Certification of cybersecurity compliance will be required for suppliers to do business with General Dynamics Land Systems and the U.S. DoD, unless the supplier solely provides COTS. Certification of cybersecurity compliance is led by the Office of Under Secretary of Defense for Acquisition and Sustainment, and CMMC scores will be tracked by the DoD. Again, all companies will require a CMMC rating from 1 to 3 (except COTS suppliers), and DoD solicitations may restrict the use of suppliers below a specified CMMC level. In order for a supplier to process, store or transmit CUI, it must be certified at least at CMMC level 2.
Suppliers will be responsible for sourcing, conducting and reporting their CMMC audits via accredited third-party entities.