Cybersecurity Maturity Model Certification (CMMC) Capabilities
BRG’s Government Contracts and Cybersecurity practices are an integrated team of professionals experienced in cybersecurity, incident response, government contracting, and technology risk. We help companies align and comply with the CMMC.
The US Department of Defense (DoD) created the Cybersecurity Maturity Model Certification (CMMC) to respond to the increasing presence of cyber threats and intrusions aimed at the defense industrial base and its supply chains of more than 300,000 defense contractors. This new risk-management framework is designed to assess and enhance the cybersecurity posture of all contractors and subcontractors doing business with the DoD. CMMC certification initially will be a requirement to participate in some DoD requests for information (RFIs) and requests for proposal (RFPs) and eventually will expand to cover all DoD procurement.
While the CMMC requirements build on the NIST 800-171 revision 1 security requirements and other cybersecurity standards and frameworks, there are key differences:
- CMMC does not allow self-attestations.
- CMMC requires a certified third-party assessment organization (C3PAO) to audit and certify an organization’s processes and practices as meeting the requirements for a certain maturity level (Levels 1 to 5).
- To achieve a certain maturity level, all security requirements or “practices” and processes associated with that level must be implemented at the time of audit. These requirements are cumulative.
- Plans of action and milestones (POA&Ms) will no longer be acceptable. At time of certification, you must have fully implemented all requirements.
Regardless of the size of the business, DoD contractors that do not comply with these requirements put their business at risk. Not meeting these requirements is not an option if you want to continue to do business with the DoD. Existing and future contracts are on the line if you are not in compliance.
How BRG Can Help
BRG’s Government Contracts and Cybersecurity practices are an integrated team of professionals experienced in cybersecurity, incident response, government contracting, and technology risk. We help companies align and comply with the CMMC.
In its efforts to help contractors meet the new compliance obligations, the CMMC has authorized certain organizations to provide CMMC consulting and support. These registered provider organizations (RPOs) must be staffed by registered CMMC practitioners who are trained in CMMC methodologies and trusted by the CMMC to provide assessment preparation and other services.
BRG has been approved by the CMMC Accreditation Body as an RPO and has several Registered Practitioners on its CMMC team.
Related Services
Related Industries
Our industry knowledge is broad and deep.
BRG combines intellectual rigor with practical, real-world experience. We have an in-depth understanding of industries and markets, with expertise spanning the major sectors of the global economy. Following are some of the many sectors that we know inside and out.