Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Impact Of Coronavirus Pandemic On CMMC Implementation Efforts
Articles

The Impact Of Coronavirus Pandemic On CMMC Implementation Efforts

ISBuzz TeamBy ISBuzz TeamMay 29, 2020Updated:July 4, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
chthonic trojan
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The coronavirus pandemic has unexpectedly affected all aspects of life, including businesses, schools, events, and even social factors. In line with government directives for less travel, social distancing, and stay at home, companies have encouraged their workers to telework to reduce the spread of COVID-19. Compellingly, governments will reorder budgeting to fund the healthcare sector adequately. In effect, the unforeseen measures will have implications on CMMC implementation efforts.  

What is CMMC 

CMMC is a combination of an array of cybersecurity standards and best practices mapped across multiple maturity levels ranging from cyber hygiene to advanced. In this case, each CMMC level comprises of processes and controls that enable organizations to minimize risk against a set of cyber threats. With different levels, it becomes affordable and straightforward for small businesses to implement CMMC. On the other hand, third-parties leverage the model to conduct audits and inform risk in organizations.  

The CMMC effort is built upon existing DFARS 252.201-7012 based on trust by adding a verification aspect for cybersecurity requirements. Stakeholders integrate CMMC into the Defense Federal Acquisition Regulation Supplement (DFARS) and apply it as part of stipulations in the procurement process and contract award. The DoD specifies the required CMMC level in requests for information (RFIs) and requests for proposals (RFPs).  

COVID-19 May Affect CMMC Implementation  

DoD, accreditation body, third-party assessors, and contractors need to prepare for the implementation of the CMMC certification. However, the current coronavirus pandemic will adversely impact such efforts in the following ways:    

1. Cancellation of CMMC Training Events   

As the Department of Defense strives to stay as close to schedule as possible while implementing CMMC, the current circumstance will affect CMMC training events. In particular, the concerned parties will cancel, postpone, or virtualize training to reduce physical contacts to prevent the spread of COVID-19.  

Katie Arrington, the Chief Information Security Officer for DoD acquisition, stated that the department had slated training of third-party assessors for the CMMC program. Fortunately, the original intent of DoD was to have a fraction of the training online using germane technologies.  

2. Reduced In-Person Visits by Third-Party Assessors  

DoD CMMC certification is a requirement for thousands of DoD contractors who will work with third-party assessors to verification of implemented security practices. The process, in some measure, involves an in-person visit from the assessors to examine the cybersecurity posture and establish that firms seeking certification are authentic companies with real employees. 

However, unless the current situation improves, people will continue experiencing restricted movement as countries gain time to implement effective preparedness measures rapidly. In theory, never leaving home during the coronavirus pandemic is an effective means of prevention that reduces the change of infection. COVID-19 will adversely affect the in-person visits necessary for the CMMC audit process since assessors will not be eager to travel to handle the work at in-scope locations.  

3. Scarcity of Resources  

COVID-19 pandemic will certainly cause DoD’s budget to shrink as the disease compels the government to shift the focus to the healthcare sector. The furiously spreading coronavirus will ultimately trigger a realignment of the U.S. national priorities, which will impact on the DoD’s efforts to implement CMMC certification.  

4. Disintegrated Work from Home Strategies  

CMMC certification process requires covered entities to inventory all systems that collect, store, and process FCI CUI. Secondly, the implementation involves conducting a gap assessment of current cybersecurity controls relative to the model to determine remediation activities and improvements to achieve the desired certification level. Besides, a covered entity should document cybersecurity policies, formalize security controls in procedural documentation, and assemble all documents in preparation for the certification. 

Today, COVID-19 has increased the number of employees working from home. This practice complicates CMMC preparedness, including readiness and documentation. It is challenging to inventory all devices collecting and storing CUI and FCI. Additionally, it is difficult for organizations to document and assemble all cybersecurity documentation while handling in-office and remote teams.  

In a Nutshell  

CMMC remains a priority to DoD. The government continues to collaborate with industry partners and the accreditation body to meet the certification timelines, despite the current pandemic’s impacts. Nevertheless, the CMMC implementation progress will face canceled, postponed, and virtualized training events as well as reduced in-person visits by assessors, constrained resources, and work from home strategies. CMMC implementation process might take place behind schedule as stakeholders will miss valuable interim training and third-party assessors’ identification processes.  

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

June 2, 20263 Mins Read

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read

Artificial intelligence and elections: When an election is annulled because of TikTok

June 1, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}