The Department of Defense (DoD) released for comment a proposed rule setting guidelines for implementation of the Cybersecurity Maturity Model Certification (CMMC) program.

The proposal, published Tuesday, would “establish requirements for a comprehensive and scalable assessment mechanism to ensure defense contractors and subcontractors have … implemented required security measures” under the CMMC, which applies to federal contract information and controlled unclassified information.