Seclight partner Peter Gisseman is acknowledged CMMC Registerd Practitioner (RP) to advise and assist companies certifying to comply with US information security requirements in place 2025.
The accreditation body The Cyber AB has appointed Peter Gisseman from the Swedish IT security consultancy Seclight in the role of Registered Practitioner of Cybersecurity Maturity Model Certification (CMMC).
Suppliers, part of the defence industrial base (DIB) have agreed to comply with the requirements and know what applies.
”They are experts and know this like the back of their hand”, says Peter Gisseman.
Now also subcontractors are subject to certification, including third parties such as IT consultants and service providers.
“Down the supply chain, the level of knowledge may vary”, says Peter Gisseman.
A promise may not be enough. CMMC calls for verification of compliance. In Sweden, the ISO/IEC 27001 standard is well known and IT professionals are aware of the System and Organization Controls type 2 (SOC 2) including third parties.
“Understanding your dependencies is an important step”, says Peter Gisseman.
Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing compliance with standards published by the authority National Institute of Standards and Technology, well known in Sweden for its IT security framework NIST Cyber Security Framework. In May 2024, NIST released a new version, r3, of the NIST SP 800-171 requirements for parties handling so-called controlled unclassified information, controlled unclassified information (CUI) and federal contract information (FCI).
Now subcontractors are also covered. The certification will be a prerequisite for bids in procurements. CMMC incorporates supposedly affordable controls for small businesses to implement at lower certification levels.
Rules apply to access, processing and storage of CUI and FCI in all companies of importance to the defense in a broader sense, what is known as the Defense Industrial Base (DIB) and in the US also includes the Treasury Department, the Department of Justice, the Department of Energy, the FBI and Homeland Security.
CMMC is developed by and operated under the supervision of the US Department of Defense. The certifications are carried out by the independent and non-profit fee-financed organization The Cybersecurity Maturity Model Certification Accreditation Body, The Cyber AB.
After a review by Congress, the Department of Defense is expected to decide on rules during 2024. The rules can then come into force within 60 days.
The role of Registered Practitioner (RP) involves assisting with experience and CMMC training in implementation and compliance. As a consultant, an RP can identify gaps, propose applications and delimitations, lay out strategy and roadmap and implement security controls when a company prepares for assessment and certification. Previously, there are RP from Denmark, Norway and the Netherlands. Defense cooperation between the USA and Sweden has increased since Sweden became a member of NATO in March 2024 and it is only now that Swedish citizens are entitled to become RP.
Seclight – keeping you bright and safe.
Contact: David Hässler +46 8 94 55 99 david.hassler@seclight.com
