News
Insight

Swede takes on new US requirements

Seclight's Peter Gisseman has been appointed as an advisor to strengthen information security in the supply chain to the US defence sector. New requirements could affect many companies in Sweden in 2025.

The US accreditation body The Cyber AB has appointed Peter Gisseman from the Swedish IT security company Seclight to the role of official practitioner, Registered Practitioner, under the CMMC certification model for suppliers of significance to the US defence sector.

Peter may be the first Swede to become a Registered Practitioner. Now suppliers in Sweden also need to get certified. All direct suppliers have long since agreed contractually to meet the requirements and are familiar with what applies.

— They're experts, and they know this inside out, says Peter Gisseman.

During 2025, third parties such as IT consultants and service providers may also become subject to the requirements. The aim is to secure the supply chain, with control over third parties.

— Further down the supply chain, the level of knowledge isn't always the same, says Peter Gisseman.

And promises are no longer enough. During 2025, suppliers and subcontractors will likely need to prove they meet the requirements by holding a valid CMMC certification.

— The US really wants to verify and demonstrate compliance, says Peter Gisseman, comparing it to audits against other frameworks with controls and processes, such as System and Organization Controls, a so-called SOC 2 report.

— Getting a handle on your third-party dependencies and making them aware of the certification requirement is going to be important, says Peter Gisseman.

Cybersecurity Maturity Model Certification (CMMC) is a framework for assessing compliance with standards published by the National Institute of Standards and Technology, familiar in Sweden through the NIST Cybersecurity Framework. In May 2024, NIST released a new version, r3, of the NIST SP 800-171 requirements for parties who, in the course of developing or delivering something, gain access to information that must not be made public and whose distribution may need to be controlled — so-called Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

The certification will become a prerequisite for submitting bids in procurements and for delivering products and services to the US defence sector. Even smaller companies should be able to achieve certification, depending on the information involved and the role the supplier plays, regardless of size.

The requirements can apply to any company of relevance to defence in a broader sense, what's known as the Defense Industrial Base (DIB). The purpose is to protect different levels of access, processing and storage of that information against cyber attacks.

CMMC is developed by, and operates under the oversight of, the US Department of Defense. Certifications are carried out by the independent, non-profit, fee-funded organisation The Cybersecurity Maturity Model Certification Accreditation Body, The Cyber AB.

Following a review by Congress, the Department of Defense is expected to decide on supplier certification rules during 2024. The rules could then take effect within 60 days.

The Registered Practitioner (RP) role involves helping companies apply their experience and specialised CMMC training to meet the requirements. As a consultant, an RP can identify gaps, propose applications and scoping decisions, lay out a strategy, and help implement protections that meet the requirements as a company prepares for assessment and certification. RPs already exist from Denmark, Norway and the Netherlands. Defence cooperation between the US and Sweden has increased since Sweden joined NATO in March 2024, and it is only now that Swedish citizens are able to become RPs.


Seclight — keeping you bright and safe.

Contact: David Hässler +46 8 94 55 99 david.hassler@seclight.com