Recently introduced, the Cybersecurity Maturity Model Certification framework will dramatically change the process for IT vendors looking to do business with the Defense Department.
Recently introduced, the Cybersecurity Maturity Model Certification framework will dramatically change the process for IT vendors looking to do business with the Defense Department. Put simply, vendors will no longer be able to self-attest that all necessary controls are either in place or will be in place within a specified time frame; now, they'll be assessed by a third party and issued a level rating.
Greg Thornton with SSE Inc. in St. Louis, MO shares insights into CMMC and what will be required from IT vendors looking to work with DoD.
How does it work?
The Department of Defense is currently setting up the accreditation body that will oversee the program. Sometime this month, they will release the memorandum of understanding and then begin the process of credentialing C3PAOs, the third-party organizations that will assess and certify vendors and then monitor those certifications going forward.
Vendors will be certified on a five-tier system based on their progress toward 173 practices and 43 capabilities. The standards used are based on the National Institute of Standards of Technology, international standards and standards that drive aviation. After compiling all standards, the Pentagon worked through the list to reduce it to those that will be used going forward.
How will it impact IT vendors?
There are both advantages and disadvantages to IT vendors. Right now, if two vendors bid on a single project, the vendor with the lower rate will win. However, what clients can't see is that one vendor has 110 controls in place with the other vendor may only have 80 or 90 controls in place and an action plan in motion for the remaining controls. The current process is deceiving to clients and leaves more qualified vendors with less work, in many cases. The new process brings awareness to the difference between a higher bid and a lower bid, giving qualified vendors a better shot at the projects they want.
However, there are disadvantages. Those lower-priced vendors with fewer controls in place may find it more difficult to compete despite lower bids due to the transparency of the rating system. Additionally, not all vendors are in a position to attain certification due to the commitment required to meet all controls. The Department of Defense does plan to offer scholarships or grants to assist vendors who need it.
Are all vendors impacted?
No. Right now, the certification is required for vendors who want to provide contracted services to the Defense Department. However, those working in tech know how critical it is to be nimble and ready for change all times, and this certification program could easily lay the groundwork for the future. Large organizations may choose to adopt the same standard for increased security, marking the beginning of new expectations across the board when it comes to IT vendor selection.
For this reason, it is in the best interest of IT services vendors to work toward certification whether they plan to work for the Defense Department or not and in the best interest of organizations to consider adopting the same or similar standards.
This article does not necessarily reflect the opinions of the editors or management of EconoTimes.


Supreme Court Asked to Reinstate Mail-Order Access to Abortion Pill Mifepristone
Starbucks Raises 2026 Outlook as Turnaround Strategy Boosts Sales and Earnings
Samsung Reports Record Profit as AI Boom Drives Memory Chip Demand
T-Mobile Beats Q1 Earnings Expectations on Strong Postpaid Growth
Why Paycom Was Named a 2026 Platinum Employer on the Where You Work Matters List
Coles Group Q3 Sales Rise Driven by Supermarkets and E-Commerce Growth
TSMC Exits Arm Holdings with $231 Million Share Sale Amid Strategic Portfolio Shift
GameStop Eyes eBay Acquisition as Stock Prices Surge After Hours
U.S. Cybersecurity Pushes Faster Patch Deadlines Amid Rising AI-Driven Threats
United Airlines Flight Hits Light Pole During Newark Landing, FAA Investigates
Robinhood Q1 Earnings Miss Expectations, Stock Drops After Hours
Ford Q1 Earnings Beat Expectations, Stock Surges on Strong Guidance
NAB First-Half Earnings Miss Forecasts Amid Rising Global Risks
Anthropic’s $1.5B AI Venture with Wall Street Firms Targets Private Equity Market
Standard Chartered Q1 Profit Hits Record on Wealth and Investment Banking Growth
Pershing Square Raises $5 Billion in Landmark U.S. IPO and Share Placement
Apple Q2 2026 Earnings Surge as iPhone 17 Sales Drive Record Revenue 



