Department of Defense Releases CMMC Implementation memo

Department of Defense Releases CMMC Implementation memo
On January 17, 2025, the Department of Defense released a memo titled, "Implementing the Cybersecurity Maturity Model Certification (CMMC) Program: Guidance for Determining Appropriate CMMC Compliance Assessment Levels and Process for Waiving CMMC Assessment Requirements." 

The purpose of the document is to help program managers and contractors determine the appropriate CMMC level for that contractor. The memo notes that the guidelines it sets forth are for minimum CMMC requirements. When companies handle, transmit, or store CUI, they must use the highest possible level of CMMC compliance to protect that data. 

The memo can prove helpful to you as you work to understand how your business can work toward CMMC compliance. For example, it outlines:
  • When a self-assessment is appropriate
  • When a self-assessment is appropriate for level 2
  • What contractors need to meet level 3 CMMC compliance
You can download the document here

As you read through the guidelines, please feel free to contact us with any questions, or schedule a meeting with us for a longer discussion. 
Cancel
Show Policy

Latest Resources

See all resources