The Defense Department's proposed rule for acquisition purposes proposes alternative approaches to implement its Cybersecurity Maturity Model Certification program, while explaining why the Pentagon is moving forward with its preferred option. “DOD considered three alternatives for the timing of the requirement to achieve a CMMC 2.0 level certification in the development of this proposed rule, weighing the benefits and risks associated with requiring CMMC 2.0 level certification: (1) at time of proposal submission; (2) at time of award; or (3)...