SlideShare a Scribd company logo
1 of 21
Presenters
01 | Senior Manager, Rea & Associates – Millersburg, Ohio
02 | 8+ years of Manufacturing experience
03 | Consulting – Product Costing, Profitability, Inventory, & Operations
04 | Tax Planning and Advisory
05 | Rea Manufacturing & Distribution
● Andrew Geiser, CPA
Presenters
01 | Sr. InformationAssurance Manager, Rea & Associates
02 | 10+ years of Information Technology experience
03 | Consulting – CMMC, Governance| Risk | Compliance
04 | FBI InfraGard Member
05 | Rea Cyberservices Division
● Tyrone Whittenburg, RP
What is your biggest issue right now?
Labor
What effects are we seeing?
Higher Costs – wages & benefits
Unfilled positions
How are you going to grow?
Consider these questions
How many open positions do you currently
have, and how long have you been trying
to fill them?
How many MORE positions would you
need to fill to support your current growth
objectives?
Is that realistic? What do you do?
Automation
Robotics
Industry 4.0
Robotic Process Automation (RPA)
3D Printing
Additive Manufacturing
Smart Factories
The cost/benefit is changing …
Automation means connectivity
What does this mean for your security?
If your organization …
● Currently holds, bids, or reviews federal contract information;
● Has ever logged into the Procurement Integrated Enterprise
Environment (PIEE) or the Supplier Performance Risk System (SPRS);
● Produces specific materials for a government contract or for company
that currently holds, bids, or reviews government contracts;
● Plans to bid on government work at any point in the future; or
● Has a current or future need to review federal contract information
You have a CMMC requirement.
Overview
The “cybersecurity maturity model certification” is unifying
the implementation of cybersecurity across the Defense
Industrial Base (DIB).
Problems to solve
FCI
Federal Contract
Information
CUI
Controlled
Unclassified
Information
CMMC objective
The DoD is a policy creation organization.
Oversight is not their area of expertise.
An Independent Accreditation Body was
created to authorize and accredit 3rd party
assessors and practitioners.
Understanding the path
The foundation
The regulations and
frameworks to address
physical and electronic
controls for safeguarding
Covered Defense
Information and Cyber
Incident Reporting.
Federal Acquistion Regulation
52.204-21
Defense Federal Acquistion
Supplement 252.204-7012
NIST 800 -171
Methodical 5 year roll-out
2021
1,500 Certified
● 899@ML1
● 149@ML2
● 452@ML3
2022
7,500 Certified
● 44900@ML1
● 749@ML2
● 2245@ML3
● 8 @ML4 &5
2023
25,000 Certified
● 14981@ML1
● 2497@ML@
● 7,490 @ML#
● 16@ML4r & %
2024
47,905 Certified
Organizations Seeking Certification and
Recertification will be taking place
2025
47,905 Certified
New OSC and OSCs seeing recertification.
Rollout will allow for development of
practices and processes.
ML 1
99.9%
Majority of organizations will be
need to be at Maturity Levels 1-3.
ML 4
.1%
This will primarily be your Primary
Contractors.
ML 2 ML 3
ML 5
Basic Cyber
Hygiene
17 Practices
Intermediate
Hygiene
72 Practices
Good Cyber
Hygiene
130 Practices
Proactive
Cyber
156Practices
Progressive
Hygiene
17 1 Practices
Proposed solution
The Organization Seek Certification needs
to make Self-Assessment available, scope
their systems boundaries, and request
maturity level sought.
Process
0
1
Self Assessment
Conduct internal assessment or hire RPO to
conduct GAP Analysis
0
2
Close POAM
Plan of action milestones must be achieved
before Maturity Level Assessment
0
3
Hire C3PAO to Assess
C3PAO assigns Certified Assessor as Lead
Assessor. That Lead Assessor reviews
preparatory information and makes a
Go/no-go decision based on OE provided.
[ON-DEMAND RECORDING] Deep Impact: Is Your Manufacturing Company On A Collision Course With CMMC?

More Related Content

What's hot

Is a Data Processing Agreement Required?
Is a Data Processing Agreement Required?Is a Data Processing Agreement Required?
Is a Data Processing Agreement Required?Adam Stone
 
IT Due Diligence Overview
IT Due Diligence OverviewIT Due Diligence Overview
IT Due Diligence Overviewitduediligence
 
Is a Data Processing Agreement Required?
Is a Data Processing Agreement Required?Is a Data Processing Agreement Required?
Is a Data Processing Agreement Required?Adam Stone
 
AI in Insurance: How to Automate Insurance Claims Processing with Machine Lea...
AI in Insurance: How to Automate Insurance Claims Processing with Machine Lea...AI in Insurance: How to Automate Insurance Claims Processing with Machine Lea...
AI in Insurance: How to Automate Insurance Claims Processing with Machine Lea...Skyl.ai
 
International Business Registers Report 2018
International Business Registers Report 2018 International Business Registers Report 2018
International Business Registers Report 2018 Corporate Registers Forum
 
A Digital Rebirth for Life Insurance, Annuities and Pension Companies
A Digital Rebirth for Life Insurance, Annuities and Pension CompaniesA Digital Rebirth for Life Insurance, Annuities and Pension Companies
A Digital Rebirth for Life Insurance, Annuities and Pension CompaniesTata Consultancy Services
 
The Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureThe Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureAccenture Operations
 
Measuring the Impact of AI - TCS Global Trend Study
Measuring the Impact of AI - TCS Global Trend StudyMeasuring the Impact of AI - TCS Global Trend Study
Measuring the Impact of AI - TCS Global Trend StudyTata Consultancy Services
 
Trustpay-digital payment platform
Trustpay-digital payment platformTrustpay-digital payment platform
Trustpay-digital payment platformTRUSTpay
 
Greater IT efficiency through lean application development and maintenance fo...
Greater IT efficiency through lean application development and maintenance fo...Greater IT efficiency through lean application development and maintenance fo...
Greater IT efficiency through lean application development and maintenance fo...Mindtree Ltd.
 
Greater IT Efficiency - LEAN Application Development
Greater IT Efficiency - LEAN Application DevelopmentGreater IT Efficiency - LEAN Application Development
Greater IT Efficiency - LEAN Application DevelopmentAdrian Del Busso
 

What's hot (18)

Law Firm Payments Masterclass with LawPay
Law Firm Payments Masterclass with LawPayLaw Firm Payments Masterclass with LawPay
Law Firm Payments Masterclass with LawPay
 
The Future of Effective Governance
The Future of Effective GovernanceThe Future of Effective Governance
The Future of Effective Governance
 
Is a Data Processing Agreement Required?
Is a Data Processing Agreement Required?Is a Data Processing Agreement Required?
Is a Data Processing Agreement Required?
 
IT Due Diligence Overview
IT Due Diligence OverviewIT Due Diligence Overview
IT Due Diligence Overview
 
Is a Data Processing Agreement Required?
Is a Data Processing Agreement Required?Is a Data Processing Agreement Required?
Is a Data Processing Agreement Required?
 
How to Use Automation to Increase Efficiency at Your Law Firm
How to Use Automation to Increase Efficiency at Your Law FirmHow to Use Automation to Increase Efficiency at Your Law Firm
How to Use Automation to Increase Efficiency at Your Law Firm
 
AI in Insurance: How to Automate Insurance Claims Processing with Machine Lea...
AI in Insurance: How to Automate Insurance Claims Processing with Machine Lea...AI in Insurance: How to Automate Insurance Claims Processing with Machine Lea...
AI in Insurance: How to Automate Insurance Claims Processing with Machine Lea...
 
New Zealand - Data use and frameworks.
New Zealand - Data use and frameworks.New Zealand - Data use and frameworks.
New Zealand - Data use and frameworks.
 
Data Usage from Business Registries
Data Usage from Business RegistriesData Usage from Business Registries
Data Usage from Business Registries
 
International Business Registers Report 2018
International Business Registers Report 2018 International Business Registers Report 2018
International Business Registers Report 2018
 
A Digital Rebirth for Life Insurance, Annuities and Pension Companies
A Digital Rebirth for Life Insurance, Annuities and Pension CompaniesA Digital Rebirth for Life Insurance, Annuities and Pension Companies
A Digital Rebirth for Life Insurance, Annuities and Pension Companies
 
The Changing Role of Compliance | Accenture
The Changing Role of Compliance | AccentureThe Changing Role of Compliance | Accenture
The Changing Role of Compliance | Accenture
 
Improve your client intake process with Clio Grow
Improve your client intake process with Clio GrowImprove your client intake process with Clio Grow
Improve your client intake process with Clio Grow
 
Measuring the Impact of AI - TCS Global Trend Study
Measuring the Impact of AI - TCS Global Trend StudyMeasuring the Impact of AI - TCS Global Trend Study
Measuring the Impact of AI - TCS Global Trend Study
 
Trustpay-digital payment platform
Trustpay-digital payment platformTrustpay-digital payment platform
Trustpay-digital payment platform
 
Greater IT efficiency through lean application development and maintenance fo...
Greater IT efficiency through lean application development and maintenance fo...Greater IT efficiency through lean application development and maintenance fo...
Greater IT efficiency through lean application development and maintenance fo...
 
Greater IT Efficiency - LEAN Application Development
Greater IT Efficiency - LEAN Application DevelopmentGreater IT Efficiency - LEAN Application Development
Greater IT Efficiency - LEAN Application Development
 
Does cloud technology belong at your law firm?
Does cloud technology belong at your law firm?Does cloud technology belong at your law firm?
Does cloud technology belong at your law firm?
 

Similar to [ON-DEMAND RECORDING] Deep Impact: Is Your Manufacturing Company On A Collision Course With CMMC?

Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data DATAVERSITY
 
Ensur= let's get phygital
Ensur= let's get phygitalEnsur= let's get phygital
Ensur= let's get phygitalComarch
 
Get Ready for Syncsort's New Best-of-Breed Security Solution
Get Ready for Syncsort's New Best-of-Breed Security SolutionGet Ready for Syncsort's New Best-of-Breed Security Solution
Get Ready for Syncsort's New Best-of-Breed Security SolutionPrecisely
 
2016 Risk Management Workshop
2016 Risk Management Workshop2016 Risk Management Workshop
2016 Risk Management WorkshopStacy Willis
 
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...Rea & Associates
 
Information Security Program & PCI Compliance Planning for your Business
Information Security Program & PCI Compliance Planning for your BusinessInformation Security Program & PCI Compliance Planning for your Business
Information Security Program & PCI Compliance Planning for your BusinessLaura Perry
 
Vendor Management System - Introduction2
Vendor Management System - Introduction2Vendor Management System - Introduction2
Vendor Management System - Introduction2Frank Corris
 
Info Security & PCI(original)
Info Security & PCI(original)Info Security & PCI(original)
Info Security & PCI(original)NCTechSymposium
 
Outsourcing for Profit: Make investment work
Outsourcing for Profit: Make investment workOutsourcing for Profit: Make investment work
Outsourcing for Profit: Make investment workIndusNetMarketing
 
September 2023 State of Enterprise Tech Spending
September 2023 State of Enterprise Tech Spending September 2023 State of Enterprise Tech Spending
September 2023 State of Enterprise Tech Spending Battery Ventures
 
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance PostureEVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance PostureMichele Collu
 
lookingforwardwebinardeloitteworkdayanalyticsfinal-210524213844 (1).pdf
lookingforwardwebinardeloitteworkdayanalyticsfinal-210524213844 (1).pdflookingforwardwebinardeloitteworkdayanalyticsfinal-210524213844 (1).pdf
lookingforwardwebinardeloitteworkdayanalyticsfinal-210524213844 (1).pdfCharlesSantos684817
 
The CFO Guide to Data with Deloitte & Workday
The CFO Guide to Data with Deloitte & WorkdayThe CFO Guide to Data with Deloitte & Workday
The CFO Guide to Data with Deloitte & WorkdayWorkday, Inc.
 
Social Supply Chain and Sales Pipeline Bridge
Social Supply Chain and Sales Pipeline BridgeSocial Supply Chain and Sales Pipeline Bridge
Social Supply Chain and Sales Pipeline BridgeSteelwedge
 
Iot viewpoints. Ovum explores the IoT opportunity in 2018 and beyond
Iot viewpoints. Ovum explores the IoT opportunity in 2018 and beyondIot viewpoints. Ovum explores the IoT opportunity in 2018 and beyond
Iot viewpoints. Ovum explores the IoT opportunity in 2018 and beyondDigital Policy and Law Consulting
 
How to measure your cybersecurity performance
How to measure your cybersecurity performanceHow to measure your cybersecurity performance
How to measure your cybersecurity performanceAbhishek Sood
 
value and implications of master data management.pptx
value and implications of master data management.pptxvalue and implications of master data management.pptx
value and implications of master data management.pptxMuhammad Khalid
 

Similar to [ON-DEMAND RECORDING] Deep Impact: Is Your Manufacturing Company On A Collision Course With CMMC? (20)

Rethinking Trust in Data
Rethinking Trust in Data Rethinking Trust in Data
Rethinking Trust in Data
 
Ensur= let's get phygital
Ensur= let's get phygitalEnsur= let's get phygital
Ensur= let's get phygital
 
Get Ready for Syncsort's New Best-of-Breed Security Solution
Get Ready for Syncsort's New Best-of-Breed Security SolutionGet Ready for Syncsort's New Best-of-Breed Security Solution
Get Ready for Syncsort's New Best-of-Breed Security Solution
 
Digital Transformation in Insurance Operations
Digital Transformation in Insurance OperationsDigital Transformation in Insurance Operations
Digital Transformation in Insurance Operations
 
2016 Risk Management Workshop
2016 Risk Management Workshop2016 Risk Management Workshop
2016 Risk Management Workshop
 
Advance Degree vs. IT Certification
Advance Degree vs. IT Certification Advance Degree vs. IT Certification
Advance Degree vs. IT Certification
 
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...
EPISODE 1 | Security Wars: A New Goal: CMMC Compliance & Department of Defens...
 
Information Security Program & PCI Compliance Planning for your Business
Information Security Program & PCI Compliance Planning for your BusinessInformation Security Program & PCI Compliance Planning for your Business
Information Security Program & PCI Compliance Planning for your Business
 
CGI Final
CGI FinalCGI Final
CGI Final
 
Vendor Management System - Introduction2
Vendor Management System - Introduction2Vendor Management System - Introduction2
Vendor Management System - Introduction2
 
Info Security & PCI(original)
Info Security & PCI(original)Info Security & PCI(original)
Info Security & PCI(original)
 
Outsourcing for Profit: Make investment work
Outsourcing for Profit: Make investment workOutsourcing for Profit: Make investment work
Outsourcing for Profit: Make investment work
 
September 2023 State of Enterprise Tech Spending
September 2023 State of Enterprise Tech Spending September 2023 State of Enterprise Tech Spending
September 2023 State of Enterprise Tech Spending
 
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance PostureEVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
EVERFI/SEI Webinar: Implementing a Competitive GDPR Compliance Posture
 
lookingforwardwebinardeloitteworkdayanalyticsfinal-210524213844 (1).pdf
lookingforwardwebinardeloitteworkdayanalyticsfinal-210524213844 (1).pdflookingforwardwebinardeloitteworkdayanalyticsfinal-210524213844 (1).pdf
lookingforwardwebinardeloitteworkdayanalyticsfinal-210524213844 (1).pdf
 
The CFO Guide to Data with Deloitte & Workday
The CFO Guide to Data with Deloitte & WorkdayThe CFO Guide to Data with Deloitte & Workday
The CFO Guide to Data with Deloitte & Workday
 
Social Supply Chain and Sales Pipeline Bridge
Social Supply Chain and Sales Pipeline BridgeSocial Supply Chain and Sales Pipeline Bridge
Social Supply Chain and Sales Pipeline Bridge
 
Iot viewpoints. Ovum explores the IoT opportunity in 2018 and beyond
Iot viewpoints. Ovum explores the IoT opportunity in 2018 and beyondIot viewpoints. Ovum explores the IoT opportunity in 2018 and beyond
Iot viewpoints. Ovum explores the IoT opportunity in 2018 and beyond
 
How to measure your cybersecurity performance
How to measure your cybersecurity performanceHow to measure your cybersecurity performance
How to measure your cybersecurity performance
 
value and implications of master data management.pptx
value and implications of master data management.pptxvalue and implications of master data management.pptx
value and implications of master data management.pptx
 

More from Rea & Associates

2022 Rea & Associates' Cybersecurity Conference
2022 Rea & Associates' Cybersecurity Conference 2022 Rea & Associates' Cybersecurity Conference
2022 Rea & Associates' Cybersecurity Conference Rea & Associates
 
Rea & Associates' Manufacturing Day 2022
Rea & Associates' Manufacturing Day 2022Rea & Associates' Manufacturing Day 2022
Rea & Associates' Manufacturing Day 2022Rea & Associates
 
Rea & Associates - 4th Annual Construction Kickoff
Rea & Associates - 4th Annual Construction KickoffRea & Associates - 4th Annual Construction Kickoff
Rea & Associates - 4th Annual Construction KickoffRea & Associates
 
Rea Manufacturing Day 2021
Rea Manufacturing Day 2021Rea Manufacturing Day 2021
Rea Manufacturing Day 2021Rea & Associates
 
HR Compliance & Insurance Benefit Perspectives: What Employers Should Be Awar...
HR Compliance & Insurance Benefit Perspectives: What Employers Should Be Awar...HR Compliance & Insurance Benefit Perspectives: What Employers Should Be Awar...
HR Compliance & Insurance Benefit Perspectives: What Employers Should Be Awar...Rea & Associates
 
LIVE EVENT - 3rd Annual Fall Construction Risk Update - September 30
LIVE EVENT - 3rd Annual Fall Construction Risk Update - September 30LIVE EVENT - 3rd Annual Fall Construction Risk Update - September 30
LIVE EVENT - 3rd Annual Fall Construction Risk Update - September 30Rea & Associates
 
[ON-DEMAND WEBINAR] COVID 2.0 | Tips To Address New Cases, Mask Mandates, & V...
[ON-DEMAND WEBINAR] COVID 2.0 | Tips To Address New Cases, Mask Mandates, & V...[ON-DEMAND WEBINAR] COVID 2.0 | Tips To Address New Cases, Mask Mandates, & V...
[ON-DEMAND WEBINAR] COVID 2.0 | Tips To Address New Cases, Mask Mandates, & V...Rea & Associates
 
[ON-DEMAND WEBINAR] Revealing The State & Local Tax Considerations Of A Remot...
[ON-DEMAND WEBINAR] Revealing The State & Local Tax Considerations Of A Remot...[ON-DEMAND WEBINAR] Revealing The State & Local Tax Considerations Of A Remot...
[ON-DEMAND WEBINAR] Revealing The State & Local Tax Considerations Of A Remot...Rea & Associates
 
[ON-DEMAND WEBINAR] How To Hire More Employees & Keep Them Happy: Tips To Att...
[ON-DEMAND WEBINAR] How To Hire More Employees & Keep Them Happy: Tips To Att...[ON-DEMAND WEBINAR] How To Hire More Employees & Keep Them Happy: Tips To Att...
[ON-DEMAND WEBINAR] How To Hire More Employees & Keep Them Happy: Tips To Att...Rea & Associates
 
[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...
[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...
[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...Rea & Associates
 
[ON-DEMAND WEBINAR] CPA Pros Prepare For The 2020 Medicaid School Program (MSP)
[ON-DEMAND WEBINAR] CPA Pros Prepare For The 2020 Medicaid School Program (MSP)[ON-DEMAND WEBINAR] CPA Pros Prepare For The 2020 Medicaid School Program (MSP)
[ON-DEMAND WEBINAR] CPA Pros Prepare For The 2020 Medicaid School Program (MSP)Rea & Associates
 
[ON-DEMAND WEBINAR] Security Wars: Episode 2 | CMMC: Return of The Process Fo...
[ON-DEMAND WEBINAR] Security Wars: Episode 2 | CMMC: Return of The Process Fo...[ON-DEMAND WEBINAR] Security Wars: Episode 2 | CMMC: Return of The Process Fo...
[ON-DEMAND WEBINAR] Security Wars: Episode 2 | CMMC: Return of The Process Fo...Rea & Associates
 
[ON-DEMAND WEBINAR] Construction Companies: Manage Cyber Risk Exposure & Prev...
[ON-DEMAND WEBINAR] Construction Companies: Manage Cyber Risk Exposure & Prev...[ON-DEMAND WEBINAR] Construction Companies: Manage Cyber Risk Exposure & Prev...
[ON-DEMAND WEBINAR] Construction Companies: Manage Cyber Risk Exposure & Prev...Rea & Associates
 
[ON-DEMAND WEBINAR] Covid Vaccine & HIPAA: Can Employers To Receive The COVID...
[ON-DEMAND WEBINAR] Covid Vaccine & HIPAA: Can Employers To Receive The COVID...[ON-DEMAND WEBINAR] Covid Vaccine & HIPAA: Can Employers To Receive The COVID...
[ON-DEMAND WEBINAR] Covid Vaccine & HIPAA: Can Employers To Receive The COVID...Rea & Associates
 
[ON-DEMAND RECORDING] Managing Remote Employees, HR Policies, Sales Tax, & Ot...
[ON-DEMAND RECORDING] Managing Remote Employees, HR Policies, Sales Tax, & Ot...[ON-DEMAND RECORDING] Managing Remote Employees, HR Policies, Sales Tax, & Ot...
[ON-DEMAND RECORDING] Managing Remote Employees, HR Policies, Sales Tax, & Ot...Rea & Associates
 
[ON-DEMAND WEBINAR] Understanding SOC2: A SOC 2 Guide for Managed Service Pro...
[ON-DEMAND WEBINAR] Understanding SOC2: A SOC 2 Guide for Managed Service Pro...[ON-DEMAND WEBINAR] Understanding SOC2: A SOC 2 Guide for Managed Service Pro...
[ON-DEMAND WEBINAR] Understanding SOC2: A SOC 2 Guide for Managed Service Pro...Rea & Associates
 
[ON-DEMAND WEBINAR] Third Annual Construction Industry Kickoff | Rea & Associ...
[ON-DEMAND WEBINAR] Third Annual Construction Industry Kickoff | Rea & Associ...[ON-DEMAND WEBINAR] Third Annual Construction Industry Kickoff | Rea & Associ...
[ON-DEMAND WEBINAR] Third Annual Construction Industry Kickoff | Rea & Associ...Rea & Associates
 
[ON-DEMAND WEBINAR] New Year, New COVID 19 Vaccine, New Unemployment Rules, N...
[ON-DEMAND WEBINAR] New Year, New COVID 19 Vaccine, New Unemployment Rules, N...[ON-DEMAND WEBINAR] New Year, New COVID 19 Vaccine, New Unemployment Rules, N...
[ON-DEMAND WEBINAR] New Year, New COVID 19 Vaccine, New Unemployment Rules, N...Rea & Associates
 
[ON-DEMAND WEBINAR] Next Steps In COVID 19 Protocols & Compliance
[ON-DEMAND WEBINAR] Next Steps In COVID 19 Protocols & Compliance[ON-DEMAND WEBINAR] Next Steps In COVID 19 Protocols & Compliance
[ON-DEMAND WEBINAR] Next Steps In COVID 19 Protocols & ComplianceRea & Associates
 
[ON-DEMAND WEBINAR] Social Security v. Medicare: Addressing Your Most Asked Q...
[ON-DEMAND WEBINAR] Social Security v. Medicare: Addressing Your Most Asked Q...[ON-DEMAND WEBINAR] Social Security v. Medicare: Addressing Your Most Asked Q...
[ON-DEMAND WEBINAR] Social Security v. Medicare: Addressing Your Most Asked Q...Rea & Associates
 

More from Rea & Associates (20)

2022 Rea & Associates' Cybersecurity Conference
2022 Rea & Associates' Cybersecurity Conference 2022 Rea & Associates' Cybersecurity Conference
2022 Rea & Associates' Cybersecurity Conference
 
Rea & Associates' Manufacturing Day 2022
Rea & Associates' Manufacturing Day 2022Rea & Associates' Manufacturing Day 2022
Rea & Associates' Manufacturing Day 2022
 
Rea & Associates - 4th Annual Construction Kickoff
Rea & Associates - 4th Annual Construction KickoffRea & Associates - 4th Annual Construction Kickoff
Rea & Associates - 4th Annual Construction Kickoff
 
Rea Manufacturing Day 2021
Rea Manufacturing Day 2021Rea Manufacturing Day 2021
Rea Manufacturing Day 2021
 
HR Compliance & Insurance Benefit Perspectives: What Employers Should Be Awar...
HR Compliance & Insurance Benefit Perspectives: What Employers Should Be Awar...HR Compliance & Insurance Benefit Perspectives: What Employers Should Be Awar...
HR Compliance & Insurance Benefit Perspectives: What Employers Should Be Awar...
 
LIVE EVENT - 3rd Annual Fall Construction Risk Update - September 30
LIVE EVENT - 3rd Annual Fall Construction Risk Update - September 30LIVE EVENT - 3rd Annual Fall Construction Risk Update - September 30
LIVE EVENT - 3rd Annual Fall Construction Risk Update - September 30
 
[ON-DEMAND WEBINAR] COVID 2.0 | Tips To Address New Cases, Mask Mandates, & V...
[ON-DEMAND WEBINAR] COVID 2.0 | Tips To Address New Cases, Mask Mandates, & V...[ON-DEMAND WEBINAR] COVID 2.0 | Tips To Address New Cases, Mask Mandates, & V...
[ON-DEMAND WEBINAR] COVID 2.0 | Tips To Address New Cases, Mask Mandates, & V...
 
[ON-DEMAND WEBINAR] Revealing The State & Local Tax Considerations Of A Remot...
[ON-DEMAND WEBINAR] Revealing The State & Local Tax Considerations Of A Remot...[ON-DEMAND WEBINAR] Revealing The State & Local Tax Considerations Of A Remot...
[ON-DEMAND WEBINAR] Revealing The State & Local Tax Considerations Of A Remot...
 
[ON-DEMAND WEBINAR] How To Hire More Employees & Keep Them Happy: Tips To Att...
[ON-DEMAND WEBINAR] How To Hire More Employees & Keep Them Happy: Tips To Att...[ON-DEMAND WEBINAR] How To Hire More Employees & Keep Them Happy: Tips To Att...
[ON-DEMAND WEBINAR] How To Hire More Employees & Keep Them Happy: Tips To Att...
 
[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...
[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...
[ON-DEMAND WEBINAR] Managed Service Providers vs Managed Security Service Pro...
 
[ON-DEMAND WEBINAR] CPA Pros Prepare For The 2020 Medicaid School Program (MSP)
[ON-DEMAND WEBINAR] CPA Pros Prepare For The 2020 Medicaid School Program (MSP)[ON-DEMAND WEBINAR] CPA Pros Prepare For The 2020 Medicaid School Program (MSP)
[ON-DEMAND WEBINAR] CPA Pros Prepare For The 2020 Medicaid School Program (MSP)
 
[ON-DEMAND WEBINAR] Security Wars: Episode 2 | CMMC: Return of The Process Fo...
[ON-DEMAND WEBINAR] Security Wars: Episode 2 | CMMC: Return of The Process Fo...[ON-DEMAND WEBINAR] Security Wars: Episode 2 | CMMC: Return of The Process Fo...
[ON-DEMAND WEBINAR] Security Wars: Episode 2 | CMMC: Return of The Process Fo...
 
[ON-DEMAND WEBINAR] Construction Companies: Manage Cyber Risk Exposure & Prev...
[ON-DEMAND WEBINAR] Construction Companies: Manage Cyber Risk Exposure & Prev...[ON-DEMAND WEBINAR] Construction Companies: Manage Cyber Risk Exposure & Prev...
[ON-DEMAND WEBINAR] Construction Companies: Manage Cyber Risk Exposure & Prev...
 
[ON-DEMAND WEBINAR] Covid Vaccine & HIPAA: Can Employers To Receive The COVID...
[ON-DEMAND WEBINAR] Covid Vaccine & HIPAA: Can Employers To Receive The COVID...[ON-DEMAND WEBINAR] Covid Vaccine & HIPAA: Can Employers To Receive The COVID...
[ON-DEMAND WEBINAR] Covid Vaccine & HIPAA: Can Employers To Receive The COVID...
 
[ON-DEMAND RECORDING] Managing Remote Employees, HR Policies, Sales Tax, & Ot...
[ON-DEMAND RECORDING] Managing Remote Employees, HR Policies, Sales Tax, & Ot...[ON-DEMAND RECORDING] Managing Remote Employees, HR Policies, Sales Tax, & Ot...
[ON-DEMAND RECORDING] Managing Remote Employees, HR Policies, Sales Tax, & Ot...
 
[ON-DEMAND WEBINAR] Understanding SOC2: A SOC 2 Guide for Managed Service Pro...
[ON-DEMAND WEBINAR] Understanding SOC2: A SOC 2 Guide for Managed Service Pro...[ON-DEMAND WEBINAR] Understanding SOC2: A SOC 2 Guide for Managed Service Pro...
[ON-DEMAND WEBINAR] Understanding SOC2: A SOC 2 Guide for Managed Service Pro...
 
[ON-DEMAND WEBINAR] Third Annual Construction Industry Kickoff | Rea & Associ...
[ON-DEMAND WEBINAR] Third Annual Construction Industry Kickoff | Rea & Associ...[ON-DEMAND WEBINAR] Third Annual Construction Industry Kickoff | Rea & Associ...
[ON-DEMAND WEBINAR] Third Annual Construction Industry Kickoff | Rea & Associ...
 
[ON-DEMAND WEBINAR] New Year, New COVID 19 Vaccine, New Unemployment Rules, N...
[ON-DEMAND WEBINAR] New Year, New COVID 19 Vaccine, New Unemployment Rules, N...[ON-DEMAND WEBINAR] New Year, New COVID 19 Vaccine, New Unemployment Rules, N...
[ON-DEMAND WEBINAR] New Year, New COVID 19 Vaccine, New Unemployment Rules, N...
 
[ON-DEMAND WEBINAR] Next Steps In COVID 19 Protocols & Compliance
[ON-DEMAND WEBINAR] Next Steps In COVID 19 Protocols & Compliance[ON-DEMAND WEBINAR] Next Steps In COVID 19 Protocols & Compliance
[ON-DEMAND WEBINAR] Next Steps In COVID 19 Protocols & Compliance
 
[ON-DEMAND WEBINAR] Social Security v. Medicare: Addressing Your Most Asked Q...
[ON-DEMAND WEBINAR] Social Security v. Medicare: Addressing Your Most Asked Q...[ON-DEMAND WEBINAR] Social Security v. Medicare: Addressing Your Most Asked Q...
[ON-DEMAND WEBINAR] Social Security v. Medicare: Addressing Your Most Asked Q...
 

Recently uploaded

Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...lizamodels9
 
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckPitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckHajeJanKamps
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...lizamodels9
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailAriel592675
 
Call Girls In ⇛⇛Chhatarpur⇚⇚. Brings Offer Delhi Contact Us 8377877756
Call Girls In ⇛⇛Chhatarpur⇚⇚. Brings Offer Delhi Contact Us 8377877756Call Girls In ⇛⇛Chhatarpur⇚⇚. Brings Offer Delhi Contact Us 8377877756
Call Girls In ⇛⇛Chhatarpur⇚⇚. Brings Offer Delhi Contact Us 8377877756dollysharma2066
 
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / NcrCall Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncrdollysharma2066
 
Call Girls In Kishangarh Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delh...
Call Girls In Kishangarh Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delh...Call Girls In Kishangarh Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delh...
Call Girls In Kishangarh Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delh...lizamodels9
 
Marketing Management Business Plan_My Sweet Creations
Marketing Management Business Plan_My Sweet CreationsMarketing Management Business Plan_My Sweet Creations
Marketing Management Business Plan_My Sweet Creationsnakalysalcedo61
 
BEST Call Girls In BELLMONT HOTEL ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In BELLMONT HOTEL ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In BELLMONT HOTEL ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In BELLMONT HOTEL ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation SlidesKeppelCorporation
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | DelhiFULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | DelhiMalviyaNagarCallGirl
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,noida100girls
 
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdfCatalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdfOrient Homes
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis UsageNeil Kimberley
 
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCRsoniya singh
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Serviceankitnayak356677
 

Recently uploaded (20)

Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
Call Girls In Radisson Blu Hotel New Delhi Paschim Vihar ❤️8860477959 Escorts...
 
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deckPitch Deck Teardown: NOQX's $200k Pre-seed deck
Pitch Deck Teardown: NOQX's $200k Pre-seed deck
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
Lowrate Call Girls In Sector 18 Noida ❤️8860477959 Escorts 100% Genuine Servi...
 
Case study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detailCase study on tata clothing brand zudio in detail
Case study on tata clothing brand zudio in detail
 
Best Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting PartnershipBest Practices for Implementing an External Recruiting Partnership
Best Practices for Implementing an External Recruiting Partnership
 
Call Girls In ⇛⇛Chhatarpur⇚⇚. Brings Offer Delhi Contact Us 8377877756
Call Girls In ⇛⇛Chhatarpur⇚⇚. Brings Offer Delhi Contact Us 8377877756Call Girls In ⇛⇛Chhatarpur⇚⇚. Brings Offer Delhi Contact Us 8377877756
Call Girls In ⇛⇛Chhatarpur⇚⇚. Brings Offer Delhi Contact Us 8377877756
 
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / NcrCall Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
Call Girls in DELHI Cantt, ( Call Me )-8377877756-Female Escort- In Delhi / Ncr
 
Call Girls In Kishangarh Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delh...
Call Girls In Kishangarh Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delh...Call Girls In Kishangarh Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delh...
Call Girls In Kishangarh Delhi ❤️8860477959 Good Looking Escorts In 24/7 Delh...
 
Marketing Management Business Plan_My Sweet Creations
Marketing Management Business Plan_My Sweet CreationsMarketing Management Business Plan_My Sweet Creations
Marketing Management Business Plan_My Sweet Creations
 
BEST Call Girls In BELLMONT HOTEL ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In BELLMONT HOTEL ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In BELLMONT HOTEL ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In BELLMONT HOTEL ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
Keppel Ltd. 1Q 2024 Business Update  Presentation SlidesKeppel Ltd. 1Q 2024 Business Update  Presentation Slides
Keppel Ltd. 1Q 2024 Business Update Presentation Slides
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | DelhiFULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
FULL ENJOY - 9953040155 Call Girls in Chhatarpur | Delhi
 
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
BEST Call Girls In Greater Noida ✨ 9773824855 ✨ Escorts Service In Delhi Ncr,
 
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdfCatalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
 
2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage2024 Numerator Consumer Study of Cannabis Usage
2024 Numerator Consumer Study of Cannabis Usage
 
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
(8264348440) 🔝 Call Girls In Keshav Puram 🔝 Delhi NCR
 
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts ServiceVip Female Escorts Noida 9711199171 Greater Noida Escorts Service
Vip Female Escorts Noida 9711199171 Greater Noida Escorts Service
 

[ON-DEMAND RECORDING] Deep Impact: Is Your Manufacturing Company On A Collision Course With CMMC?

  • 1.
  • 2. Presenters 01 | Senior Manager, Rea & Associates – Millersburg, Ohio 02 | 8+ years of Manufacturing experience 03 | Consulting – Product Costing, Profitability, Inventory, & Operations 04 | Tax Planning and Advisory 05 | Rea Manufacturing & Distribution ● Andrew Geiser, CPA
  • 3. Presenters 01 | Sr. InformationAssurance Manager, Rea & Associates 02 | 10+ years of Information Technology experience 03 | Consulting – CMMC, Governance| Risk | Compliance 04 | FBI InfraGard Member 05 | Rea Cyberservices Division ● Tyrone Whittenburg, RP
  • 4. What is your biggest issue right now? Labor What effects are we seeing? Higher Costs – wages & benefits Unfilled positions
  • 5. How are you going to grow? Consider these questions How many open positions do you currently have, and how long have you been trying to fill them? How many MORE positions would you need to fill to support your current growth objectives? Is that realistic? What do you do?
  • 6. Automation Robotics Industry 4.0 Robotic Process Automation (RPA) 3D Printing Additive Manufacturing Smart Factories The cost/benefit is changing …
  • 7. Automation means connectivity What does this mean for your security?
  • 8.
  • 9. If your organization … ● Currently holds, bids, or reviews federal contract information; ● Has ever logged into the Procurement Integrated Enterprise Environment (PIEE) or the Supplier Performance Risk System (SPRS); ● Produces specific materials for a government contract or for company that currently holds, bids, or reviews government contracts; ● Plans to bid on government work at any point in the future; or ● Has a current or future need to review federal contract information You have a CMMC requirement.
  • 10. Overview The “cybersecurity maturity model certification” is unifying the implementation of cybersecurity across the Defense Industrial Base (DIB).
  • 14. CMMC objective The DoD is a policy creation organization. Oversight is not their area of expertise. An Independent Accreditation Body was created to authorize and accredit 3rd party assessors and practitioners.
  • 16. The foundation The regulations and frameworks to address physical and electronic controls for safeguarding Covered Defense Information and Cyber Incident Reporting. Federal Acquistion Regulation 52.204-21 Defense Federal Acquistion Supplement 252.204-7012 NIST 800 -171
  • 17. Methodical 5 year roll-out 2021 1,500 Certified ● 899@ML1 ● 149@ML2 ● 452@ML3 2022 7,500 Certified ● 44900@ML1 ● 749@ML2 ● 2245@ML3 ● 8 @ML4 &5 2023 25,000 Certified ● 14981@ML1 ● 2497@ML@ ● 7,490 @ML# ● 16@ML4r & % 2024 47,905 Certified Organizations Seeking Certification and Recertification will be taking place 2025 47,905 Certified New OSC and OSCs seeing recertification.
  • 18. Rollout will allow for development of practices and processes. ML 1 99.9% Majority of organizations will be need to be at Maturity Levels 1-3. ML 4 .1% This will primarily be your Primary Contractors. ML 2 ML 3 ML 5 Basic Cyber Hygiene 17 Practices Intermediate Hygiene 72 Practices Good Cyber Hygiene 130 Practices Proactive Cyber 156Practices Progressive Hygiene 17 1 Practices
  • 19. Proposed solution The Organization Seek Certification needs to make Self-Assessment available, scope their systems boundaries, and request maturity level sought.
  • 20. Process 0 1 Self Assessment Conduct internal assessment or hire RPO to conduct GAP Analysis 0 2 Close POAM Plan of action milestones must be achieved before Maturity Level Assessment 0 3 Hire C3PAO to Assess C3PAO assigns Certified Assessor as Lead Assessor. That Lead Assessor reviews preparatory information and makes a Go/no-go decision based on OE provided.

Editor's Notes

  1. Defending the information & intellectual property of the DoD is getting increasingly harder and Self-Assessments were not effective. The CMMC is intended to serve as a verification mechanism to ensure that companies implement the appropriate measures.
  2. Federal Contract Information: Information not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public Web sites) or simple transactional information, such as necessary to process payments. Maturity Level 1 focuses purely on safeguarding this information.
  3. Unclassified information associated with a law, regulation, or government-wide policy and identified as needing safeguarding is considered CUI • DoD CUI replaces all references to CDI • Authorized holder is responsible for determining whether information in a document or material falls into a CUI category, and applying CUI markings and dissemination instructions accordingly • At minimum, CUI markings for DoD CUI documents will include the acronym “CUI” in the banner and footer of the document (FOUO not valid for new documents)
  4. FAR 52.204-21 established 17 baseline controls that orgs (contractors) need to achieve to conduct business with the govt. The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls: Here’s a portion of the controls. (i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems). (ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute. (iii) Verify and control/limit connections to and use of external information systems. (DoD) issued an interim rule on Sept. 29, 2020 to amend the Defense Federal Acquisition Regulation Supplement (DFARS) to implement the Cybersecurity Maturity Model Certification (CMMC) framework. This interim rule includes new DFARS clause 252.204-7021, which specifies CMMC requirements and enables the department to verify. DFARS interim rule became effective on November 30, 2020. The public review and comment period for DFARS Case 2019-D041 ended on November 30, 2020. Due to its designation as a major rule change, the interim rule must also complete a Congressional Review. Unlike NIST SP 800-171, the CMMC model possesses five levels. The model is cumulative whereby each level consists of practices and processes as well as those specified in the lower levels. The CMMC Model includes additional cybersecurity practices in addition to the security requirements specified in NIST SP 800-171.
  5. • Engaging C3PAO ○ OSC registers with CMMC-AB ○ OSC requests CMMC Cert, and timing ○ CMMC-AB puts OSC in contact with available C3PAO's § Those who need Cert are prioritized(provisional) • Selecting C3PAO ○ Select ○ Make available read-ahead info to incd: § Pre/Self-TAssessment results § Scope Boundaries § Recent Certification results (e.g. ISO, Etc) § Maturity Level sought ○ C3PAO assigns Certified Assessor as Lead Assessor ○ Lead Assessor rvws info ○ Go/no-go decision is rendered based on info provided ○ Assuming GO decision § Lead assessor and OSC determine/confirm scope □ Staffing □ Dates/duration □ pricing
  6. Each practice must be satisfied based on at least 2 forms of objective evidence. Interviews Evidence review (preferred is demonstration) Testing Findings are categorized as Pass – addresses CMMC practice Fail – a failure to address some aspect of CMMC req Not Applicable