The Defense Department (DOD) has released the final rule for its Cybersecurity Maturity Model Certification (CMMC) program, marking a significant step towards enhancing the security of controlled but unclassified information held by contractors. Official publication is set for October 14, 2024, initiating a 60-day Congressional Review Act period during which Congress can block the rule, though observers deem this unlikely. CMMC introduces a third-party certification process for contractors to demonstrate compliance with the National Institute of Standards and Technology’s cybersecurity standard 800-171, replacing the previous self-certification method. The rule spans 470 pages and outlines internal and external mechanisms that DOD must implement, with comments due for the accompanying part 48 rule by Tuesday. The full roll-out of CMMC will commence once both part 32 and part 48 rules are finalized, anticipated by early 2025.
Mike Semel of Semel Consulting reached out to me and highlighted this passage: “If an OSA (Organization Seeking Assessment – the Defense Contractor) utilizes an ESP (External Service Provider), including a Cloud Service Provider (CSP), that does not process, store, or transmit CUI (Controlled Unclassified Information), the ESP (External Service Provider) does not require its own CMMC assessment. The services provided by the ESP (External Service Provider) are assessed as part of the OSC’s (Organization Seeking Certification – the Defense Contractor) assessment as Security Protection Assets.”
His initial analysis: As long as MSPs or their vendors aren’t processing, storing, or transmitting CUI (like with backups), you will not need an expensive CMMC Level 2 assessment.
Providers had better know what data their customers have. I may be a broken record, but data management lets you know if you’re handling CUI.
With the CMMC requirements becoming mandatory for defense contractors, a significant market opens up for managed service providers (MSPs), cybersecurity firms, and compliance specialists. Contractors will need extensive help aligning their systems with NIST 800-171 standards, spanning 110 security controls designed to protect sensitive information. MSPs can offer consulting, assessment, and remediation services to ensure clients achieve the necessary certification levels (CMMC Levels 1 to 3, depending on contract requirements).
And they need to know if they must be compliant themselves.

