Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

DoD Updates Draft Cybersecurity Maturity Model Certification—300,000+ DoD Contractors and Subcontractors Required to Be Certified as a Prerequisite to Contracting

By David A. Simon, Marcia Madsen, Rajesh De, Veronica R. Glick & Joel Silverstein on May 16, 2019
Email this postTweet this postLike this postShare this post on LinkedIn

On November 7, the U.S. Department of Defense (DoD) Office of the Under Secretary of Defense for Acquisition and Sustainment (OUSD(A&S)) released Draft Version 0.6 of its Cybersecurity Maturity Model Certification (CMMC) for public comment. According to DoD’s overview briefing, the CMMC was created to provide “a unified cybersecurity standard for DoD acquisitions to reduce exfiltration of Controlled Unclassified Information (CUI) from the Defense Industrial Base (DIB).” In brief, the CMMC builds upon DFARS 252.204-7012, which generally requires contractors to maintain “adequate security” on all covered contractor information systems and to report any cybersecurity incidents to the DoD Cyber Crime Center (DC3) within 72 hours. The certification process, which will rely on non-government third parties, raises legal and business risks for contracting entities, including the potential for disputes. Whereas DFARS 252.204-7012 relies on contractor self-certification, the CMMC framework will require all government contractors and subcontractors to obtain cybersecurity certification from yet-to-be-created CMMC Third-Party Assessment Organizations (C3PAO) as a prerequisite to performing DoD contracts.1

Continue reading.

Photo of David A. Simon David A. Simon

David Simon is a partner in Mayer Brown’s Washington DC office and a leading member of the global Cybersecurity & Data Privacy practice. He is also a member of the firm’s National Security and Government Contracts practices. A former special counsel at the…

David Simon is a partner in Mayer Brown’s Washington DC office and a leading member of the global Cybersecurity & Data Privacy practice. He is also a member of the firm’s National Security and Government Contracts practices. A former special counsel at the US Department of Defense (DoD) and chief cyber counsel to the US Cyberspace Solarium Commission, David has deep experience advising victims of ransomware attacks and state-sponsored cyber activity. Named as a Cybersecurity Trailblazer by The National Law Journal, David has also been named to Cybersecurity Docket’s “Incident Response 40,” a collection of 40 of the “best and brightest” incident response attorneys in the country. David regularly supports clients as the lead investigator and crisis manager for cross-border cyber incidents, including data breaches involving personal data, nation-state threats targeting intellectual property, state-sponsored theft of sensitive U.S. government information, and destructive attacks. David has directed and advised on dozens of complex cyber incident and data breach investigations in the last few years alone. He has counseled companies on major cyber incidents and incident preparedness across virtually every sector of the economy. David represents financial institutions, automotive manufacturers and self-driving car companies, tech companies, telecommunications companies, healthcare companies, insurance companies, defense and aerospace companies, private equity firms and their portfolio companies.

Read David’s full bio.

Read more about David A. SimonEmailDavid's Linkedin Profile
Show more Show less
Photo of Marcia Madsen Marcia Madsen

Marcia focuses on Government Contracts and Litigation, advising clients on contract formation, teaming and strategic alliances, contract and subcontract negotiations, performance disputes, audits, terminations, cost accounting and allowability, technical data rights and trade secrets, and fraud/false claims investigations • litigates bid protests and…

Marcia focuses on Government Contracts and Litigation, advising clients on contract formation, teaming and strategic alliances, contract and subcontract negotiations, performance disputes, audits, terminations, cost accounting and allowability, technical data rights and trade secrets, and fraud/false claims investigations • litigates bid protests and claims and disputes before the GAO, the Boards of Contract Appeals, the Court of Federal Claims, and various other federal and state courts • has handled numerous ADR and mediation proceedings • areas of concentration include aerospace and defense contracts, systems integration, information systems and telecommunications contracts, health care and bio-technology, homeland security contracts, environmental remediation, and research and development contracts.

Read Marcia’s full bio.

Read more about Marcia MadsenEmail
Show more Show less
Rajesh De

Raj De serves on Mayer Brown’s global Management Committee. He was previously the Managing Partner of Mayer Brown’s Washington DC office, which is comprised of more than two hundred lawyers. He leads the firm’s global Cybersecurity & Data Privacy practice, as well as…

Raj De serves on Mayer Brown’s global Management Committee. He was previously the Managing Partner of Mayer Brown’s Washington DC office, which is comprised of more than two hundred lawyers. He leads the firm’s global Cybersecurity & Data Privacy practice, as well as the firm’s National Security practice, and serves as a member of the firm’s Congressional Investigations & Crisis Management team. After nearly two decades in private practice and public service across all three branches of the United States government, Raj is one of the most trusted voices in Washington. He has held senior appointments in the White House, the Department of Justice (DOJ) and the Department of Defense (DOD). Raj returned to Mayer Brown in 2015 after serving as General Counsel at the United States National Security Agency (NSA). Since returning to the firm, Raj has received numerous recognitions, including by American Lawyer (“Lateral All-Star”), Washingtonian magazine (“Top Lawyer”), The National Law Journal (“Cybersecurity and Data Privacy Trailblazer”), and Cybersecurity Docket (“Incident Response 30”).

Raj focuses his practice on cutting-edge legal and policy issues at the nexus of technology, national security, law enforcement and privacy. He advises clients, including management teams and boards of directors, in connection with crisis management, government and internal investigations, high-stakes litigation, regulatory enforcement matters, and congressional inquiries. Raj provides clients with strategic counseling and practical legal advice, drawing upon a wealth of experience in government service and private practice.

Read Raj’s full bio.

Read more about Rajesh DeEmail
Show more Show less
Photo of Veronica R. Glick Veronica R. Glick

Veronica Glick is a partner in Mayer Brown’s Washington, DC office and a member of the firm’s National Security and Cybersecurity & Data Privacy practices. She is also a member of the firm’s Litigation & Dispute Resolution practice and Congressional Investigations & Crisis…

Veronica Glick is a partner in Mayer Brown’s Washington, DC office and a member of the firm’s National Security and Cybersecurity & Data Privacy practices. She is also a member of the firm’s Litigation & Dispute Resolution practice and Congressional Investigations & Crisis Management team. Veronica focuses her practice on complex and cutting-edge legal issues regarding national security, cybersecurity and international law, with particular experience responding to multijurisdictional cyber incidents.

Read Veronica’s full bio.

Read more about Veronica R. GlickEmail
Show more Show less
  • Posted in:
    Government Contracts, Privacy and Cybersecurity
  • Blog:
    Inside Cybersecurity & Privacy Law
  • Organization:
    Mayer Brown

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo