News: 1757448380

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

New cybersecurity rules land for Defense Department contractors

(2025/09/09)


It's about to get a lot harder for private companies that are lax on cybersecurity to get a contract with the Pentagon, as the Defense Department has finalized a rule requiring contractor compliance with its Cybersecurity Maturity Model Certification (CMMC) program.

The final rule, which was [1]released as a preview ahead of its formal publication in the Federal Register on Wednesday, will go into effect on November 9. After that point, all vendors who contract with the DoD (known as the defense industrial base (DIB)) will need to meet one of three levels of CMMC compliance, depending on the sensitivity of unclassified information they handle, in order to be eligible for award consideration once the rule is phased in.

CMMC requirements include limiting access to sensitive data, authenticating users with access, imposing physical security rules for facilities where US government data is stored, installing regular software updates, and reporting/remediating any incidents promptly. Meeting Level 1 of CMMC requires an annual self-assessment and attestation. Level 2 may allow a self-assessment in rare cases, but most contracts will require a third-party audit. Level 3 demands a government-led assessment.

[2]

"We expect our vendors to put U.S. national security at the top of their priority list," said acting DoD Chief Information Officer Katherine "Katie" Arrington. "By complying with cyber standards and achieving CMMC, this shows our vendors are doing exactly that."

[3]

[4]

Arrington, who is performing the duties of DoD CIO without Senate confirmation after rejoining the department earlier this year (possibly due to the fact that her DoD security clearance was [5]suspended over concerns of disclosure of classified data in 2021), was instrumental in helping the DoD develop the CMMC during Trump's first term.

[6]Defense Dept didn't protect social media accounts, left stream keys out in public

[7]The US government has no idea how many cybersecurity pros it employs

[8]Forget the Space Force! Trump needs to create a Cyber Force, says think tank

[9]Signalgate lessons learned: If creating a culture of security is the goal, America is screwed

Hey, what about the Department of War?

You may have heard that President Donald Trump has recently found another way to drag the United States back into the past by renaming the DoD to the Department of War, a name it hasn't held since 1947. While that's technically true, we're going to keep calling it the DoD; thank you very much.

The US President lacks the authority to unilaterally rename a government branch. That authority is reserved for Congress. The President appears to know this, given his executive order renaming the DoD makes clear that it's [10]just a nickname , despite the government wasting money to [11]change signs and [12]redirect websites (many sites still use the defense.gov URL without a redirect) to make it look like an official action.

While the EO also directs the DoD to submit a recommendation that includes proposed legislative changes to formally rename the branch, that has yet to happen.

Vendors seeking contracts with the Pentagon under CMMC have to demonstrate clear evidence that they have conformed to [13]cybersecurity standards set forth in the program, which was made [14]official in October of last year. CMMC only applies to contractors working with information about federal contracts and controlled unclassified information. Classified data and the software systems that handle it are subject to different rules, though that's not to say those [15]rules [16]are [17]always [18]followed .

Vendors objected to many of the requirements imposed on them through the CMMC, leading to the development of a [19]revised [PDF] version. It's that version that was made official last year, and that version that contractors will need to comply with under the rule previewed on Tuesday.

In addition to putting the compliance onus on contractors, the new rule requires DoD contracting officers to specify the applicable CMMC level in solicitations and ensure awards only go to vendors with a current assessment or certification. The Pentagon didn't respond to questions for this story. ®

Get our [20]Tech Resources



[1] https://www.federalregister.gov/public-inspection/2025-17359/defense-federal-acquisition-regulation-assessing-contractor-implementation-of-cybersecurity

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aMCjeZrfVMhPMUteye4SYAAAAE8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aMCjeZrfVMhPMUteye4SYAAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aMCjeZrfVMhPMUteye4SYAAAAE8&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2025/02/19/trumps_pentagon_ciso_pick_was/

[6] https://www.theregister.com/2025/09/09/us_dod_exposed_keys/

[7] https://www.theregister.com/2025/09/08/us_govt_lacks_clarity_infosec_workforce/

[8] https://www.theregister.com/2025/08/04/think_tank_military_cyber_force/

[9] https://www.theregister.com/2025/04/25/signalgate_lessons_learned_if_creating/

[10] https://www.whitehouse.gov/presidential-actions/2025/09/restoring-the-united-states-department-of-war/#:~:text=may%20be%20referred%20to%20as%20the%20Department%20of%20War%20and%20the%20Office%20of%20the%20Secretary%20of%20War

[11] https://www.pbs.org/newshour/politics/watch-pentagon-changes-secretary-of-defense-signage-to-secretary-of-war

[12] https://www.defense.gov/

[13] https://www.acquisition.gov/far/52.204-21

[14] https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program

[15] https://www.theregister.com/2025/07/21/massive_security_snafu_microsoft/

[16] https://www.theregister.com/2024/04/05/microsoft_government_contracts/

[17] https://www.theregister.com/2024/04/21/microsoft_national_security_risk/

[18] https://www.theregister.com/2023/08/14/us_government_investigates_microsoft_breach/

[19] https://dodcio.defense.gov/Portals/0/Documents/CMMC/CMMC-FAQs.pdf

[20] https://whitepapers.theregister.com/



Eclectic Man

all vendors who contract with the DoD (known as the defense industrial base (DIB)) will need to meet one of three levels of CMMC compliance, depending on the sensitivity of classified information they handle

You mean they did not already have to have these measures in place?

Compliance officers everywhere are rejoicing

Anonymous Coward

Their future is guaranteed.

Engineers, not so much.

It is now 10 p.m. Do you know where Henry Kissinger is?
-- Elizabeth Carpenter