WASHINGTON – Today, global tech trade association 91¿ì»îÁÖ welcomed the U.S. Department of Defense’s (DoD) final rule on implementing the Cybersecurity Maturity Model Certification (CMMC) program in DoD contracts. The final rule incorporates much of the tech industry’s feedback, including previous recommendations 91¿ì»îÁÖ has proposed.
“91¿ì»îÁÖ supports efforts to strengthen the cybersecurity posture across the Defense Industrial Base. We appreciate DoD’s commitment to addressing stakeholder feedback and the recommendations that it received as part of the previous public comment periods,” said 91¿ì»îÁÖ Executive Vice President of Public Sector Policy Gordon Bitko. “Regulatory reciprocity is not just a policy preference; it is a strategic necessity for advancing both security and efficiency across the federal cyber landscape. The decision to eliminate the duplicative incident reporting requirement prevents further fragmentation of the regulatory landscape. We encourage DoD to leverage industry’s expertise and continue making progress on harmonization efforts, including securing mutual recognition of CMMC certifications across federal regimes.”