📰 CMMC 2.0 in 2025 Discussion

josem.serrano
josem.serrano Member Posts: 71 admin
edited January 8 in General Community

Hello everyone! I recently read this Breaking Defense article that discusses the implementation of the Cybersecurity Maturity Model Certification (CMMC) 2.0.

In the article they state:

"The 32 Code of Federal Regulations (CFR) final rule, which lays the framework for CMMC 2.0, went into effect on Dec. 16, but the DoD won’t actually begin implementing the CMMC 2.0 requirement for contractors until the 48 CFR final rule is released — likely in the spring of 2025.

However, in order to avoid a scramble to meet the new regulations with little notice, those requirements won’t become mandatory until after a three-year phase-in period."

Some questions I thought I should ask this community of compliance professionals were:

  • How do you see CMMC 2.0 affecting your company specifically?
    • What challenges do you anticipate when trying to meet these new regulations?
  • Is a 3 year phase in period enough to meet these new rules?
  • Do you think these updated standards will actually reduce cybersecurity risk?

I'd love to know your thoughts!