deprecationObservedPublished: 13h ago

DOD CIO Davies highlights need to address operational technology under CMMC program

DOD CIO Kirsten Davies discussed feedback from a July 13 request for information on potential changes to the Cybersecurity Maturity Model Certification program, in a Sept. 9 appearance at the Billington Cybersecurity Summit where she weighed in how operational technology can be incorporated into the initiative, which focuses on controlled unclassified information. “Let me be clear: Cybersecurity is of utmost importance not only inside the building [at the Pentagon] but also across our government's industrial base,” Davies said at the summit . The decision to pause implementation of CMMC level two “isn't about whether cybersecurity is important or not,” Davies said. “It is. It's critical. It's vital, especially with the frontier AI models and defending against attacks that are at speed, at scale, [more than] we've never seen before.” The pause was put in place because DOD “wanted to hear more from the defense industrial base on what was important for meaningful, dynamic cybersecurity,” according to Davies. Davies announced on July 13 the pause on implementing CMMC level two, which was set to begin on Nov. 10 and would have added in a third-party assessment requirement to defense contract solicitations. Davies stood up a CMMC Reform Task Force made up of DOD officials and released a July 13 RFI to get feedback on specific areas to inform their work. The CMMC Reform Task Force convened for three days last week to go over the RFI comments. Davies said DOD received over 1,100 comments and is in the process of reviewing them. Davies highlighted one of her takeaways: “Manufacturers, operational technology is so critical right now, and nowhere in the CMMC was there even the mention around how to build cyber resilience for a manufacturing line.” CMMC is focused on protecting controlled unclassified information on nonfederal systems. Davies emphasized, “But the handling of federal data doesn't necessarily build cyber resilience for small and medium manufacturing companies.” Over 50 percent of the comments are in favor of the pause, Davies said based on the RFI results, and are “seeking some level of reform.” She added, “A lot of this has been very, very positive.” DOD received negative feedback asking why the DOD started the review and if they were prepared to do it, Davies said, noting that a lot of this feedback came for the “third-party assessor base” who asked how DOD will “prove that the defense industrial base is following federal policies.” In response, Davies said the answer is “still something that we need to resolve for.” Davies also addressed efforts to reform the DOD Risk Management Framework. First, Davies said the Pentagon has “identified over 60 percent of the policies, doctrines, and mandates that were ridiculous and can literally just be removed. That's happening right now.” The second part is looking at the actual process for software companies and others who want to “get approval for a particular piece of software,” Davies said. That process can take six to 12 months, Davies said, but with artificial intelligence, Davies said it can be shortened to 17 seconds. Davies said DOD wants to be asking the “right questions,” such as “demanding the right documentation from software companies that is the output of a 17 second process [that can] actually reduce the risk.” The Billington session came nearly a week after DOD issued a class deviation to update Part 240 of the Defense Federal Acquisition Regulation Supplement. Part 240 is focused on “Information Security and Supply Chain Security” and includes the CMMC acquisition regulation finalized in 2024. When Davies announced the CMMC level two pause, Davies and Michael Duffey, Under Secretary of Defense for Acquisition and Sustainment, sent out memos providing instructions for the military services and defense agencies. The class deviation formalizes the level two suspension as an intermediate step. DOD is looking at opportunities to revamp DFARS, in line with other Trump administration efforts on the civilian agency side to streamline acquisition rules through the rulemaking process. -- Sara Friedman (sfriedman@iwpnews.com) Article Type: Daily News Sara Friedman tags: CMMC Weight: -20

Download social card
Copy launch post

Why this byte is shareable

Signal quality

observed

Confidence badge and source context included.

Entity anchor

AI News

Clear company or model context for distribution.

Export ready

1200 x 630 card

Optimized for X, LinkedIn, and chat previews.

Why it matters

Deprecations can break production agents quickly. Teams should audit dependencies and ship migration patches before cutoffs.

Suggested launch post

Use this in X threads, community posts, internal team chats, or launch recaps.

DOD CIO Davies highlights need to address operational technology under CMMC program

Why it matters: Deprecations can break production agents quickly. Teams should audit dependencies and ship migration patches before cutoffs.

Source: Insidecybersecurity
https://a2zai.ai/bytes...
Post to X
Copy text

Permalink: https://a2zai.ai/bytes/dod-cio-davies-highlights-need-to-address-operational-technology-under-cmmc-prog-3015677a

Social card: https://a2zai.ai/bytes/dod-cio-davies-highlights-need-to-address-operational-technology-under-cmmc-prog-3015677a/opengraph-image

Social and community

Discussion