Key quotes from the new 48CFR Rule for #CMMC. This rule is the one that goes into new and renewing contracts and requires having a CMMC certificate or self-assessment upon contract award. They tightened up the language quite a bit. On quick scan, it looks well done. The first 40 pages give a lot of information about the DoD's thought process on CMMC, including some technical clarifications like whether joint ventures need to be individually certified, and whether talking about CUI over the phone is in scope.
𝐓𝐡𝐞 𝐂𝐨𝐧𝐭𝐫𝐚𝐜𝐭𝐨𝐫 𝐬𝐡𝐚𝐥𝐥 - - (these quotes from the proposed 48CFR Rule that is releasing tomorrow) "Have a current CMMC certificate or current CMMC self-assessment at the following CMMC level, or higher: ____________ [Contracting Officer to fill in the required CMMC level];" "Only process, store, or transmit data on information systems that have a CMMC certificate or CMMC self-assessment at the CMMC level required by the contract, or higher;" "Notify the Contracting Officer within 72 hours when there are any lapses in information security or changes in the status of CMMC certificate or CMMC self-assessment levels during performance of the contract; " "Ensure all subcontractors and suppliers complete and maintain on an annual basis, or when changes occur in CMMC compliance status (see 32 CFR part 170), an affirmation of continuous compliance with the security requirements associated with the CMMC level required for the subcontract or other contractual instrument for each of the contractor information systems that process, store, or transmit FCI or CUI and that are used in performance of the contract. " "Prior to awarding a subcontract or other contractual instrument, ensure that the subcontractor has a current CMMC certificate or current CMMC self-assessment at the CMMC level that is appropriate for the information that is being flowed down to the subcontractor." Also introduces unique IDs for assessed information systems, to prevent gaming the system. "(2) Contracting officers shall require the apparently successful offeror to provide the DoD UID(s) applicable to each of the contractor information systems that will process, store, or transmit FCI or CUI and that will be used in performance of the contract.” “DoD unique identifier means an alpha-numeric string of ten characters assigned within the Supplier Performance Risk System to each contractor assessment, with the first two characters indicating the confidence level of the assessment.” Link to text: https://lnkd.in/dnpwiStQ #CMMC