The CMMC Proposed Rule and Expectations in 2024

The CMMC Proposed Rule and Expectations in 2024

In December 2023, the Department of Defense announced its new Proposed Rules for CMMC. This release comes two years after their initial proposal for CMMC 2.0 as a framework. 


Many of CMMC’s expected requirements are coming to pass, and the DoD is looking to finalize and aggressively roll out the program over the next three years. 


Learn more about this next phase in CMMC implementation and what it might mean for your organization.

What Is CMMC 2.0?


CMMC 2.0 is a revision of the original 1.0 specification intended to streamline and bolster model aspects based on initial engagement and feedback from organizations and stakeholders. The CMMC framework assures that contractors have a consistent and appropriate model for their security, abide by reasonable and mature cybersecurity practices and processes, and maintain those standards over time.


In a broad sense, version 2.0 was designed to ease contractors’ certification paths, lower costs for small and medium enterprises, and raise visibility and access to cybersecurity requirements. 


Major updates in CMMC 2.0 include:


  • Maturity Level Simplification: The initial five levels were reduced to simplify the framework. This simplified compliance expectations and removed unnecessary “gap” maturity levels–the original Levels 2 and 4 were generally seen as preparatory phases between an organization’s ability to handle CUI and its ability to handle Advanced Persistent Threats (APTs). 

  • Assessment Prioritization: Under CMMC 2.0, third-party assessments will be mandatory for companies at Levels 3 and most at Level 2; companies at Level 1 can perform self-assessments, significantly reducing the compliance barrier for small businesses with less sensitive information.

  • POA&M (Plan of Action and Milestones): This enables organizations with non-compliant systems to finalize certification later, provided ..

    Support the originator by clicking the read the rest link below.