Skip to content Skip to footer

Is Your Business Ready for CMMC?

What is CMMC?

CMMC stands for Cybersecurity Maturity Model Certification. This certification will be taking over the role of NIST 800 – 171 regarding qualifications to work with the Department of Defense. The Cybersecurity Maturity Model Certification will have many of the same controls as NIST 800 – 171 but will have about 33 more in addition. CMMC will be needed by every contractor and subcontractor to continue working with the DoD by 2020. So, is your business ready for CMMC?

A lot of details of the CMMC are still being determined.  

CMMC Requirements:

CMMC will have several of the same controls as NIST 800-171. Also, there is a requirement of a 3rd – party audit in order to receive certification. This is different from the self- verification of NIST. With NIST, contractors could rank themselves with the honors- system. Now, with CMMC, this is not the case. The contractors will have to find a CMMC approved auditor and go through the process. The auditor will rank the contractors from 1 to 5. The levels of the contractors are important because that will determine not only the contractors’ status, but this will also show which contracts they can bid on. 

What are the levels of CMMC?

Now that we know what the requirements are, let’s go over the levels. There are five levels of the CMMC. These levels are based on the maturity level of your security standards. The levels range from 1 to 5. Level 1 is the most basic level, “Basic Cyber Hygiene”. The next Level is 2, “Intermediate Cyber Hygiene”. Following, is Level 3, which is “Good Cyber Hygiene”. Level 4 is “Proactive”. Finally, Level 5, is the “Advanced or Progressive” level. The higher the maturity level, the better off your company will become. 

Common Questions regarding CMMC:

There is still unknown information about the CMMC. The information below is what we do know now.  

  • The final version of the CMMC will be available this upcoming January (2020).
  • The auditors for the CMMC must be an approved, non-related, 3rd- party.
  • https://www.acq.osd.mil/cmmc/faq.html 

For more information on CMMC and how it will affect your business, visit our website.

Interested in more ways to secure your business? Subscribe below to receive more information:

Share it :
Facebook
Twitter
LinkedIn

Rule your records in a digital landscape

NARA M-19-21

Journey face blended into fingerprint with yellow ring

For over 14 years, Bravo has proven continuous success with our clients by providing digital records management solutions. Our ultimate goal is to ensure that your organization is in records compliance and adhere to the National Archives and Records Association mandates. By partnering with Bravo, our records management team will ensure that your documents are properly digitized and stored before final approval of the file plan. Per the OMB/NARA Memorandum M-19-21: Transition to Electronic Records, all Federal agencies must manage all temporary records in an electronic format and manage all permanent records in an electronic format with appropriate metadata by the end of the year. For further review of your existing process, we can set up a records consultation with our team to discuss methods to finalize your digital file plan. 

If you have any additional questions about the 2022 NARA Mandate, our compliance experts are happy to answer them for you! Please fill out the form at the bottom of the page. 

Latest Update

Recommended Blogs

3 ways to strethc your cybersecurity budget
Cybersecurity

3 Ways to Stretch Your Cybersecurity Budget

3 Ways to Stretch Your Cybersecurity Budget In today’s environment, increased digital platforms in the workplace can make managing your cybersecurity budget a seemingly impossible task. Luckily, it doesn’t have

Business Email Compromise
Cybersecurity

BEC Scams: What You Need to Know!

BEC Scams: What You Need to Know! As we get deeper into October, which is National Cybersecurity Awareness Month, the need for proper cyber hygiene measures is more apparent than

Talk to a Human

Bravo is here to help you, not to spam you

Rule your records in a digital landscape

NARA M-19-21

Journey face blended into fingerprint with yellow ring

For over 14 years, Bravo has proven continuous success with our clients by providing digital records management solutions. Our ultimate goal is to ensure that your organization is in records compliance and adhere to the National Archives and Records Association mandates. By partnering with Bravo, our records management team will ensure that your documents are properly digitized and stored before final approval of the file plan. Per the OMB/NARA Memorandum M-19-21: Transition to Electronic Records, all Federal agencies must manage all temporary records in an electronic format and manage all permanent records in an electronic format with appropriate metadata by the end of the year. For further review of your existing process, we can set up a records consultation with our team to discuss methods to finalize your digital file plan. 

If you have any additional questions about the 2022 NARA Mandate, our compliance experts are happy to answer them for you! Please fill out the form at the bottom of the page. 

Latest Update

Recommended Blogs

3 ways to strethc your cybersecurity budget
Cybersecurity

3 Ways to Stretch Your Cybersecurity Budget

3 Ways to Stretch Your Cybersecurity Budget In today’s environment, increased digital platforms in the workplace can make managing your cybersecurity budget a seemingly impossible task. Luckily, it doesn’t have

Business Email Compromise
Cybersecurity

BEC Scams: What You Need to Know!

BEC Scams: What You Need to Know! As we get deeper into October, which is National Cybersecurity Awareness Month, the need for proper cyber hygiene measures is more apparent than

Talk to a Human

Bravo is here to help you, not to spam you