Lawyers argue for allowing plan of action and milestones to address security lapses in CMMC compliance

By Sara Friedman / November 12, 2024 at 2:25 PM
The American Bar Association’s Public Contract Law section is urging the Defense Department to consider allowing a plan of action and milestones for contractors to address ongoing compliance issues with the Cybersecurity Maturity Model Certification program, as the Pentagon works to finalize a rulemaking to change its acquisition regulations. “The Proposed Rule requires contractors to achieve, at time of award, a CMMC certificate or CMMC self-assessment at the level specified in the solicitation, or higher. This is understandable as part...

Not a subscriber? Sign up for 30 days free access to exclusive, behind-the-scenes reporting on defense policy and procurement.

Log in to access this content.