The much-anticipated CMMC rule update to the one of the two final rules is now published to the Federal Register. The changes to the 32 CFR codify the CMMC program, the assessment guides, scoping, and other requirements for obtaining a Cybersecurity Maturity Model Certification.
You have questions about this CMMC rule update, and we have answers!
Q: What’s next?
The CMMC rule now in the final reviewing stage. There will be 2-3 months of statutory review, including a Congressional review.
Q: When will it get entered into contracts?
We still need to see the 48 CFR rules before the language requiring CMMC can be inserted into contracts, but that is expected shortly. Both rules are likely to come out and be enforced on the same timeline.
Q: When can I get a CMMC Assessment?
The current Joint Surveillance Voluntary Assessment Program with DIBCAC will continue until the effective date of the CMMC Rule. Once the rule is effective, a C3PAO will be authorized to conduct assessments on a self- determined schedule working directly with OSCs.
Q: When is the effective date?
To be determined! Once the CMMC rule is through the process, an effective date will be attached to the rule. This could be as soon as September (60 days) or later October if it goes the full 90 days.
Q: Does the 48 CFR have to be in place, or contracts out, before we can get an assessment?
No! The 48 CFR is needed for the DoD contracts to insert the CMMC requirements into them, however the CMMC program will be law and certifications by a C3PAO can begin. (Note: The DoD is likely to required C3PAO’s to prioritize those with active DoD contracts with the CMMC requirements in them once things kick into gear!)
Q: Can we see the final rule?
Not yet. The final rule, guides, and associated information will be released once the final reviews are complete. Expect another CMMC rule update this summer!
Still have a question you need answered? Stuck on how to get your CMMC project rolling? Wondering what CMMC is? Or are you ready to schedule your assessment? Contact us today!
If you are looking for a great way to double-check your CMMC readiness, try the Monarch ISC Security Catapult. Answer real assessment questions created by the Monarch ISC certified assessors to get a real time SPRS score and get confidence in your preparations for CMMC. Level 1 is still free!