (CMMC) Program, implemented required security measures to expand application of existing security requirements for Federal Contract Information (FCI) and add new Controlled Unclassified Information (CUI) security requirements for certain priority programs. DoD currently requires covered defense contractors and subcontractors to implement the security protections set forth in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Rev 2 to provide adequate security for sensitive unclassified DoD information that is processed, stored, or transmitted on contractor information systems and to document their implementation status, including any plans of action for any NIST SP 800-171 Rev 2 requirement not yet implemented, in a System Security Plan (SSP). The CMMC Program provides the Department the mechanism needed to verify that a defense contractor or subcontractor has implemented the security requirements at each CMMC Level and is maintaining that status across the contract period of performance, as required.","document_number":"2023-27280","html_url":"https://www.federalregister.gov/documents/2023/12/26/2023-27280/cybersecurity-maturity-model-certification-cmmc-program","pdf_url":"https://www.govinfo.gov/content/pkg/FR-2023-12-26/pdf/2023-27280.pdf","public_inspection_pdf_url":"https://public-inspection.federalregister.gov/2023-27280.pdf?1703252717","publication_date":"2023-12-26","agencies":[{"raw_name":"DEPARTMENT OF DEFENSE","name":"Defense Department","id":103,"url":"https://www.federalregister.gov/agencies/defense-department","json_url":"https://www.federalregister.gov/api/v1/agencies/103","parent_id":null,"slug":"defense-department"},{"raw_name":"Office of the Secretary"}],"excerpts":"DoD is proposing to establish requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have, as part of the Cybersecurity Maturity Model Certification (CMMC) Program, implemented required..."}]}