At the end of December, the Department of Defense published its proposed rule implementing the Cybersecurity Maturity Model Certification. This long-anticipated issuance answered many — but not all — of the questions about how the department will implement the program. In this episode of Bona Fide Needs, Arnold and Porter's Ronald Lee and Tom Pettit discuss the proposed rule and address some of those questions contractors may be asking:

  • What should contractors focus on immediately?
  • What did the rule resolve and what was left uncertain?
  • How should subcontractors approach the proposed rule?
  • Can a contractor (or DIDBCAP for Level 3) ever affirm compliance if the contractor IT system is not in full compliance?
  • How can a contractor lose a self-certification or certification assessment?

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.