New member
I have heard of CMMC, but I don't quite understand how it relates to NIST, or even DFARS for that matter. Are they all the same thing? When will the audits start?


Staff member
In January 2020, the DoD will roll out version 1.0 of the CMMC framework, and will integrate CMMC requirements into RFP's (Request For Proposals) in June 2020. CMMC stands for Cybersecurity Maturity Model Certification. CMMC will eventually replace NIST 800-53/800-171 and DFARS requirements. The CMMC is a culmination of the best practices gleaned from each, and lays the framework for DoD vendors to become more secure, and less prone to data breach.
