<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<REGINFO_RIN_DATA xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" RUN_DATE="2026-04-04-04:00" xsi:noNamespaceSchemaLocation="https://www.reginfo.gov/public/xml/REGINFO_XML_Ver10262011.xsd">
    <RIN_INFO>
        <RIN>0750-AK81</RIN>
        <PUBLICATION>
            <PUBLICATION_ID>202210</PUBLICATION_ID>
            <PUBLICATION_TITLE>The Regulatory Plan and the Unified Agenda of Federal Regulatory and Deregulatory Actions</PUBLICATION_TITLE>
        </PUBLICATION>
        <AGENCY>
            <CODE>0750</CODE>
            <NAME>Defense Acquisition Regulations Council</NAME>
            <ACRONYM>DARC</ACRONYM>
        </AGENCY>
        <PARENT_AGENCY>
            <CODE>0700</CODE>
            <NAME>Department of Defense</NAME>
            <ACRONYM>DOD</ACRONYM>
        </PARENT_AGENCY>
        <RULE_TITLE>Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)</RULE_TITLE>
        <ABSTRACT><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>DoD is amending an interim rule to implement the CMMC framework 2.0&nbsp;in order to protect against the theft of intellectual property and sensitive information from the Defense Industrial Base (DIB) sector. The CMMC framework is a&nbsp;DoD certification process that measures a company&rsquo;s institutionalization of processes and implementation of cybersecurity practices. This rule&nbsp;provides the Department with assurances that a DIB contractor can adequately protect sensitive unclassified information at a level commensurate with the risk, accounting for information flow down to its subcontractors in a multi-tier supply chain.</p>
</body>
</html>]]></ABSTRACT>
        <PRIORITY_CATEGORY>Economically Significant</PRIORITY_CATEGORY>
        <RIN_STATUS>Previously Published in The Unified Agenda</RIN_STATUS>
        <RULE_STAGE>Proposed Rule Stage</RULE_STAGE>
        <MAJOR>Yes</MAJOR>
        <UNFUNDED_MANDATE_LIST>
            <UNFUNDED_MANDATE>No</UNFUNDED_MANDATE>
        </UNFUNDED_MANDATE_LIST>
        <CFR_LIST>
            <CFR>48 CFR 204</CFR>
            <CFR>48 CFR 212</CFR>
            <CFR>48 CFR 217</CFR>
            <CFR>48 CFR 252</CFR>
        </CFR_LIST>
        <LEGAL_AUTHORITY_LIST>
            <LEGAL_AUTHORITY>41 U.S.C. 1303</LEGAL_AUTHORITY>
            <LEGAL_AUTHORITY>Pub. L. 116-92, sec. 1648</LEGAL_AUTHORITY>
        </LEGAL_AUTHORITY_LIST>
        <LEGAL_DLINE_LIST/>
        <RPLAN_ENTRY>Yes</RPLAN_ENTRY>
        <RPLAN_INFO>
            <STMT_OF_NEED><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The purpose of this DFARS rule is to ensure&nbsp;that Defense Industrial Base (DIB) contractors will adequately protect sensitive unclassified information at a level commensurate with the risk, accounting for information flow down to its subcontractors in a multi-tier supply chain.</p>
</body>
</html>]]></STMT_OF_NEED>
            <LEGAL_BASIS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>This rule is being implemented under the authority of 41 U.S.C. 1303 and section 1648 of the National Defense Authorization Act for Fiscal Year (FY) 2020 (Pub. L. 116-92).&nbsp; The USD (A&amp;S) has the authority and responsibility for promulgating DoD procurement rules under the OFPP statute, codified at title 41 of the U.S. Code. Section 1648 of the National Defense Authorization Act for Fiscal Year 2020 (Pub. L. 116-92) directs the Secretary of Defense to develop a risk-based cybersecurity framework for the DIB sector, such as CMMC, as the basis for a mandatory DoD standard.&nbsp;</p>
</body>
</html>]]></LEGAL_BASIS>
            <ALTERNATIVES><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p class="GPOHtml">DoD considered and adopted several alternatives during the development of the interim rule that reduced the burden on small entities and still meet the objectives of the rule. DoD will consider similar alternatives for the amendment rule. These alternatives include: (1) exempting contracts and orders exclusively for the acquisition of commercially available off-the-shelf items; and (2) implementing a phased rollout and stipulating that the inclusion a CMMC requirement in new contracts until that time be approved by the Office of the Under Secretary of Defense for Acquisition and Sustainment.</p>
</body>
</html>]]></ALTERNATIVES>
            <COSTS_AND_BENEFITS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The annualized value of costs beginning in fiscal year 2021 (calculated in perpetuity in 2016 dollars at a 7 percent discount rate) associated with implementing the CMMC Framework in the interim is $4 billion. The primary benefit of this rule is improving the protection of the Department's sensitive information and reducing the threat&nbsp;to DIB sector intellectual property&nbsp;by:</p>
<ul>
<li>Enabling assessments at the entity-level of contractor implementation of cyber security processes and practices that should already be in place;</li>
<li>Requiring comprehensive implementation of cybersecurity requirements rather than plans of action to accomplish implementation;</li>
<li>Verifying&nbsp;DIB sector contractor and subcontractor cybersecurity postures; and&nbsp;&nbsp;</li>
<li>Reducing duplicative or repetitive assessments of our industry partners through standardization.</li>
</ul>
<p>&nbsp;&nbsp;</p>
</body>
</html>]]></COSTS_AND_BENEFITS>
            <RISKS><![CDATA[<!DOCTYPE html>
<html>
<head>
</head>
<body>
<p>The theft of intellectual property and sensitive information from all U.S. industrial sectors due to malicious cyber activity threatens economic security and national security.&nbsp; Malicious cyber actors have and continue to target the DIB sector and the supply chain of the Department of Defense. These attacks not only focus on the large prime contractors, but also target subcontractors that make up the lower tiers of the DoD supply chain. Many of these subcontractors are small entities that provide critical support and innovation. The aggregate loss of intellectual property and certain unclassified information from the DoD supply chain can undercut U.S. technical advantages and innovation, as well as significantly increase risk to national security.</p>
</body>
</html>]]></RISKS>
        </RPLAN_INFO>
        <TIMETABLE_LIST>
            <TIMETABLE>
                <TTBL_ACTION>Interim Final Rule</TTBL_ACTION>
                <TTBL_DATE>09/29/2020</TTBL_DATE>
                <FR_CITATION>85 FR 48513</FR_CITATION>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>Interim Final Rule Effective</TTBL_ACTION>
                <TTBL_DATE>11/30/2020</TTBL_DATE>
            </TIMETABLE>
            <TIMETABLE>
                <TTBL_ACTION>NPRM</TTBL_ACTION>
                <TTBL_DATE>05/00/2023</TTBL_DATE>
            </TIMETABLE>
        </TIMETABLE_LIST>
        <RFA_REQUIRED>Yes</RFA_REQUIRED>
        <SMALL_ENTITY_LIST>
            <SMALL_ENTITY>Businesses</SMALL_ENTITY>
        </SMALL_ENTITY_LIST>
        <GOVT_LEVEL_LIST>
            <GOVT_LEVEL>Federal</GOVT_LEVEL>
        </GOVT_LEVEL_LIST>
        <FEDERALISM>No</FEDERALISM>
        <ENERGY_AFFECTED>No</ENERGY_AFFECTED>
        <COMPLIANCE_COST>
            <INITIAL_PUBLIC_COST>0</INITIAL_PUBLIC_COST>
            <BASE_YEAR>2021</BASE_YEAR>
            <RECURRING_PUBLIC_COST>0</RECURRING_PUBLIC_COST>
        </COMPLIANCE_COST>
        <PRINT_PAPER>Yes</PRINT_PAPER>
        <INTERNATIONAL_INTEREST>No</INTERNATIONAL_INTEREST>
        <RELATED_RIN_LIST>
            <RELATED_RIN>
                <RIN>0750-AL68</RIN>
                <RIN_RELATION>Split from</RIN_RELATION>
            </RELATED_RIN>
            <RELATED_RIN>
                <RIN>0790-AL49</RIN>
                <RIN_RELATION>Related to</RIN_RELATION>
            </RELATED_RIN>
        </RELATED_RIN_LIST>
        <AGENCY_CONTACT_LIST>
            <CONTACT>
                <FIRST_NAME>Jennifer</FIRST_NAME>
                <LAST_NAME>Johnson</LAST_NAME>
                <MIDDLE_NAME>D.</MIDDLE_NAME>
                <TITLE>Office of the Under Secretary of Defense for Acquisition and Sustainment</TITLE>
                <AGENCY>
                    <CODE>0750</CODE>
                    <NAME>Defense Acquisition Regulations Council</NAME>
                    <ACRONYM>DARC</ACRONYM>
                </AGENCY>
                <PHONE>703 717-8226</PHONE>
                <EMAIL>jennifer.d.johnson1.civ@mail.mil</EMAIL>
                <MAILING_ADDRESS>
                    <STREET_ADDRESS>Defense Pricing, Contracting, &amp; Acquisition Policy, Defense Acquisition Regulations System, Room 3B938, 3060 Pentagon,</STREET_ADDRESS>
                    <CITY>Washington</CITY>
                    <STATE>DC</STATE>
                    <ZIP>20301-3060</ZIP>
                </MAILING_ADDRESS>
            </CONTACT>
        </AGENCY_CONTACT_LIST>
    </RIN_INFO>
</REGINFO_RIN_DATA>
