{"id":25461,"date":"2021-11-04T10:37:44","date_gmt":"2021-11-04T14:37:44","guid":{"rendered":"https:\/\/www.oxebridge.com\/emma\/?p=25461"},"modified":"2021-11-04T15:03:26","modified_gmt":"2021-11-04T19:03:26","slug":"breaking-pentagon-announces-cmmc-2-0-dismantling-the-bulk-of-prior-approach","status":"publish","type":"post","link":"https:\/\/www.oxebridge.com\/emma\/breaking-pentagon-announces-cmmc-2-0-dismantling-the-bulk-of-prior-approach\/","title":{"rendered":"BREAKING: Pentagon Announces CMMC 2.0, Dismantling Nearly All of Program to Date"},"content":{"rendered":"<p>The Dept. of Defense has released an <a href=\"https:\/\/www.oxebridge.com\/downloads\/2021-24160.pdf\">advanced notice of proposed rulemakin<\/a>g which announces it intends to scuttle the majority of the current CMMC plan, in favor of what it calls &#8220;CMMC 2.0.&#8221; The plan immediately suspends all current CMMC pilot projects, will abandon the tiered maturity model approach, and allow for self-attestation for what was previously known as maturity level 1.<\/p>\n<p>The new rule will scuttle entirely the prior &#8220;Interim Rule,&#8221; touted largely by the DoD, Katie Arrington, the CMMC-AB and the overnight cottage industry of CMMC consultants, and eventually result in a new DFARS rule to make CMMC 2.0 official.<\/p>\n<p>The new approach also allows for &#8220;waivers,&#8221; and would break the current CMMC level 3 requirements into separate sets of requirements.<\/p>\n<p>There is no mention of the CMMC Accreditation Body at all. Oxebridge <a href=\"https:\/\/www.oxebridge.com\/emma\/dod-cio-to-take-over-cmmc-while-accreditation-body-contract-will-lapse-as-moot\/\">reported yesterday<\/a> that the DoD intends to allow the CMMC-AB&#8217;s contract to lapse, as it shifts management of the program to the DoD&#8217;s Office of the Chief Information Officer.<\/p>\n<p>The changes now raise questions as to whether the credentials sold by the CMMC-AB to date have any value under the new scheme. Any training and credentialing done against CMMC 1.0 would now be obsolete.<\/p>\n<p>The full DoD announcement can be read <a href=\"https:\/\/www.oxebridge.com\/downloads\/2021-24160.pdf\">here<\/a> (PDF).<\/p>\n<p>This story is breaking.<\/p>\n<hr \/>\n<p><strong>UPDATE:<\/strong> Katie Arrington has admitted failure upon the news of CMMC 2.0, in a post on LinkedIn:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-25472\" style=\"border: 1px solid #000000;\" src=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2021\/11\/failure11-04-2021.jpg\" alt=\"\" width=\"500\" height=\"99\" srcset=\"https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2021\/11\/failure11-04-2021.jpg 662w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2021\/11\/failure11-04-2021-150x30.jpg 150w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2021\/11\/failure11-04-2021-200x40.jpg 200w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2021\/11\/failure11-04-2021-24x5.jpg 24w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2021\/11\/failure11-04-2021-36x7.jpg 36w, https:\/\/www.oxebridge.com\/emma\/wp-content\/uploads\/2021\/11\/failure11-04-2021-48x9.jpg 48w\" sizes=\"(max-width: 500px) 100vw, 500px\" \/><\/p>\n<p>&nbsp;<\/p>","protected":false},"excerpt":{"rendered":"<p>DoD&#8217;s announcement dismantles nearly every aspect of what has been done to date, including the entire maturity level approach.<\/p>","protected":false},"author":644,"featured_media":24880,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","mc4wp_mailchimp_campaign":[],"footnotes":""},"categories":[3],"tags":[7679,7680,938,7683],"class_list":["post-25461","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-cmmc","tag-cmmc-ab","tag-cybersecurity","tag-cybersecurity-maturity-model-certification","et-has-post-format-content","et_post_format-et-post-format-standard"],"_links":{"self":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/25461","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/users\/644"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/comments?post=25461"}],"version-history":[{"count":7,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/25461\/revisions"}],"predecessor-version":[{"id":25474,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/posts\/25461\/revisions\/25474"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media\/24880"}],"wp:attachment":[{"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/media?parent=25461"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/categories?post=25461"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxebridge.com\/emma\/wp-json\/wp\/v2\/tags?post=25461"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}