Note: Important Change as of November 2021
The Department of Defense announced a major overhaul to the Cybersecurity Maturity Model Certification (CMMC) program. No new contracts will feature CMMC compliance requirements until the Department completes its rulemaking process for CMMC 2.0. Read our summary of the changes, Goodbye CMMC 1.0, Hello CMMC 2.0. For more detailed information, visit the CMMC website.
Keiter’s Cybersecurity team will continue to monitor the rollout of the CMMC program and update you on new information and changing requirements for DoD contractors.
Boston, Essex, and other Massachusetts Department of Defense (DoD) contractors and subcontractors will soon be required to comply with the new Cybersecurity Maturity Model Certification (CMMC) standard. The new standard is designed to help counteract the significant increase in the compromises of sensitive defense information which is shared across the defense industrial base.
In the past, DoD contractors have been responsible for maintaining certain cybersecurity practices, but under the emerging CMMC requirements contractors must undergo third-party compliance assessments and implement additional security protections. Once implemented contractors and subcontractors will need to be compliant to be awarded contract work.
5 CMMC Maturity Levels (ML)
Phased in over a five-year period, CMMC includes 5 maturity levels based on a Massachusetts DoD contractor’s access to Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). CMMC ML 1, known as basic cyber hygiene, requires the use of techniques such as antivirus and passwords to control access to FCI. The requirements become more complex reaching a Level 5, Optimizing, which requires standardized processes to address Advanced Persistent Threats (APT).
Massachusetts Top DoD Spending Locations
Boston CMMC Services
Many Boston DoD contractors will need assistance performing initial assessments to uncover issues, establish corrective actions, and to chart a path towards CMMC readiness.
The CMMC is complex. ML 3 contains 381 discrete cybersecurity requirements spread among 130 practices, and 310 policy/procedure requirements spread among 51process maturity requirements. The requirements are complex, and our team has almost 20 years of experience providing cybersecurity compliance services across many complex frameworks such as NIST SP 800-171, NIST SP 800-53, HIPAA, and others. As a CMMC Registered Provider Organization (RPO), our team can help DoD prime and subcontractors with the following:
Readiness Assessments and Gap Analyses Against the CMMC Framework
Assistance with Remediating Gaps Identified during Readiness Assessment
Assistance with NIST SIP 800-171 Self-Assessment that is recorded in Supplier Performance Risk System
Creating System Security Plans (SSP)
Creating Plans of Action and Milestones (POA&M)
About Boston (MA)
Boston, Massachusetts, often referred to as the “Hub of the Universe” or the “Cradle of Liberty,” is a historic and vibrant city located in the northeastern part of the United States. As the capital and largest city of Massachusetts, Boston is renowned for its rich history, prestigious universities, and thriving cultural scene. Here’s a narrative about Boston, MA:
Nestled along the picturesque shores of Massachusetts Bay, Boston stands as a living testament to the birth of a nation and the pursuit of freedom. From its pivotal role in the American Revolution to its present-day status as a hub of innovation and academia, Boston’s story is one of resilience, intellectualism, and a deep reverence for its storied past.
Boston’s history is woven into the very fabric of the city. Walking along the cobblestone streets of the Freedom Trail, visitors are transported back in time, passing by iconic landmarks such as the Massachusetts State House, Paul Revere’s House, and the Old North Church. These hallowed sites serve as reminders of the city’s role in shaping American history and the ideals of liberty and independence.
Contact Our CMMC Team
Keiter provides CMMC readiness assessments and remediation services to DoD contractors across Massachusetts includingEssex and Boston. If you are interested in learning how we can assist your organization, complete the form below and a team member will follow up promptly.