Table of Contents
Introduction:
CMMC 2.0 is now available! On November 4th, a proposed rule named “Cybersecurity Maturity Model Certification (CMMC 2.0) Updates and Way Forward” was inadvertently published in the Federal Register. The Under Secretary of Defense Acquisition and Sustainment Office (OUSD A&S) announced a new strategic approach for the CMMC framework. The release of CMMC 2.0 follows an internal DoD evaluation of the programme, which began in March 2021 in response to industry feedback on the interim DFARS rule.
Several changes will be made to the new CMMC Version 2.0 in comparison to the previous version. According to Jesse Salazar, Deputy Assistant Secretary of Defense for Industrial Policy, these changes “establish a more collaborative relationship with industry,” and “will support businesses in adopting the practices they need to thwart cyber threats while minimizing barriers to compliance with DoD requirements.”
What are the changes of CMMC 2.0?
These modifications will have far-reaching consequences throughout the CMMC ecosystem. They will also have a significant impact on the defence industrial base (DIB). This article will evaluate and discuss the effects of these changes:
1. Change 1: Reduces the model’s compliance levels from 5 to 3:
The prior model included five maturity levels, whereas the new model only has three.
Levels 2 and 4 were eliminated in the new format. Maturity Level 1 remained the same. It still has 17 practise standards that correspond to FAR 52.204-21‘s 15 cybersecurity practises. The former Maturity Level 3 has been replaced by the new Maturity Level 2. However, without the delta 20 practises, this level is aligned with the 110 practises of NIST SP 800-171. The new Maturity Level 3 is still in the works, and it is based on a subset of NIST 800-172. It replaces the previous Maturity Levels 4 and 5.
Previously, the Department of Defense only referred to Level 2 as a stepping stone to Level 3 and lumped Levels 4 and 5 together as a means of protecting extremely sensitive information that may be the target of advanced persistent threats. With the elimination of these Levels, contractors are left with only three levels of compliance in CMMC 2.0, depending on the sensitivity of the information and the nature of the work that they perform.
Level 1 (the bare minimum required to protect Federal Contract Information), Level 3 (the bare minimum required to protect CUI), and Level 5. (the minimum necessary to protect CUI that may be the target of advanced persistent threats).
Effects of change 1:
Under the previous version, it was expected that most firms would not strive to acquire Maturity Level 2 accreditation. This level was an intermediate step in this edition for individuals aiming for CUI certification. Only a few dozen of the largest prime contractors would have attempted Maturity Level 4 and 5 accreditation. The removal of the delta 20 practices from the new Maturity Level 2 had the greatest impact in CMMC 2.0. This brings the standards for dealing with CUI back in line with the current NIST 800-171 duties
2. Change 2: All maturity processes are eliminated:
CMMC-unique practices and all maturity processes from the CMMC Model.” ” are being phased out. Although it is unclear what DoD considers to be “CMMC-unique” practises, this change could indicate a shift, at least at the Level 3 and Level 5 certification levels, to remove controls that were incorporated into the previous version of the CMMC model but were not included in the 110 security controls in NIST SP 800-171 (Level 3), NIST SP 800-53 (Level 5), or NIST SP 800-172. (Enhanced Security Requirements for Protecting CUI).
Furthermore, eliminating the maturity processes requirement could greatly simplify the certification requirements, shifting the focus away from documentation and toward the technical execution of essential controls.
There were five maturity processes in the prior model. These were documented, managed, reviewed, and optimised as they proceeded from being done to being documented, managed, reviewed, and optimised. For those seeking a Level 2 certification, however, this does not negate the need for defined processes and standards.NIST 800-171.
These previous rules and controls were adjusted by NIST to protect CUI in nonfederal information systems. NIST cautioned that “organisations should not assume that satisfying those particular requirements (NIST 800-171) will satisfy the security requirements and controls in FIPS 200 and (NIST) SP 800-53,” and that “organisations should not assume that satisfying those particular requirements (NIST 800-171) will satisfy the security requirements and controls in FIPS 200 and (NIST) SP 800-53.”
Effects of change 2:
Organizations must design and publish an access control policy, according to NIST 800-53. It also necessitates the existence of procedures to aid in the implementation of the policy. For all 17 domains, NIST classified these policy and process criteria from NIST 800-53 as NFO controls. Neither NIST 800-53 nor FIPS 200 contain the CMMC 1.0 resourced plan requirements. For the new Maturity Level 2, CMMC 2.0 looks to delete these processes.
3. Change 3: Self-assessment will now be allowed for Maturity Level 1 certifications:
A selection of organisations seeking certifications (OSCs) aiming at Maturity Level 3 will be assessed by Certified Third-Party Assessor Organizations (C3PAOs). The subset of suppliers and contractors reviewed by C3PAOs will be determined by the type of contracts. Only those OSCs managing contracts with information deemed sensitive to national security will be subject to third-party reviews. Other OSCs with CUI may self-evaluate whether or not their contracts are considered essential to national security.
Maturity Level 3 certification will be evaluated by government officials. The Defense Industrial Base Cybersecurity Assessment Center, most likely (DIBCAC).
There was also a little divergence in the assessment process. The C3PAO would send an evaluation report to the CMMC-AB following a V1.02 assessment. After that, the CMMC-AB would conduct a final evaluation and either give a certification decision or resolve any disagreements. In version 2.0, the C3PAO now submits its assessment report to the Department of Defense.
Effects of change 3:
Cost is closely connected to enabling Maturity Level 1 certification by self-assessment. The bulk of the DIB will no longer be required to pay for a third-party assessment as a result of this move. The Maturity Level 2 certifications have been split into two parts, reducing the number of businesses that will need a third-party examination. In other words, under CMMC 2.0, C3PAOs will have a lot less work to do.
At this moment, the number of organisations that are permitted to self-assess is unknown. The Department of Defense looks to be narrowing the area of CUI they want to safeguard with the limited resources available.
4. Change 4: Plan of Action and Milestones (POA&Ms) are included:
Organizations could delay the implementation of NIST 800-171 regulations before CMMC. All they had to do was show that they intended to put those measures in place at some point in the future. The option to have a POA&M for any practise requirements at the assessed Maturity Level was eliminated in CMMC 1.0.
The possibility to employ a POA&M on a restricted basis has been restored in CMMC 2.0. At the time of the assessment, the highest weighted requirements (based on the SPRS point scale) must be fully executed. The Department of Defense also plans to publish a minimum SPRS score that will support certification with POA&Ms.
Effects of change 4:
The addition of POA&Ms marks a departure from CMMC 1.0’s pass/fail methodology. OSCs will now be able to pass a certification exam without completing all of the requisite practises. All that is required is that they use POA&Ms in accordance with yet-to-be-released guidance.
The higher the weighted requirements, the more expensive and complicated it is to establish controls. As a result, while POA&Ms are beneficial, only a subset of the requirements will allow them to be used.
5. Change 5: Waivers:
There was no provision for waivers in CMMC 1.0. The plan was for the CMMC DFARS clause to be included in an increasing number of contracts each year over the course of five years. An OSC would need to be certified before a contract with the CMMC DFARS clause could be awarded. CUI could not flow down from contracts with the CMMC DFARS clause unless the subcontracts received their CMMC certification, allowing them to receive the CUI. The concept of a waiver is introduced in CMMC 2.0.
These waivers will apply to the whole CMMC requirement (not individual controls) and will be approved on a case-by-case basis by senior DOD leadership. These waivers are expected to be used for time-sensitive acquisitions where CMMC regulations would impair mission-critical capabilities.
Effects of change 5:
Waivers would totally exclude an OSC from the CMMC 2.0 criteria. Waivers are granted based on the model’s exclusion rather than specific practices. According to the scant information available, the Department of Defense reserves the power to provide waivers with senior leadership approval in mission-critical situations. This section gives the Department of Defense the power to exclude any OSC from the cybersecurity standards.
6. Change 6: Accrediting C3PAOs, Assessors and Instructors:
The accreditation body will continue to be the CMMC-AB for:
1.C3PAOs
2. Assessors from the CMMC
3. CMMC Assessor Instructor Certification Organization is a non-profit organisation that certifies assessors and instructors (CAICO)
However, the AB must first comply with the ISO/IEC 17011 standard. C3PAOs must also meet ISO/IEC 17020 requirements, while the CAICO must meet ISO/IEC 17024 requirements. The DoD will accept all CMMC-AB conflicts of interest inside the ecosystem under CMMC 2.0.
Effects of change 6:
In March 2020, the CMMC-AB signed a Memorandum of Understanding to attain and maintain ISO/IEC 17011. As recently as the September 2021 Town Hall, CEO Matthew Travis admitted that ISO/IEC 17011 was a top priority for the CMMC-AB. We don’t expect any further C3PAOs to be accredited or a CAICO to be established until the CMMC-AB achieves ISO certification.
Overall, the proposed improvements simplify the CMMC model significantly compared to CMMC 1.0, and they represent a model that is much closer to the existing standards that contractors must meet.
Conclusion:
These changes are in response to concerns raised by the defence industrial base in a variety of ways, including the reduction of five levels to three, a greater reliance on existing federal sources of cybersecurity guidance (i.e., NIST standards), and the continued allowance of self-attestations of compliance by many defence contractors. At the same time, the Department of Defense’s new strategy follows vigorous efforts across the federal government to tighten cyber and supply chain security. Defence contractors and suppliers should continue to follow the existing cybersecurity “assessment” approach (detailed here), with a focus on compliance.
We here at Security Pilgrim are here to guide your business through the various cybersecurity concerns and compliances that can result in a robust and cyber-secure business.

