Cybersecurity Maturity Model Matures: DoD Adds New Requirements to Draft Cybersecurity Certification
Client Alert | 1 min read | 09.10.19
The Defense Department has released Revision 0.4 of its Cybersecurity Maturity Model Certification (CMMC) that, starting next year, independent auditors are to use to certify contractor compliance with DoD cybersecurity requirements. Revision 0.4 more than doubles the number of cybersecurity controls across the CMMC’s five maturity “Levels.” But the DoD emphasizes that it will further down-select these controls and that mature contractor processes may counteract gaps in the final controls’ implementation. In addition to NIST SP 800-171 (the default standard under DFARS 252.204-7012), Revision 0.4 now incorporates requirements from the NIST Cybersecurity Framework, ISO 27001, and CIS Critical Security Controls, as well as from “additional DIB inputs.” Notably missing is NIST SP 800-171B, which remains under review.
The DoD is requesting feedback on Revision 0.4 through September 25, 2019, and plans on releasing Revision 0.6 for comment in November 2019. The final CMMC is expected in January 2020.
Contacts

Partner, Crowell Global Advisors Senior Director
- Washington, D.C.
- D | +1.202.624.2698
- Washington, D.C. (CGA)
- D | +1 202.624.2500
Insights
Client Alert | 2 min read | 12.19.25
GAO Cautions Agencies—Over-Redact at Your Own Peril
Bid protest practitioners in recent years have witnessed agencies’ increasing efforts to limit the production of documents and information in response to Government Accountability Office (GAO) bid protests—often will little pushback from GAO. This practice has underscored the notable difference in the scope of bid protest records before GAO versus the Court of Federal Claims. However, in Tiger Natural Gas, Inc., B-423744, Dec. 10, 2025, 2025 CPD ¶ __, GAO made clear that there are limits to the scope of redactions, and GAO will sustain a protest where there is insufficient evidence that the agency’s actions were reasonable.
Client Alert | 7 min read | 12.19.25
In Bid to Ban “Woke AI,” White House Imposes Transparency Requirements on Contractors
Client Alert | 5 min read | 12.19.25
Navigating California’s Evolving Microplastics Landscape in 2026
Client Alert | 19 min read | 12.18.25
2025 GAO Bid Protest Annual Report: Where Have All the Protests Gone?

