CMMC2.0/CPCSC
Shipbuilders within the USA Defense Industrial Base (USA-DIB) and Canadian Defence Industrial Base (CDA-DIB) will soon be required to hold a new cybersecurity certification as part of their contractual arrangements. While the CMMC 2.0 regime is now officially on the books, Canadian suppliers continue to wait for the formal requirements communicated through ITSP 10.171, a “Canadianized” version of NIST SP 800-171 Revision 3.
Given that Winter 2025 is upon the Canadian supplier base, it is likely a good time for those running the CPCSC program to begin releasing official details regarding those requirements. The current guidance has the requirements being written into certain RFPs beginning in Winter 2025, which we are now entering.
With companies expected to achieve Level 1 by June 2025, the time may run short for those publishing the requirements to solicit feedback while leaving organizations enough time to meet their certification requirements.
The Association will monitor this and other regimes as they enter force across the shipbuilding industry.