DOD Ready to Begin CMMC Accreditations
Defense acquisition’s top official brief next plans of certifying contractors according to new cybersecurity standards.

The Defense Department will begin rolling out its Cybersecurity Maturity Model Certification (CMMC) framework for all military contractors to undergo assessments starting Dec. 1, DOD Chief Information Security Officer for Acquisition and Sustainment Katie Arrington confirmed.
Arrington expanded on the announcement during C4ISRNET CyberCon Wednesday by sharing that the department is finalizing the CMMC Accreditation Body (CMMC AB) statement of work, which will establish a third-party assessment organization to review CMMC cybersecurity compliance in new military contracts starting in December.
“As of Dec. 1, cybersecurity is in all acquisitions,” Arrington said. “Contracts prior to award need to register their self assessment via [Supplier Performance Risk System] platform, and as we move forward with the CMMC we actually had a meeting today to get ready to release the pilot programs. Each of the services and co-comms and, I want to say, two support agencies, are getting ready to release the pilots and where they’ll be.”
DOD established a memorandum of understanding in March to eventually form the CMMC AB, an organization that would establish a standard for CMMC that would guide its certification of organizations seeking to conduct business with the military based on the new tiered cybersecurity controls that the model is establishing.
Over recent months, the CMMC AB has been training auditors through “pathfinders,” Arrington said, where those individuals underwent provisional training and mock cybersecurity audits using the CMMC guidance.
“This week will be the end of the third tranche of provisional assessors through the accreditation body’s training and assessment period, and as soon as the rule goes into effect on Dec. 1, we can get them from provision to actual, real certification,” Arrington added.
Arrington and her team decided, after receiving feedback from others across DOD as well as academia and industry, to establish three International Organization for Standardization (ISO) certifications in the CMMC AB statement of work. Three of them need to be within two years, which is the standard onboarding process to ensure continuity and meet ethics requirements, she added.
CMMC has five levels of cybersecurity requirements, and each contract will require a certain level that contractors need to meet, where Level 1 corresponds to basic safeguarding requirements established by the Federal Acquisition Regulation, and Level 5 sets the most robust cybersecurity requirements for contractors and suppliers.
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
Inside Oak Ridge National Lab’s Pioneer Approach to AI
Energy Department’s Oak Ridge National Lab transforms AI vulnerabilities into strategic opportunities for national defense.
22m listen -
A Look at Federal Zero Trust Transformation
Recent developments from CISA and DOD show how government is advancing zero trust quickly.
20m read -
Modernization Strategies to Enable Energy Innovation
Lawrence Berkeley National Lab and Maximus experts explore the modernization strategies driving digital transformation and operational resilience within the energy sector.
33m watch -
DOI Must Modernize Energy to Win AI Race, Secretary Says
Doug Burgum links AI innovation to energy reform as DOI advances digital infrastructure and wildfire response under Trump’s tech agenda.
2m read -
Army Combines Commands to Propel Innovation Under New Transformation Plan
Lt. Gen. Miles Brown outlines a new transformation strategy after the AFC–TRADOC merger to integrate new technologies within 18 months.
4m read -
NIST to Release New AI Cybersecurity Guidance as Federal Use Expands
NIST plans to release AI cybersecurity guidance within the year to support safe adoption as federal agencies expand use cases.
4m read -
Federal Zero Trust Forum
The Federal Zero Trust Forum brings together key technology leaders from across government to explore practical strategies and share lessons for advancing zero trust architecture.
Ritz Pentagon City | 1250 S Hayes St, Arlington, VA 22202 -
CIA Adds Fourth Pillar to AI Strategy, CAIO Says
Lakshmi Raman says the new pillar marks a strategic shift toward embedding AI more deeply into the CIA’s day-to-day mission execution.
3m read -
FEHRM CTO Targets Two-Year Cloud Migration for Federal EHR
Lance Scott touts new EHR tech advancements, including cloud migration, expanded data exchange and AI integration to improve care delivery.
4m read -
AI Enables Coast Guard’s Workforce to Transform Operations
The Coast Guard’s Deputy CIO Brian Campo delves into the ways AI is pushing the service to rethink its core services, workforce and operations.
14m watch -
New Army Acquisition Plan Cites Autonomy, Predictive Analytics
Officials outline how the Army Transformation Initiative signals a broader shift toward efficiency with tech and acquisition reform.
4m read -
DOL Turns to Workforce Development to Maintain AI Superiority
DOL is bridging the AI skills gap through partnerships and upskilling to ensure future AI workforce readiness.
10m watch