- Cybersecurity
- Defense
DOW CIO Says There is ‘Work to Do’ on CMMC
Kirsten Davies said CMMC’s ongoing suspension will address challenges like cyber resilience and compliance barriers for the defense industrial base.
Kirsten Davies isn’t ready to tell you where the Cybersecurity Maturity Model Certification (CMMC) program is headed yet, but she divulged a little more Wednesday about where she wants it to go.
Speaking at the Billington Cybersecurity conference, the War Department chief information officer promised “no spoilers” about the current state of the cybersecurity regulation that the DOW officially paused in July, but outlined some of the concerns raised by the defense industrial base that she said need to be addressed.
“Compliance equals compliance. Compliance doesn’t equal security,” she said. “Compliance equals a point-in-time check of, ‘Where are you right now?’ We all know that cybersecurity is a dynamic process. It needs to be contiguous and continuous, and it needs to be at the pace of the threat in and of itself.”
As it currently stands, CMMC is an acquisition regulation requiring defense contractors at all levels to attest to a minimum level of cybersecurity protections to be able to do business with the government.
Though in the works since the first Trump administration, CMMC has been controversial for the compliance costs that small and midsize defense contractors would have to pay to assess their required cybersecurity levels.
DOW paused the implementation of Phase 2 of the regulation in July for 60 days, which includes the mandatory cybersecurity assessments for contractors conducted by Certified Third-Party Assessor Organizations (C3PAOs), to address those concerns.
The CIO said that the DOW is in the middle of a listening tour with the DIB, which has included more than 1,100 responses to a department-issued request for information and other outreach. Davies said she has heard calls for reforms that would make the regulation less costly for contractors and more dynamic in its intended effect.
“Operational technology is so critical right now, and nowhere in CMMC was there even a mention of how to build cyber resilience for a manufacturing line,” she said. “It’s all about clean data. So information security, 100%, that’s important, but it’s also federally mandated elsewhere. Handling federal data doesn’t necessarily build cyber resilience for small to medium manufacturing companies.”
Davies said her team is currently working to address those concerns in the CMMC revamp, as well as others raised by the C3PAOs, such as how to verify that the DIB is following federal policy. The department is also posting some of that work online.
But at its core, the CIO said the pause was necessary to ensure the regulation addresses concerns that compliance requirements could ultimately hobble contractors critical to the DOW.
“We rely on the defense industrial base for the manufacturing, for the innovation that is there. And CMMC was hitting small to medium-sized businesses really, really hard,” she said. “So we have some work to do, it’s coming.”
This is a carousel with manually rotating slides.
Use Next and Previous buttons to navigate
or jump to a slide with the slide dots
