US Department of Defense issues strict new cyber rules for potential contractors
- New cybersecurity framework will soon come into effect
- The CMMC will see more complicated rules for potential vendors
- This is the second iteration of these regulations
A new set of requirements has just been published for potential Department of Defense vendors. The new Cybersecurity Maturity Model Certification 2.0 (CMMC) standards outline stringent compliance demands for any potential contractors for the DoD, which will officially come into effect November 10 2025.
“We expect our vendors to put U.S. national security at the top of their priority list,” Katie Arrington, acting Pentagon chief information officer, said in a statement. “By complying with cyber standards and achieving CMMC, this shows our vendors are doing exactly that.”
The new cybersecurity framework operates on three different levels of compliance dependent on the sensitivity of the data being handled. Vendors will not be eligible for DoD contracts if they do not meet the requirements.
A second try
Implementing the CMMC was a difficult and lengthy process, and the cybersecurity pushed back against the requirements during the first Trump administration, arguing that the rules are overcomplicated and that SMEs are overly burdened by the regulations.
In the second version of these requirements, the process of compliance has been simplified, with just three assessment levels down from five. Vendors can self-assess their cybersecurity at the lowest sensitivity level, but tier two must be verified by a certified third-party assessor, and tier three will require assessment from the Defense Industrial Base Cybersecurity Assessment Center.
The new requirements also set out ‘plans of action and milestones’ that will help contractors that don’t meet the regulations by allowing them 180 days of a conditional certification as they work to become compliant.
Earlier this year, the US Department of Defense was urged to address serious IT systems flaws after programs were found to be falling short of required performance standards – with four critical defense systems identified without “developed plans to implement a more rigorous cybersecurity approach—zero trust architecture—by the 2027 deadline”.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
You might also like
New cybersecurity framework will soon come into effect The CMMC will see more complicated rules for potential vendors This is the second iteration of these regulations A new set of requirements has just been published for potential Department of Defense vendors. The new Cybersecurity Maturity Model Certification 2.0 (CMMC) standards…
Recent Posts
- Shokz upgraded its open earbuds with better sound and a lighter design
- Shokz says its clip-on OpenDots 2 earbuds focus on improved volume and bass
- How to watch England vs New Zealand: TV Channels, Full Schedule & 1st Test Preview
- Nomad Goods Promo Codes: Get 25% Off in June 2026
- NordVPN Coupons and Deals: 77% Off in June 2026
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023