Talk to an Expert →
Blog · December 17, 2019

Cybersecurity Maturity Model Certification (CMMC) Version 0.7 Arrives!

The Cybersecurity Maturity Model Certification (CMMC) Draft Version 0.7 is live and available here.

Version 0.7 includes Level 4-5 practices and modifies some maturity processes and Level 1-3 practices.

This draft is another step closer to the final version — CMMC 1.0.

The CMMC will be a new contractual requirement for all DoD contractors.  The new certification requirement is intended to push defense contractors to strengthen their cybersecurity programs and standards. It will not be a self-attestation model, but rather a third-party certification and compliance model.

More in-depth analysis of the 190-page document will follow.

Clarifications –

In addition to CMMC Version 0.7, the DoD has released the following clarification:

See the “Updates” tab of the CMMC website.

Timeline –

Draft Version 0.4 was released for public comment in September 2019.

Draft Version 0.6 was released on Friday, November 8, 2019.

Draft Version 0.7, dated December 6, 2019, was posted on the CMMC website on December 13, 2019.

Version 1.0 of the CMMC framework is expected to be available in January 2020. In June 2020, industry should begin to see the CMMC requirements as part of Requests for Information.

More Information –

For more information on the Cybersecurity Maturity Model Certification program, the latest draft, and news on the formation of a CMMC Accreditation Body, visit the DoD’s official CMMC website.

 

 

 

CREDIT: Colleen H. Johnson, Sera-Brynn

See the enclave in action.

The Compliant Computing Enclave keeps CUI inside one boundary, with your endpoints out of scope and the evidence trail already built.

Talk to an Expert →
Keep reading

More from the blog

September 29, 2026

Week 9: Cost and Performance Compound the Risk

Why GCC High cost and limitations matter Last week, we examined Microsoft’s broader security record and...

Read it →

September 22, 2026

Week 8: Microsoft’s Broader Security Record

Why Microsoft security culture matters Last week, we examined support boundaries, personnel access, and why secure...

Read it →

September 16, 2026

Week 7: China-Based Support and the Support Boundary

Why the GCC High support boundary matters Last week, we discussed the “too embedded to reject”...

Read it →