Pentagon pauses the cyber audit rule that was pushing small suppliers out
The figure that seems to have finished the programme off is not a cost. It is a ratio: more than 100,000 companies in the American defence supply chain needing an independent cybersecurity audit, against roughly 100 accredited assessors licensed to carry one out.
“So the math just simply doesn’t math,” Kirsten Davies, the Pentagon’s chief information officer, told reporters, in what may be the most quotable sentence ever produced by a federal certification review.
On Monday, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification programme, the compliance regime that would have required contractors handling sensitive but unclassified information to pass an audit by a certified third-party assessor before winning contract awards.
Those requirements were due to take effect on 10 November. They are now frozen, along with every other pending CMMC milestone, until further notice.
The 💜 of EU tech
The latest rumblings from the...
Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE