Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

DOD Announces CMMC 2.0; Cancels Rollout of CMMC 1.0

By Jeffrey E. Jakob on November 11, 2021
Email this postTweet this postLike this postShare this post on LinkedIn
Programming and password concept - graphic

On November 4, 2021, the Department of Defense (DOD) announced it is revamping the Cybersecurity Maturity Model Certification program. The changes are intended to make the program more streamlined and flexible, which, in turn, will make it easier (and cheaper) for contractors to implement. Details of the revised program are limited, but some of the highlights include:

  • Fewer Levels: CMMC 2.0 will have only three levels of certification rather than five, and they will align more closely with existing cybersecurity standards. For example, Level 2 will align with NIST SP 800-171, the standard that applies when contractors handle controlled unclassified information.

  • Self-Assessments: Level 1 certifications, and in some cases, Level 2, can be based on self-assessments, whereas CMMC 1.0 did not allow for self-assessments. This will relieve many, if not most, contractors from the burden and expense of undergoing a third-party assessment, but it will also increase the potential for liability under the False Claims Act for contractors who incorrectly certify their compliance.
  • Flexible Timing: Contractors can be certified even if they do not meet all of the requirements as long as they have a clear plan as to when and how they will achieve those requirements. That flexibility will be limited, however, as certain requirements will have to be met prior to certification.

The DOD is implementing CMMC 2.0 through the rulemaking process and has indicated that the requirements will not appear in any contracts until that process is complete. The DOD estimates that could take anywhere from nine months to two years. In the meantime, the department is canceling its rollout of CMMC 1.0, which was supposed to be incorporated into an increasing number of contracts over the next five years. Therefore, while contractors are still encouraged to strengthen their cybersecurity, they do not have to worry about complying with CMMC for the time being.

Photo of Jeffrey E. Jakob Jeffrey E. Jakob

Jeff assists clients in a wide range of government contracting matters, including contracts, bid protests, and small business procurement issues. He also represents government contractors in all stages of litigation, including litigating claims under the Contract Disputes Act (CDA).t construction litigation experience and…

Jeff assists clients in a wide range of government contracting matters, including contracts, bid protests, and small business procurement issues. He also represents government contractors in all stages of litigation, including litigating claims under the Contract Disputes Act (CDA).t construction litigation experience and counsels owners, developers, general contractors, subcontractors, and suppliers in construction-related disputes. He has handled all types of dispute resolution, including litigation in state and federal courts as well as arbitration and mediation.

Continue Reading

Read more about Jeffrey E. JakobEmailJeffrey's Linkedin Profile
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Federal Construction Contracting Blog
  • Organization:
    Cohen Seglias Pallas Greenhall & Furman
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo