Rose Ketchum’s Post

View profile for Rose Ketchum, graphic

VP of Client Engagement for Semel Consulting - Your trusted compliance expert helping you to secure your business since 1980. CMMC - DFARS - HIPAA - NIST

CMMC Final Rule Published: What This Means for MSPs The CMMC Final Rule has been pre-published in the U.S. Federal Register, with official publication on October 15. This update brings a critical change for MSPs supporting defense contractors. The original proposal required MSPs to pass a Level 2 or 3 CMMC assessment at the same level as their clients, or the clients would fail. But the final rule changes that: If an MSP (or any External Service Provider) does not process, store, or transmit Controlled Unclassified Information (CUI), they will not need their own CMMC assessment. Instead, their services will be assessed as part of the defense contractor's certification. What this means for MSPs: If you or your vendors aren't handling CUI, you're not on the hook for a costly Level 2 assessment. Mike will share more once he has had time to dive into the full 470-page document, but feel free to reach out with any immediate questions.

  • No alternative text description for this image

To view or add a comment, sign in

Explore topics