logo

New cybersecurity rules land for Defense Department contractors

ID: 91117110-9c9c-521f-b8cf-044071e612c5

STIX ID: report--91117110-9c9c-521f-b8cf-044071e612c5

Feed Name: The Register (Security)

Date Published: 2025-09-09

Date Updated: 2026-04-26

Author: Brandon Vigliarolo

...
...

The U.S. Department of Defense has finalized its CMMC rule, effective November 9, requiring defense contractors to meet one of three cybersecurity compliance levels based on the sensitivity of unclassified data they handle. Level 1 involves annual self-assessment, most Level 2 cases require third-party audits, and Level 3 mandates government-led assessments. The rule also directs contracting officers to specify required CMMC levels in solicitations and only award to vendors with current assessments, reflecting a shift of compliance responsibility onto contractors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.