top of page
letter head header.jpg

Notice of Upcoming Cybersecurity Maturity Model Certification (CMMC) Requirements
 

Dear Valued Subcontractor,

 

This letter serves as notice of upcoming cybersecurity compliance requirements affecting KMK Construction, Inc. (KMK) and its Subcontractors.

 

In 2016, the U.S. Government established regulations requiring contractors and subcontractors participating in the Defense Industrial Base (DIB) to implement cybersecurity controls, primarily under Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 and the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171.

 

In recent years, the U.S. Government identified significant gaps in the DIB’s implementation of these requirements. To enforce compliance, the Department of Defense, in partnership with The Cyber AB, is finalizing the Cybersecurity Maturity Model Certification (CMMC) program. The final rule is being issued under Title 32 of the Code of Federal Regulations (CFR) and is anticipated to be published in mid-2025. Once effective, CMMC requirements will appear in Department of Defense solicitations and contracts, flowing down to subcontractors at all tiers.

 

KMK and its Subcontractors will be subject to these CMMC requirements. KMK is committed to assisting our Subcontractors through this transition. We recommend the following actions be undertaken:

 

  1. Engage a CMMC consultant, compliance advisor, or Managed Service Provider (MSP), as needed. KMK can recommend reputable partners upon request.

  2. Designate a CMMC Compliance Lead within your company. This individual should consider pursuing The Cyber AB’s Registered Practitioner (RP) and/or Certified CMMC Professional (CCP) certifications, becoming an internal compliance champion.

  3. Register in the System for Award Management (SAM.gov) and the Procurement Integrated Enterprise Environment (PIEE) and perform a NIST SP 800-171 self-assessment within the Supplier Performance Risk System (SPRS).

  4. Continue implementing and maturing NIST SP 800-171 controls, closing any identified gaps, and preparing for a CMMC assessment.

  5. Engage in CMMC training opportunities, including webinars, seminars, and resources provided by The Cyber AB, DoD, and industry groups.
     

For your convenience, the following page provides helpful links and resources to assist with CMMC preparation.

 

Thank you,

 

Tyler Phillips

Vice President of Contracts & IT

Helpful Resources and Links for CMMC Preparation

 

1. Official CMMC Resources
 

 

2. NIST SP 800-171 Resources
 

 

3. Registration Platforms and Self-Assessment Platforms
 

 

4. Additional Guidance and Tools
 

KMK Logo _ White.png

© 1996 by KMK Construction, Inc. All rights reserved.

MAINE

384 Harold L. Dow Hwy,

Suite 14,

Eliot, ME 03903

(207) 439-3569

​

​FLORIDA

1395 Chaffee Rd. S.

Suite 2,

Jacksonville, FL 32221

(904) 204-0692

Service-Disabled Veteran-Owned-Certified.jpg
bottom of page