The Cybersecurity Maturity Model Certification (CMMC) 2.0 is a comprehensive framework launched by the Department of Defense (DoD) to protect the Defense Industrial Base (DIB) from increasingly frequent and complex cyber-attacks. It particularly aims to safeguard information defined as Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) shared within the DIB.
CMMC 2.0 builds on existing trust-based regulations (DFARS 252.204-7012) by adding a verification component for cybersecurity requirements. The program has three key features:
It is imperative that all HII subcontractors and/or suppliers that receive and generate FCI and/or CUI meet these new DFARS requirements to be eligible for future work that will contain CMMC 2.0 requirements. Together our continued diligence will protect vital information, minimize risks and secure a competitive advantage for all parties.
When a cyber-incident is discovered, contractors, subcontractors and suppliers must conduct a review for evidence of compromise of covered defense information and report to the DoD and HII within 72 hours. A “Cyber incident” is defined as actions taken through the use of computer networks that result in a compromise or an actual or potentially adverse effect on an information system and/or the information residing therein.
When engaging with other suppliers that require access to covered defense information in performance of a contract, include the DFARS 252.204-7012 clause in any subcontracts, or similar contractual instruments with those suppliers. Read the full clause here.
4101 Washington Ave.
Newport News, VA 23607
4101 Washington Ave
Newport News, VA 23607
1000 Jerry St. Pe’ Highway
Pascagoula, MS 39568
8350 Broad Street, Suite 1400
McLean, VA 22102
2451 Crystal Drive, Suite 1100
Arlington, VA 22202