Newly released CMMC 2.0 Makes Changes and Creates More Uncertainty of What to Do Next?
The DoD announced a change to CMMC 1.0 and renaming as CMMC 2.0. Within this change are a host of enhancement and implications for the supply base at a high level. I will outline the changes as directly as possible. The main change is the addition of self-assessment similarly to NIST 800-171 under DFAR 252.204-7012. In addition to the self-assessment is the requirement for annual affirmation by the company leadership. This is where the rubber really hits the road. Affirmation under the
False Claims Act, where both prosecution and insider complaints will be addressed. I suggest all suppliers read this link. In addition to these, changes in 2.0 will be lower costs for suppliers as certification by a 3rd party is no longer required in many cases.
There is now the ability to present interim status vs 100% compliance as we have with the current DFARS and NIST requirements. These interim reports can be handled in the traditional manner by presenting a Plan of Action and Milestones (POAM) that have a less than 180-day completion date for allowed baseline gaps. Unallowed gaps will have a “No POAM” designation and need to be implemented. If you have any doubts, work with a highly skilled 3rd party who has expertise in these standards and track record of enabling comprehensive successful standards-based cyber programs. The information presented by the suppliers in POAM’s or claiming 100% compliance will be evaluated and can and will likely trigger audits if certain high level cyber controls are not met or the 100% compliance score creates suspicion of a false claim. Be careful to present accurate and validated information.
There will be a rulemaking process that is expected to take place for 9+ months and the CMMC 2.0 will not show up in acquisitions until the rulemaking process is complete. There is an expectation that once the rulemaking is complete, the effects of and implementation will likely be swift and mandatory.
So, what does this all mean? Reality, if you are a DoD supplier or have plans to be one.
YOU MUST be compliant with the DFARS clause 252.204.7012 and NIST 800-171 under your current contracts. (NIST SP 800-171 & CMMC Interim Rule Effective November 30, 2020 - Cytellix).The False Claims Act applies today to all cyber compliance representations. You should start now preparing for CMMC 2.0 as it clearly aligns with DFARS and NIST. Waiting is a bad idea. Why you ask? It is very clear that most suppliers and Small and Medium Businesses are not cyber prepared and nowhere near compliance with any cyber framework. The timeframe for a typical business to understand, develop and implement full compliance is more than 1-year assuming they have skills and personnel to complete the objectives.
*If you have any questions, please reach out to our experts – [email protected]
Cytellix® Cyber Watch Platform (C-CWP™)
C-CWP™ provides value by baselining the truth about the true cyber posture of our customers. We then move towards a cybersecurity mesh architecture of integrated continuous improvement that aligns with business objectives. C-CWP™ is an interoperable and open platform designed for change in posture and threat landscape. C-CWP™ is delivered as a complete “turnkey” outsourced service or in combination with internal teams and previously purchased security capabilities
Cytellix® Endpoint Detection Response (C-EDR™)
Cytellix® Endpoint Detection & Response (C-EDR™) is a flexible solution that can be used standalone, enables bring-your-own-license or can be provided turnkey as a complete managed solution with our C-GRC™, C-MDR™, XDR, SOC 24x7x365 managed Turnkey Solutions. The Cytellix turnkey C-EDR™ is a Enterprise grade solution that is complete and has full integration with the Cytellix platform.
Cytellix® Governance Risk & Compliance (C-GRC™) & IT Risk Management (IRM)
Risk Management requirements are evolving to align to the changes arising from compliance risk shifting towards regulatory impact on business process. The demand on organizations to understand their cybersecurity posture, report status and meet regulatory obligations is driving demand across the enterprise (small>large) for a non-technical, turnkey all-inclusive platform.
Cytellix® Managed Detection Response (C-MDR™)
Patented technology compiles information from the vulnerability's, governance, risk, compliance assessments, event data, and analytics. Delivers real-time analysis, including continuous improvement visualization and scorecard.
Extended Detection Response (C-XDR™)
The Cytellix® Extended Detection Response (C-XDR™) solution leverages our flagship Cytellix Cyber Watch Portal (C-CWP™) as turnkey compliance, awareness and response platform. Our C-XDR™ includes, vulnerability management, devices profiling, network segmentation, asset discover, threat intelligence, leak detection, EDR, pre-defined use cases for log ingestion and correlation of threats and our USA based 24x7x365 Security Operations Center (SOC). The Cytellix platform leverages our in-house AI/ML models for real-time telemetry, threat discovery/hunting and ticket reduction. This is a complete turn-key, affordable XDR solution.
Cybersecurity for Small and Medium Business
Cytellix® has designed its platform to enable the small and medium business to adopt quickly, with low friction at an affordable price. We have found that the tasks of both regulatory compliance with cybersecurity frameworks and building a high quality cybersecurity monitoring and infrastructure is a significant time, resource and expense issue for SMB's.
We will get btackts to you as soon as posTsible.
Oops, there was an error sending your message.
Please try again later.
The Cytellix® team of experts have been delivering cybersecurity for the past 15-years to some of the largest networks in the world. This expertise is delivered to our SMB customers as an affordable, precise, and comprehensive solution designed for organizations who need to comply with Cybersecurity regulatory requirements. There is no other fully integrated GRC, MDR, XDR, EDR single pane of glass solution that is as rich in capabilities, as easy to use and available in production today.
Cytellix® - Patent Pending. All Rights are Reserved By Cytellix®