Talk to an Expert
Blog · December 17, 2019

Cybersecurity Maturity Model Certification (CMMC) Version 0.7 Arrives!

The Cybersecurity Maturity Model Certification (CMMC) Draft Version 0.7 is live and available here.

Version 0.7 includes Level 4-5 practices and modifies some maturity processes and Level 1-3 practices.

This draft is another step closer to the final version — CMMC 1.0.

The CMMC will be a new contractual requirement for all DoD contractors.  The new certification requirement is intended to push defense contractors to strengthen their cybersecurity programs and standards. It will not be a self-attestation model, but rather a third-party certification and compliance model.

More in-depth analysis of the 190-page document will follow.

Clarifications –

In addition to CMMC Version 0.7, the DoD has released the following clarification:

See the “Updates” tab of the CMMC website.

Timeline –

Draft Version 0.4 was released for public comment in September 2019.

Draft Version 0.6 was released on Friday, November 8, 2019.

Draft Version 0.7, dated December 6, 2019, was posted on the CMMC website on December 13, 2019.

Version 1.0 of the CMMC framework is expected to be available in January 2020. In June 2020, industry should begin to see the CMMC requirements as part of Requests for Information.

More Information –

For more information on the Cybersecurity Maturity Model Certification program, the latest draft, and news on the formation of a CMMC Accreditation Body, visit the DoD’s official CMMC website.

 

 

 

CREDIT: Colleen H. Johnson, Sera-Brynn

See the enclave in action.

The Compliant Computing Enclave keeps CUI inside one boundary, with your endpoints out of scope and the evidence trail already built.

Talk to an Expert
Keep reading

More from the blog

September 3, 2026

Week 6: Too Embedded to Reject

How GCC High vendor lock-in changes the decision Last week, we examined the assessor problem. This...

Read it →

August 26, 2026

Week 5: FedRAMP’s Assessor Problem

Why FedRAMP assessor independence matters Last week, we examined the larger architecture problem. This week, we...

Read it →

August 20, 2026

Week 4: The Problem Did Not Stop with Encryption

Why GCC High security architecture matters Last week, we focused on the encryption question. This week,...

Read it →