Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

What GovCons Need to Know About CMMC 2.0

by Pat Host
May 12, 2025
in Cybersecurity, News
What GovCons Need to Know About CMMC 2.0

CMMC 2.0 is moving forward at the Department of Defense despite a potentially high-ranking official promising to review the effort if confirmed.

Table of Contents

    • You might also like
    • Jay Clayton Nominated as Director of National Intelligence
    • Navy Discloses Topics for SBIR-STTR FY26 Release 3 Solicitation
    • DHS S&T Highlights New SPARTA Resources for Defending Spacecraft Against Cyberattacks
  • Who Is DOD’s Michael Duffey?
  • What Is SWFT?
  • Key CMMC 2.0 Impacts for GovCons

You might also like

Jay Clayton Nominated as Director of National Intelligence

Navy Discloses Topics for SBIR-STTR FY26 Release 3 Solicitation

DHS S&T Highlights New SPARTA Resources for Defending Spacecraft Against Cyberattacks

Cybersecurity Maturity Model Certification 2.0 is DOD’s framework for assessing contractor implementation of cyber requirements and improving their protection of unclassified information in the DOD supply chain. The program provides DOD with better assurance that government contractors and subcontractors are meeting the cybersecurity requirements for nonfederal systems processing controlled unclassified information—a.k.a. CUI—or federal contract information. The final CMMC 2.0 rule made it a requirement for bidding on defense contracts.

Katie Arrington, performing the duties of DOD chief information officer and a previous Wash100 Award winner, is pushing CMMC 2.0 forward after founding the program during the first administration of President Donald Trump. Contractors previously were only required to self-certify compliance with National Institute of Standards and Technology Standard 800-171, which provides federal agencies with recommended security requirements for protecting the confidentiality of CUI.

Get insights into how the Trump Administration will implement CMMC 2.0 at the Potomac Officers Club’s 2025 Cyber Summit on Thursday. Meet, learn and connect with DOD leaders, defense experts, research officials and industry executives at this can’t-miss event. Time is running out, sign up today!

Contractors are now required to use a third-party audit for CMMC 2.0 certification and many are unhappy about it.

“If you go on LinkedIn one more time and tell me how hard CMMC is, I’m going to beat you,” Arrington said, as reported by Washington Technology.

Who Is DOD’s Michael Duffey?

Contractors upset about CMMC 2.0 may receive relief from Trump nominee Michael Duffey, who was tabbed to be DOD undersecretary for acquisition and sustainment. Duffey told senators during his confirmation hearing that he would review CMMC 2.0 if confirmed. Redspin, a provider of cyber services involving CMMC 2.0, issued a report on GovCon preparedness for CMMC 2.0, saying most respondents did not feel ready for its requirements.

Duffey said in prepared remarks that it is important to improve cyber among defense GovCons without putting unnecessary requirements on small and medium-sized businesses. While these contractors, he said, can be more vulnerable to cyber attacks because of fewer financial resources, they play a pivotal role in supporting DOD.

“If confirmed, I will review the current requirements of the CMMC program and evaluate options to improve the requirements and implementation so that industry can affordably maintain pace with current cybersecurity best practices,” Duffey said.

What Is SWFT?

Arrington recently kicked off a new effort to improve how DOD acquires software that leverages CMMC 2.0. In a memo issued April 24, Arrington directed the development of the Software Fast-Track Initiative, or SWFT.

This will define clear and specific cyber and supply chain risk management requirements and stringent software security verification processes. It will also define secure information-sharing procedures and federal government-led risk determinations to accelerate cyber authorizations for faster software adoption.

Arrington said software providers will be required to provide her with DOD’s base risk scores on 12 characteristics of range, including CMMC 2.0. SWFT will use AI to evaluate contractor certifications for faster processing.

Key CMMC 2.0 Impacts for GovCons

CMMC 2.0 is a dramatic shift in how defense contractors must approach cyber compliance, according to a GovCon expert. Payam Pourkhomami, OSIbeyond president and CEO, said in GovCon Wire that contractors must meet one of three certification levels based on the sensitivity of the information they handle.

Level 1 requires annual self-assessments for federal contract information. Level 2 makes contractors either self-assess or provide third-party certification for CUI. The most strict, Level 3, requires DOD assessments for critical programs and high-value assets.

Non-compliance with CMMC 2.0, particularly when handling CUI, can lead to big consequences for GovCons. These include financial penalties, contract cancellations and long-term reputational damage. 

GovCons can learn more about consequences for CMMC 2.0 non-compliance at the Potomac Officers Club’s 2025 Cyber Summit. Held on Thursday at the Marriott Fairview Park in Falls Church, Virginia, the Cyber Summit is the best opportunity for GovCons to learn directly from federal cyber leaders from the CIA, DOD, U.S. Air Force and the DOD Cyber Crime Center, among others. Few tickets remain; don’t miss out!

What GovCons Need to Know About CMMC 2.0
Share5Tweet19

Recommended For You

Jay Clayton Nominated as Director of National Intelligence

by Jane Edwards
June 12, 2026
Jay Clayton. The U.S. attorney for the Southern District of New York has been nominated to serve as DNI.

Trump has nominated Jay Clayton to serve as director of national intelligenceClayton currently serves as U.S. attorney for the Southern District of New YorkThe 2026 Intel Summit will...

Read moreDetails

Navy Discloses Topics for SBIR-STTR FY26 Release 3 Solicitation

by Jane Edwards
June 12, 2026
Department of the Navy seal. The Navy has announced the topics for its SBIR and STTR Release 3 for fiscal year 2026.

The Department of the Navy has started the pre-release period for FY26 Release 3 SBIR/STTR topicsThe solicitation targets quantum, artificial intelligence and contested logistics technologiesThe 2026 Navy Summit...

Read moreDetails

DHS S&T Highlights New SPARTA Resources for Defending Spacecraft Against Cyberattacks

by Kristen Smith
June 12, 2026
DHS S&T logo. The directorate is supporting space cybersecurity research via SPARTA.

DHS S&T is backing research to defend space systems from cyberattacksThe work has produced two additions to The Aerospace Corporation's SPARTA frameworkDHS pointed to a 2022 attack on...

Read moreDetails

NASA Opens Applications for M-STAR Funding Opportunity

by Miles Jamison
June 12, 2026
Artemis logo. NASA has begun accepting applications for the M-STAR program.

NASA has opened M-STAR applications to support university-led space technology researchThe M-STAR program will help eligible institutions build stronger aerospace research capabilitiesThe initiative intends to fund projects supporting...

Read moreDetails

HHS to Sunset All NITAAC GWACs in October, Shift IT Buying to GSA

by Kristen Smith
June 12, 2026
HHS logo. HHS will sunset all NITAAC GWACs on Oct. 29.

HHS is sunsetting all NITAAC governmentwide acquisition contractsThe decision covers CIO-SP3, its small business counterpart and CIO-CSThe shutdown follows the cancellation of CIO-SP4The Department of Health and Human...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!