SecureWorld News

Defense Department: New Direction for the CMMC

Written by SecureWorld News Team | Mon | Nov 8, 2021 | 4:06 PM Z

The U.S. Department of Defense (DoD) just rolled out a new strategic direction for the Cybersecurity Maturity Model Certification known as "CMMC 2.0."

New guidelines correspond to the DoD's objectives of "safeguarding sensitive information," especially in terms of addressing surveillance issues with supply chains stationed in China

CMMC 2.0 released by Department of Defense

Why is this update so important for the cybersecurity of the DoD supply chain? Because it reportedly makes better cybersecurity more accessible for SMBs that operate in the space.

U.S. Deputy Secretary of Defense, Dr. Kathleen Hicks, tweeted about it. 

Here are three aims of the updated cybersecurity model:

  • Simplifying the CMMC standard and providing additional clarity on cybersecurity regulatory, policy, and contracting requirements;
  • Focusing the most advanced cybersecurity standards and third-party assessment requirements on companies supporting the highest priority programs; and
  • Increasing Department oversight of professional and ethical standards in the assessment ecosystem.

This chart from the Office of the Under Secretary of the Defense also illustrates additional changes from the original CMMC.

Find additional details about the CMMC update at


The SecureWorld Sessions podcast episode: The CMMC Explained

SecureWorld's Rockies virtual conference is coming up on Nov. 17. Register to attend for excellent presentations and panels and earn CPE credit. Find the agenda for the conference here