Tech group urges DOD to harmonize incident reporting requirements as part of CMMC acquisition rulemaking

By Sara Friedman / October 11, 2024 at 9:44 AM
The Information Technology Industry Council identifies concerns over the Pentagon's plans on cyber incident reporting from contractors in the context of the Cybersecurity Maturity Model Certification program, in response to a proposed rulemaking focused on acquisition requirements. A clause in the proposed rule would require a contractor to “Notify the Contracting Officer within 72 hours when there are any lapses in information security or changes in the status of CMMC certificate or CMMC self-assessment levels during performance of the contract,”...

Not a subscriber? Sign up for 30 days free access to exclusive, behind-the-scenes reporting on defense policy and procurement.

Log in to access this content.