On Monday 13 July, the Department of War (DoW) announced the immediate suspension of the transition to CMMC Phase II requirements. See link to DoW release here: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/
While CMMC Phase II implementation is pending review, NIST SP 800-171 security requirements continue to apply to DoD contracts and are the foundation for protecting Controlled Unclassified Information (CUI). ND-ISAC and its member organizations remain committed to our mission of elevating cybersecurity, improving enterprise resilience, and strengthening collective defense, to protect DoW information entrusted to member organizations while also protecting DIB key intellectual property. We recognize that nation state threat actors, of course, will not suspend their targeting of Defense Industrial Base companies. Via interactive deep collaboration within ND-ISAC’s trust perimeter, our member companies continually sharpen their capabilities to defend against network threats and better position themselves for success in meeting CMMC and other governance, risk, and compliance challenges.
Learn how your company can be part of ND-ISAC at: info@ndisac.org. Meanwhile it’s a great time to review these resources:
- ND-ISAC: https://ndisac.org/
- DIB SCC CyberAssist: https://ndisac.org/dibscc/cyberassist/
- DoW CIO: https://dowcio.war.gov/BrilliantBasics/
- NSA/CCC: https://www.nsa.gov/about/cybersecurity-collaboration-center/dib-cybersecurity-services/
- DC3/DCISE: https://www.dc3.mil/Missions/DIB-Cybersecurity/DIB-Cybersecurity-DCISE/
