
The episode discusses GSA's updated cybersecurity requirements for contractors handling Controlled Unclassified Information and the differences from DoD's CMMC program.
GSA recently updated its cybersecurity requirements for contractors handling Controlled Unclassified Information (CUI). While similar in concept to DoD’s CMMC program, GSA’s approach is based on NIST SP 800-171 Revision 3, while CMMC currently relies on Revision 2. This difference could force contractors that work with both agencies to meet two separate cybersecurity standards. Industry experts warn that this may create a fragmented compliance environment across federal agencies and inc...
Explore listener stats, chart rankings, contacts and more on the CMMC Academy podcast page.