Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cloud

Navigating CMMC Compliance: The Essential Role of FedRAMP for Defense Contractors

by Kristen Smith
October 15, 2025
in Cloud, Cybersecurity, News
Deltek logo. Deltek outlines how FedRAMP standards simplify CMMC certification by strengthening cloud security.

Deltek outlines how FedRAMP standards simplify CMMC certification by strengthening cloud security.

The Department of Defense’s upcoming enforcement of the Cybersecurity Maturity Model Certification is reshaping how defense contractors approach cybersecurity.

Table of Contents

    • You might also like
    • William Pulte Named Acting Director of National Intelligence
    • Supriya Ahuja Assumes Acting Deputy CISO Role at DHS
    • Executive Order Advances AI Cybersecurity, Frontier Models
  • Where FedRAMP and CMMC Meet
  • What FedRAMP Moderate Requires
  • When FedRAMP Becomes Critical
  • Preparing for Implementation

You might also like

William Pulte Named Acting Director of National Intelligence

Supriya Ahuja Assumes Acting Deputy CISO Role at DHS

Executive Order Advances AI Cybersecurity, Frontier Models

According to software provider Deltek, Federal Risk and Authorization Management Program standards can simplify one of the most demanding pieces of CMMC compliance: cloud security. Contractors that rely on third-party cloud services to store, process or transmit controlled unclassified information should prioritize FedRAMP status to support CMMC assessments, the company added.

Where FedRAMP and CMMC Meet

CMMC verifies a contractor’s cybersecurity posture for DOD work, while FedRAMP evaluates cloud service providers for use across the federal government. The programs are distinct but connect where contractors use external cloud platforms. Under Defense Federal Acquisition Regulation Supplement 252.204-7012, cloud services handling CUI must have FedRAMP Moderate authorization or an approved equivalency to support CMMC Level 2 or Level 3 requirements.

What FedRAMP Moderate Requires

FedRAMP Moderate authorization entails implementation of extensive security controls, continuous monitoring and an external assessment. Providers unable to secure federal agency sponsorship can pursue FedRAMP Moderate equivalency, which requires the same technical controls and third-party verification but without an agency sponsor. The FedRAMP 20x initiative aims to shorten authorization timelines, though those process improvements remain in rollout.

When FedRAMP Becomes Critical

Deltek explained that FedRAMP requirements apply once CUI leaves internal systems and enters a third-party cloud environment. Contractors pursuing CMMC Level 2 or Level 3 certification must ensure their external providers hold FedRAMP Moderate authorization or equivalency and are listed on the FedRAMP Marketplace, verifying that the providers satisfy 325 security controls and maintain continuous system monitoring.

Deltek highlighted that CMMC and FedRAMP alignment has become a competitive necessity for the defense industrial base. Its Costpoint GovCon Cloud Moderate platform was developed to help contractors meet FedRAMP Moderate equivalency standards, supporting CMMC Level 2 certification and long-term cybersecurity maturity.

Preparing for Implementation

The DOD will finalize CMMC regulations on Nov. 10, setting in motion a phased rollout. Early phases permit self-assessments for some contractors, followed by mandatory third-party certifications. Deltek advises firms to start with a gap analysis against National Institute of Standards and Technology Special Publication 800-171, review their system security plans, confirm FedRAMP authorization for cloud services and ensure accurate reporting to avoid compliance risks.

Deltek has partnered with GovCon Wire for the CMMC Enforcement Starts in November: Why Compliance is Your Ticket to Success Webinar on Oct. 21. Register now!

Share5Tweet19

Recommended For You

William Pulte Named Acting Director of National Intelligence

by Jane Edwards
June 3, 2026
William Pulte. The Federal Housing Finance Agency director has been named acting director of national intelligence.

Trump has tapped William Pulte to serve as acting DNIPulte's appointment follows the resignation of Tulsi Gabbard as DNIThe 2026 Intel Summit on Sept. 24 will examine data,...

Read moreDetails

Supriya Ahuja Assumes Acting Deputy CISO Role at DHS

by Kristen Smith
June 3, 2026
Supriya Ahuja. DHS appointed cybersecurity leader Supriya Ahuja as acting deputy chief information security officer.

Supriya Ahuja was named acting deputy chief information security officer at DHSThe cybersecurity leader brings extensive experience in risk management, compliance and vulnerability programsThe appointment follows Ahuja's years...

Read moreDetails

Executive Order Advances AI Cybersecurity, Frontier Models

by Jane Edwards
June 3, 2026
Artificial intelligence. President Trump signed an executive order to drive AI innovation to strengthen U.S. cybersecurity.

Trump's new executive order has ordered agencies to prioritize AI-related cybersecurity measuresThe EO calls for the establishment of an AI cybersecurity clearinghouseThe 2026 Homeland Security Summit will examine...

Read moreDetails

Army PM EW&C Releases Forecast of Up to $2.8B in Contract Opportunities

by Charles Lyons-Burt
June 3, 2026
Army Project Manager Electromagnetic Warfare and Collection logo. The office issued a planning guide with contract info.

The Army's Project Manager Electromagnetic Warfare and Collection office has outlined several potential acquisition opportunities worth billions of dollars in a recently released FY2027 strategic planning guide, offering...

Read moreDetails

GAO Flags Federal EHR Cybersecurity Coordination Gaps

by Kristen Smith
June 3, 2026
GAO logo. The watchdog has called for stronger cybersecurity oversight of the federal EHR system.

GAO has called for stronger cybersecurity oversight of the federal electronic health record systemThe audit found gaps in how agencies define and measure joint cybersecurity and privacy effortsThe...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!