Sponsored by Bertin Exensor
www.exensor.com
——————————————————————————————————————————————————————————————————————————————————————————————————————————
17 Oct 24. DOD Simplifies Process for Defense Contractors to Comply With Cybersecurity Rules.
The Defense Department on Friday released for public inspection the final cybersecurity maturity model certification program rule. The rule includes changes which make it simpler for private sector companies to comply with the cybersecurity requirements which must be in place before they can bid on defense contracts.
The department’s cybersecurity maturity model certification program, also called CMMC, ensures that private sector companies doing work for the Defense Department as part of the defense industrial base demonstrate that their computer networks and cybersecurity practices are up to the task of defending against intrusions by adversaries who may want access to information about government contracts and weapons systems development.
According to defense officials, the defense industrial base in the United States is the target of recurrent and progressively sophisticated cyberattacks, targeting the controlled unclassified information and federal contract information which is processed, stored or transmitted on nonfederal unclassified information systems. Those attacks threaten both the department mission and national security.
A big change in the new CMMC rule, which is included in Title 32 of the Code of Federal Regulations — a section dedicated to national defense — is a simplification of the assessment levels that were previously within the CMMC program. The new rule reduces the number of levels from five to just three.
“The decrease from five levels to three levels is part of the streamlining effort that we did as we went from the original program to the one that we just released,” said Buddy Dees, director of the CMMC program management office.
The CMMC program asks private sector companies who do business with or hope to do business with the department to demonstrate compliance with cybersecurity requirements described in both the Federal Acquisition Regulation and publications from the National Institute of Standards and Technology.
Previously, the DOD’s CMMC program included five levels of compliance, where levels two and four were designed specifically to help companies make transitions between the other levels.
“As part of the streamlining, we got rid of the transition levels,” said Dees.
Now, Dees said, there are only three levels of compliance.
Within CMMC, he said, level one compliance asks contractors to self-assess their ability to provide basic protection of federal contract information. At level two, which deals with general protection of controlled unclassified information, companies will either self-assess or seek assessment by a CMMC third-party assessment organization depending on the nature of the information they will be expected to process.
For level three, the highest level, compliance requires companies to demonstrate an ability to protect higher levels of controlled unclassified information. Certification at this level must be completed with an assessment by DOD’s own Defense Industrial Base Cybersecurity Assessment Center.
The CMMC has also been simplified in other ways to make it easier for private companies to demonstrate cybersecurity compliance and become eligible to contribute to national security, Dees said.
Under the original program, for instance, Dees said the department wasn’t just interested in if companies in the defense industrial base met cybersecurity requirements. It was also interested in the processes used by defense industrial base companies to achieve compliance and if those processes were repeatable.
“When we went from the original to the current CMMC, we decided to get eliminate the assessment of that process piece, and we’re strictly going to focus on assessing the cybersecurity requirements,” he said.
An additional set of requirements were also removed from CMMC which DOD had put in place but were not aligned with the cybersecurity standards outlined by NIST.
“We also included twenty cybersecurity requirements that were not previously required under NIST,” Dees said. “When we went from the transition to the new one … the decision was we’re going to align ourselves directly with the NIST cybersecurity standards. And so, we got rid of those twenty … ‘CMMC-unique requirements.’ We deleted them as part of that move from the original program to the revised program.”
Development of CMMC has been underway, in various forms, for more than five years. Original plans for implementing CMMC, however, proved cumbersome and caused concern within the defense industrial base, especially within medium-sized and small companies which might not have the resources of larger, more established defense contractors.
“There was indication from small and medium businesses that it was going to be very difficult for them to achieve this,” said Stacy Bostjanick, chief of defense industrial base cybersecurity.
With feedback from the business community a decision was made to look at how the CMMC, as originally planned, could be made simpler and less expensive for businesses, while still ensuring national security, she said.
“The new administration … made the determination that we needed to relook the program and ensure that we were doing what it intended to do and not being overly arduous and onerous on the DIB community,” Bostjanick said. “We wanted to ensure that we continued to have the support and participation of the industrial base.”
The government, she said, put a “strategic pause” on the CMMC that had been developed, so that it could be re-evaluated.
The new CMMC is expected to be better accepted by the defense industrial base, while at the same time it ensures national security, she said.
“CMMC will protect our intellectual property and our innovation,” she said. “We continuously have our data taken by advanced persistent threats. We have contractors that get targeted by malicious actors trying to extort money from them over the retention of their data, and that puts our men and women in service on the battlefield at risk, because they are impeding our ability to ensure that they have the best and highest capability weapons in their hands.”
Through CMMC, Bostjanick said, the department will ensure that weapons systems developed by the defense industrial base, in partnership with the Defense Department, will stay in the hands of America’s warfighters and allies only — and not end up in the hands of adversaries.
The CMMC 32 Code of Federal Regulations final rule, about 450 pages long, describes the CMMC program in detail. Now that the rule has been made public, it awaits approval by Congress, a process that will take 60 days.
Additionally, the CMMC 48 Code of Federal Regulations proposed rule, DFARS Clause 252.204-7021, completed public comment on Oct. 15. This rule must also be finalized and approved by Congress before the department can insert CMMC compliance requirements into defense contracts. It’s expected this won’t happen until early to mid-2025. (Source: U.S. DoD)
16 Oct 24. CNO Sets 80% Surge Readiness Goal by 2027. Chief of Naval Operations Adm. Lisa Franchetti today said that her goal of having 80% of the Navy’s ships and aircraft ready to surge on short notice by 2027 may seem ambitious, but that it will be worth all the progress that can be made in pursuit of that total percentage.
Franchetti, who recently delivered remarks on her just-released 2024 Navy navigation plan at a local Washington think tank, was asked afterward whether her relatively short-term 80% surge readiness goal was “aspirational, achievable both.”
“These are stretch goals, but I am confident we’re going to work hard to get after them,” Franchetti said of her plans to increase surge readiness.
“And if we don’t make exactly 80%,” she continued, “we’re going to be further along the road than we would be if I hadn’t set such an ambitious goal.”
Franchetti’s surge readiness goal falls under a portion of the Navigation Plan for America’s Warfighting Navy 2024 that targets seven areas the CNO sees as vital to fleet readiness.
Titled “Project 33” in reference to Franchetti being the Navy’s 33rd CNO, the seven core fleet readiness targets the plan seeks to address by 2027 are:
- Ready the force by eliminating ship, submarine and aircraft maintenance delays.
- Scale robotic and autonomous systems to integrate more platforms at speed.
- Create the command centers our fleets need to win on a distributed battlefield.
- Recruit and retain the force we need to get more players on the field.
- Deliver a quality of service commensurate with the sacrifices of our sailors.
- Train for combat as we plan to fight, in the real world and virtually.
- Restore the critical infrastructure that sustains and projects the fight from shore.
To illustrate her line of thinking as it relates to how she plans to reach the 80% surge readiness target by 2027, Franchetti gave the example of how the Navy was able to improve the readiness percentages for the F/A-18 Super Hornet in recent years.
“In 2018, Secretary Mattis challenged our aviation community to get F/A-18 readiness up from 50% readiness availability to 80%,” Franchetti said.
“And now, six years on,” she continued, “we’ve been able to sustain 80% readiness for the F/A-18s because of the processes we’ve put in place.”
Franchetti credited “data-driven, daily drumbeats of accountability” to make sure the Navy understood what the actual readiness levels of accountability for the F/A-18 were — as well as what the barriers were to achieving those proper levels — that led to the Navy successfully being able to sustain 80% readiness for the aircraft through 2024.
The Navy has since been able to scale those methods of upping readiness levels to the submarine force and surface force, Franchetti said.
“I am committed, and the team is committed to going after that stretch goal,” Franchetti said of the 80% surge readiness by 2027 target.
“We have all those processes in place now, and I’m really looking forward to that.”
Franchetti’s navigation plan focuses on 2027 as the year for the Navy to achieve maximized fleet readiness because that’s also the year China’s Xi Jinping has told his military to be ready for armed conflict.
“As the CNO who will be at the helm into 2027, I am compelled to do more — and do more, faster — to ensure that our Navy is more ready,” Franchetti said.
“I have a clock in my office that tells me there are 807 days left until 1 January 2027,” she added. “There is no time to waste, and your Navy is ready to get after it.” (Source: U.S. DoD)
11 Oct. 24. US Army Pacific to absorb new units under ‘transformation’ mantra. The U.S. Army command for the Indo-Pacific finds itself at the front of the service’s transformation initiative, incorporating new unit types created to facilitate rapid adaptation to adversary tactics, according to U.S. Army Pacific Command chief Gen. Charles Flynn.
Several units in the Pacific, from Hawaii to Alaska, were chosen as part of Army Chief of Staff Gen. Randy George’s initiative, dubbed “Transforming in Contact,” Flynn said in an interview ahead of the Association of the U.S. Army’s annual conference.
“But there’s a whole other transformation in contact that’s going on out here at the operational and theater level.”
That transformation has to do with absorbing new organizations and capabilities designed to facilitate the quick incorporation of new tactics and technologies in the field.
“In my view, that is where the connective tissue occurs between tactical forces and operational and strategic forces that exist in the joint world,” Flynn said.
For example, the Army in the Pacific is the first to get a Theater Information Advantage Detachment, Flynn said. The TIAD is meant to keep its finger on the pulse of how adversarial nations like China and Russia are conducting information warfare.
The service has deployed a Security Force Assistance Brigade, a Theater Fires Element and the TIAD into areas near China, Flynn added.
The Army has already created two of three Multidomain Task Forces in the Pacific theater, which have been heavily involved in exercises throughout 2024.
The service is planning to build five MDTFs total. Another is based in Europe, while one more will be based at Fort Liberty, North Carolina, and designed to align with global rapid responses.
The units will operate across all domains — land, air, sea, space and cyberspace — and are equipped with the Army’s growing capabilities, including long-range precision fires.
The MDTFs will take on game-changing capabilities like the Precision Strike Missile, or PrSM, the Mid-Range Capability missile system and the delayed Long-Range Hypersonic Weapon as part of a Long-Range Fires Battalion.
The Army in June fired two PrSM missiles in Palau as part of a ship sinking exercise during Valiant Shield. The service also deployed the MRC missile to the Philippines during the Balikatan exercise in May. The MRC missile system, for the time being, will remain in the Philippines, Flynn said.
The Pacific Army has also established a Theater Strike Effects Group, Flynn added. (Source: Defense News)
17 Oct 24. NRO Official Discusses Agency’s Focus on Maintaining U.S. Intelligence Edge. The National Reconnaissance Office remains focused on maintaining the United States’ intelligence advantage amid rapid technological advancements and evolving threats, a senior leader from the agency said today.
Troy Meink, NRO’s principal deputy director, said these forces, combined with growing stakeholder demands for real-time data, have created a generational change in how the agency innovates and deploys new technology to serve the warfighter and intelligence community partners.
“The NRO has always supported the needs of the warfighters in an operational environment. What’s new … is the rate of change, increasing complexity and the expanding set of information that we need to fuse and deliver quickly,” Meink said today during a Schriever Spacepower Series discussion hosted by the Mitchell Institute for Aerospace Studies in Arlington, Virginia.
“And that’s where our focus is: working across the whole-of-government to ensure that we do this efficiently and we deliver the capability to our customers,” he said. “In the end, the mission drives how we operate, and that’s where we are today.”
Established in the 1960’s, the NRO is tasked with acquiring, developing, launching and operating space-based intelligence capabilities in support of the U.S. intelligence community, the Defense Department and key allies throughout the globe.
Meink said today that, while NRO’s core mission remains the same, it now faces ever-increasing demands from stakeholders for rapid collection dissemination of critical information and increasing competition in the space domain.
“China and Russia continue to challenge our nation’s space advantage,” he said. “Each has developed and deployed counter-space capabilities that are designed to place U.S. satellites and ground capabilities at risk,” he said. “This includes on-orbit weapons systems but also ground-based weapons systems” in addition to cyber capabilities.
To stay ahead of the challenges, Meink said, the NRO remains focused on modernizing the United States’ Intelligence Surveillance and Reconnaissance capabilities and the supporting ground infrastructure used by warfighters and intelligence professionals.
He added that partnerships across the interagency and with private industry are key to rapidly innovating and meeting today’s demands.
The NRO has also focused extensively on its workforce, Meink said, in adapting to today’s challenges.
He noted, for instance, the growth of NRO’s internship program which now receives approximately 50 applicants per every intern hired.
“Success is directly related to talent,” he said, adding that attracting and maintaining “world class technical talent” is a primary focus among senior NRO officials. (Source: U.S. DoD)
17 Oct 24. Austin Highlights Key Lessons for Continued Success in Global Counterterrorism. Secretary of Defense Lloyd J. Austin III today highlighted three lessons that he views as key to ongoing success against global terrorism while speaking at NATO’s Ministerial of the force contributing members of the Global Coalition to Defeat ISIS, or D-ISIS, in Brussels.
“We meet here today to salute reflect on the tremendous sacrifices of this fight, and to ensure greater security and stability in the future,” Austin told those in attendance, then noting that the 87-country strong coalition has had great success against ISIS since its founding in 2014.
He said that continued success against ISIS — and continued successful global counterterrorist efforts, overall — will require vigilance and resoluteness regarding transnational terrorism; an ongoing collective response to terrorist aggression; and understanding the importance of adaptability.
“Today’s strategic environment is very different from that of 2014. ISIS remains focused on us. But the threat from ISIS and other terrorist groups is now one of several strategic priorities for us,” Austin said, while addressing the topic of vigilance and resoluteness.
“We’re tackling a range of key challenges, including bullying from the People’s Republic of China and Russia’s reckless invasion of Ukraine,” he continued. “But as we do so, we must not lose sight of the threat that ISIS still poses. So, this ministerial underscores our shared vigilance, and our shared resolve.”
Shifting next to the importance of nations working collectively to combat terrorist groups, Austin said that working together helps individual countries from draining their resources.
“If any one of us were to confront ISIS in every region of the globe, we could exhaust our resources — and our will. That would play into their hands,” he said.
“But our coalition has undermined their strategy to outlast us,” he continued. “Together, we’ve shared the responsibility for the territorial defeat of ISIS in Iraq and Syria. And together, we have the global presence and resources to confront ISIS wherever it may emerge.”
Austin then noted that the day’s discussions about West Africa and Central Asia would focus on the coalition’s efforts to counter key ISIS affiliates in those regions.
The secretary wound down his speech addressing the importance of adaptability, pointing out that the U.S. and Iraq recently announced the phased transition of Operation Inherent Resolve — D-ISIS’ military component — to a bilateral security relationship between the two countries.
“We’ll talk today about what that process means for the military mission and for our ongoing security partnership with Iraq,” Austin said.
“Our success stems from our resolve, our commitment to working together and our willingness to adapt,” he continued. “These core elements will remain at the heart of the next phase of our mission.”
In addition to the D-ISIS ministerial, Austin is also participating in engagements, through the end of the week, focused on strengthening NATO’s defense posture and enhancing military support for Ukraine.
He is then scheduled to attend the first-ever G7 Defense Ministers Meeting on Saturday in Naples, Italy. (Source: U.S. DoD)
16 Oct 24. Army Announces Effort to Help Small Business Meet. Cybersecurity Requirements. The Defense Department is actively working on plans to build cybersecurity requirements for the defense industrial base into defense contracts as part of its Cybersecurity Maturity Model Certification program, or CMMC. The first contracts with those requirements built in are expected sometime in 2025.
But for small businesses who might not have the resources to meet stringent cybersecurity requirements on their own, the Army is planning to launch a pilot program called the Next-Generation Commercial Operations in Defended Enclaves, or NCODE, said Undersecretary of the Army Gabe Camarillo, during a discussion Tuesday at the 2024 Association of the United States Army Annual Meeting and Exposition in Washington.
“This essentially provides a cyber-secure enclave in a secure environment for small businesses to participate in where they can collaborate, share information, most importantly, do their own work that they need to that would otherwise present a threat vector for actors that we know are very active in the cybersecurity space,” Camarillo said. “What’s great about it is it is compliant with CMMC, so all of the department’s requirements would be met by operating in this environment.”
Camarillo said many of the small businesses the Army worked with last year were at least partially at risk to cybersecurity threat vectors.
“Depending on how they’re capitalized and how many resources they have, their ability to overcome , despite our efforts across the department, can be very, very challenging,” he said. “So, we knew we had to do something.”
The Army is setting aside about $26 m in both fiscal year 2025 and fiscal year 2026 for the pilot NCODE program, Camarillo said.
” will be an initial foray in creating kind of a secure classified enclave where there will be collaboration tools, there’ll be a workspace where these companies can kind of do what they need to do, and also kind of begin to do some software development efforts for those that are in that type of business,” he said.
How small businesses can apply to participate in NCODE and how many will be able to participate are details still being worked out within the office of the Assistant Secretary of the Army for Acquisition, Logistics and Technology, Camarillo said.
“I think we will learn a lot in terms of its utilization and how effective it is with the initial kind of tranche of small businesses that we bring into it,” he said. “And I think the goal is to learn from that and continue to evolve the program to make it even better.”
DOD Programs
Helping small businesses find success in working with the Defense Department is one of the roles of the DOD Office of Small Business Programs, and the department has had success in that effort, said program director Farooq Mitha.
One example of that is the DOD’s APEX Accelerator program, which aims to teach small businesses what’s needed for them to do business with the government.
“Our APEX Accelerator Program, which used to be with and we took it over about two years ago now, our 97 centers across the country that help companies learn how to do business with DOD,” Mitha said.
APEX Accelerators, Mitha said, are now focused on helping small businesses comply with things like CMMC and also helping them find more information on the programs and opportunities that exist within the DOD.
The DOD’s Mentor-Protege Program has been strengthened in recent years, Mitha said. The program is the oldest continuously operating federal mentor-protege program in existence. Under the program, small businesses are partnered with other companies to help them learn to expand their footprint within the defense industrial base.
On the Mentor-Protege Program, he said, DOD has worked to get funding for the program back into the president’s budget and has also worked with Congress in fiscal year 2023 to make the program permanent. There are also changes to the program to improve its performance, he said. For instance, the revenue requirement for companies who want to serve as mentors changed from $100 m to $25 m.
“We believe strongly that sometimes, or often, small and medium-sized businesses can mentor small businesses better than a large company,” he said.
While firms who serve as mentors within the Mentor-Protege Program were already eligible to receive cost reimbursement for their role, a new pilot program, Mitha said, provides up to 25% reimbursement to protege firms for engineering, software development or manufacturing customization.
Mitha also said as part of the Mentor-Protege Program, the timeline for developing partnership contracts has been sped up.
“Contracting timelines used to take 12 to 18 months,” he said. “We’ve now set up a new centralized contracting mechanism where we are now awarding better mentor/protege agreements in 60 days or less.” (Source: U.S. DoD)
16 Oct 24. US Army Announces Effort to Help Small Business Meet Cybersecurity Requirements. The Defense Department is actively working on plans to build cybersecurity requirements for the defense industrial base into defense contracts as part of its Cybersecurity Maturity Model Certification program, or CMMC. The first contracts with those requirements built in are expected sometime in 2025.
But for small businesses who might not have the resources to meet stringent cybersecurity requirements on their own, the Army is planning to launch a pilot program called the Next-Generation Commercial Operations in Defended Enclaves, or NCODE, said Undersecretary of the Army Gabe Camarillo, during a discussion Tuesday at the 2024 Association of the United States Army Annual Meeting and Exposition in Washington.
“This essentially provides a cyber-secure enclave in a secure environment for small businesses to participate in where they can collaborate, share information, most importantly, do their own work that they need to that would otherwise present a threat vector for actors that we know are very active in the cybersecurity space,” Camarillo said. “What’s great about it is it is compliant with CMMC, so all of the department’s requirements would be met by operating in this environment.”
Camarillo said many of the small businesses the Army worked with last year were at least partially at risk to cybersecurity threat vectors.
“Depending on how they’re capitalized and how many resources they have, their ability to overcome , despite our efforts across the department, can be very, very challenging,” he said. “So, we knew we had to do something.”
The Army is setting aside about $26m in both fiscal year 2025 and fiscal year 2026 for the pilot NCODE program, Camarillo said.
” will be an initial foray in creating kind of a secure classified enclave where there will be collaboration tools, there’ll be a workspace where these companies can kind of do what they need to do, and also kind of begin to do some software development efforts for those that are in that type of business,” he said.
How small businesses can apply to participate in NCODE and how many will be able to participate are details still being worked out within the office of the Assistant Secretary of the Army for Acquisition, Logistics and Technology, Camarillo said.
“I think we will learn a lot in terms of its utilization and how effective it is with the initial kind of tranche of small businesses that we bring into it,” he said. “And I think the goal is to learn from that and continue to evolve the program to make it even better.”
DOD Programs
Helping small businesses find success in working with the Defense Department is one of the roles of the DOD Office of Small Business Programs, and the department has had success in that effort, said program director Farooq Mitha.
One example of that is the DOD’s APEX Accelerator program, which aims to teach small businesses what’s needed for them to do business with the government.
“Our APEX Accelerator Program, which used to be with and we took it over about two years ago now, our 97 centers across the country that help companies learn how to do business with DOD,” Mitha said.
APEX Accelerators, Mitha said, are now focused on helping small businesses comply with things like CMMC and also helping them find more information on the programs and opportunities that exist within the DOD.
The DOD’s Mentor-Protege Program has been strengthened in recent years, Mitha said. The program is the oldest continuously operating federal mentor-protege program in existence. Under the program, small businesses are partnered with other companies to help them learn to expand their footprint within the defense industrial base.
On the Mentor-Protege Program, he said, DOD has worked to get funding for the program back into the president’s budget and has also worked with Congress in fiscal year 2023 to make the program permanent. There are also changes to the program to improve its performance, he said. For instance, the revenue requirement for companies who want to serve as mentors changed from $100 m to $25 m.
“We believe strongly that sometimes, or often, small and medium-sized businesses can mentor small businesses better than a large company,” he said.
While firms who serve as mentors within the Mentor-Protege Program were already eligible to receive cost reimbursement for their role, a new pilot program, Mitha said, provides up to 25% reimbursement to protege firms for engineering, software development or manufacturing customization.
Mitha also said as part of the Mentor-Protege Program, the timeline for developing partnership contracts has been sped up.
“Contracting timelines used to take 12 to 18 months,” he said. “We’ve now set up a new centralized contracting mechanism where we are now awarding better mentor/protege agreements in 60 days or less.” (Source: U.S. DoD)
—————————————————————————————————————————————————————————————————————————————————————————————————————————————
Founded in 1987, Exensor Technology is a world leading supplier of Networked Unattended Ground Sensor (UGS) Systems providing tailored sensor solutions to customers all over the world. From our Headquarters in Lund Sweden, our centre of expertise in Network Communications at Communications Research Lab in Kalmar Sweden and our Production site outside of Basingstoke UK, we design, develop and produce latest state of the art rugged UGS solutions at the highest quality to meet the most stringent demands of our customers. Our systems are in operation and used in a wide number of Military as well as Homeland Security applications worldwide. The modular nature of the system ensures any external sensor can be integrated, providing the user with a fully meshed “silent” network capable of self-healing. Exensor Technology will continue to lead the field in UGS technology, provide our customers with excellent customer service and a bespoke package able to meet every need.
A CNIM Group Company
———————————————————————————————————————————————————————————————————————————————————————————————————————————–

