<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cybersecurity Archives - Florida Surety Bonds</title>
	<atom:link href="https://floridasuretybonds.com/category/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://floridasuretybonds.com/category/cybersecurity/</link>
	<description>Florida Surety Bonds provides you with the best possible surety bonding program. Contract, bid, performance, payment, maintenance, license and permit bonds</description>
	<lastBuildDate>Wed, 26 Nov 2025 01:15:23 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://floridasuretybonds.com/wp-content/uploads/2025/08/cropped-Florida-Surety-Bonds-logo-footer-32x32.png</url>
	<title>Cybersecurity Archives - Florida Surety Bonds</title>
	<link>https://floridasuretybonds.com/category/cybersecurity/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Cmmc 2.0 Cybersecurity Compliance For Dod Contracts</title>
		<link>https://floridasuretybonds.com/cmmc-2-0-cybersecurity-compliance-for-dod-contracts/</link>
		
		<dc:creator><![CDATA[Sarah O'Linn]]></dc:creator>
		<pubDate>Wed, 24 Sep 2025 13:16:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Surety Blog]]></category>
		<guid isPermaLink="false">https://floridasuretybonds.com/?p=6520</guid>

					<description><![CDATA[<p>The Department of Defense just released its final CMMC 2.0 rule requiring DoD contractors and subcontractors to meet new security certification levels before contract award. The new DFARS rule takes effect November 10, 2025. If you touch Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), even as a subcontractor, this rule applies to you. [&#8230;]</p>
<p>The post <a href="https://floridasuretybonds.com/cmmc-2-0-cybersecurity-compliance-for-dod-contracts/">Cmmc 2.0 Cybersecurity Compliance For Dod Contracts</a> appeared first on <a href="https://floridasuretybonds.com">Florida Surety Bonds</a>.</p>
]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="6520" class="elementor elementor-6520" data-elementor-post-type="post">
				<div data-particle_enable="false" data-particle-mobile-disabled="false" class="elementor-element elementor-element-854fc4 e-flex e-con-boxed e-con e-parent" data-id="854fc4" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-245a68d8 elementor-widget__width-initial elementor-widget elementor-widget-text-editor" data-id="245a68d8" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">The Department of Defense just released its final CMMC 2.0 rule requiring DoD contractors and subcontractors to meet new security certification levels before contract award.</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><strong><span style="color: #000000;">The new DFARS rule takes effect November 10, 2025.</span></strong></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">If you touch Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), even as a subcontractor, this rule applies to you.</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">CMMC Certification Levels are based on data handled:</span></p>
<p><span style="color: #000000;"></span></p>
<ul class="wp-block-list">
<li><span style="color: #000000;">Level 1: Basic cybersecurity for FCI (17 practices). Self-assessment.</span></li>

<li><span style="color: #000000;">Level 2: Advanced protection for CUI (110 practices based on NIST SP 800-171). Select cases are Self-assessments, others are 3<sup>rd</sup> party.</span></li>

<li><span style="color: #000000;">Level 3: Expert level for highly sensitive CUI (based on NIST SP 800-172; limited use). 3<sup>rd</sup> party.</span></li>
</ul>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">You cannot be awarded DOD Contracts unless you meet the CMMC level required by the solicitation or can get conditional certification/waiver.</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;"><strong><u>Contracting Actions to Take: How do you know if this applies to your immediate bids/contracts?</u></strong></span></p>
<p><span style="color: #000000;"></span></p>
<ul class="wp-block-list">
<li><span style="color: #000000;">Every DOD solicitation and contract that requires the processing, storage or transmission of FCI or CUI will specify the exact CMMC level required for the contractor&#8217;s information systems.</span></li>

<li><span style="color: #000000;">The CMMC level is determined by the program office or requiring activity based on the sensitivity of the information and risk profile of the contract.</span></li>

<li><span style="color: #000000;">This requirement is codified in the contract clause at DFARS 252.204-7021 and the solicitation provision at DFARS 252.204-7025.</span></li>

<li><span style="color: #000000;">NIST SP 800-171: The security standard that CMMC builds upon</span></li>
</ul>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;"><strong><u>Action to take before bidding:</u></strong> Search solicitations for DFARS 252.204.7025 and CMMC key terms like CMMC, FCI, CUI, NIST SP 800, Level</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;"><strong><u>Action to before signing contract</u></strong><strong>:</strong> Search contracts for DFARs 252.204-7021 and other key terms like CMMC, FCI, CUI, NIST SP 800, level  </span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">These clauses must be included in all applicable solicitations and contracts, except those solely for the acquisition of commercially available off-the-shelf (COTS) items</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;"><strong><u>Cost and Schedule Impacts:  </u></strong></span></p>
<p><span style="color: #000000;"></span></p>
<ul class="wp-block-list">
<li><span style="color: #000000;">CMMC costs are often allowable under DOD contracts in most cases. Did you include this in your estimates or contracts that required CMMC?</span></li>

<li><span style="color: #000000;">Third party certifications can cost $20 &#8211; $60k depending on business size and readiness.</span></li>

<li><span style="color: #000000;">Once awarded, certifications must be maintained through the contract lifecycle. This will be visible to COs on SPRS.</span></li>
</ul>
<p><span style="color: #000000;"></span></p>
<ul class="wp-block-list">
<li><span style="color: #000000;">Certification can take up to a year or more. Noone wants you to lose contract award if you wait until contract award to get certified, except maybe next viable bidder.</span></li>

<li><span style="color: #000000;">False claims of compliance could trigger civil or criminal penalties under the False Claims Act</span></li>
</ul>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;"><strong><u>Potential good news</u></strong>:</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">Rule introduces flexibility for contractors working toward full CMMC compliance since full certification may not always be feasible, especially higher levels.</span></p>
<p><span style="color: #000000;"></span></p>
<ul class="wp-block-list">
<li><span style="color: #000000;">Conditional Status: for CMMC Levels 2 &amp; 3, contractors may be awarded contract with a “conditional” CMMC Status for up to 180 days if they are actively closing out a Plan of Action and Milestones (POA&amp;M).</span></li>

<li><span style="color: #000000;">No conditional status is allowed for Level 1.</span></li>
</ul>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">The rule balances the need for cybersecurity with practical considerations for contractor readiness. DOD programs don’t want to get unduly delayed so flexibility is being considered in phased rollout.</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;"><strong><u>Subcontractors:</u></strong></span></p>
<p><span style="color: #000000;"></span></p>
<ul class="wp-block-list">
<li><span style="color: #000000;">Prime contractors must ensure their subs are certified at the appropriate level before work begins.</span></li>

<li><span style="color: #000000;">CMMC 2.0 Flowdown is based on the type of information the subcontractor handles, not just their role.</span></li>
</ul>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">CMMC cybersecurity expert Josh of H&amp;V Facility Solutions provided some applicable training to our federal contractor clients and friends to help them prepare for CMMC 2.0 rollout.  Their helpful slides are below:</span></p>
<p><span style="color: #000000;"></span></p>
<div data-wp-interactive="core/file" class="wp-block-file"><span style="color: #000000;"><object data-wp-bind--hidden="!state.hasPdfPreview" hidden class="wp-block-file__embed" style="width: 100%; height: 600px;" data="https://floridasuretybonds.com/wp-content/uploads/2025/10/CMMC-2.0-Educational-Presentation_FSB_09.17.2025-002.pdf" type="application/pdf" width="300" height="150" aria-label="Embed of CMMC-2.0-Educational-Presentation_FSB_09.17.2025-002."></object><a id="wp-block-file--media-6c1499ab-e21c-40cb-ad7f-4915abbfc3b4" style="color: #000000;" href="https://floridasuretybonds.com/wp-content/uploads/2025/10/CMMC-2.0-Educational-Presentation_FSB_09.17.2025-002.pdf">CMMC-2.0-Educational-Presentation_FSB_09.17.2025-002</a><a class="wp-block-file__button wp-element-button" style="color: #000000;" href="https://floridasuretybonds.com/wp-content/uploads/2025/10/CMMC-2.0-Educational-Presentation_FSB_09.17.2025-002.pdf" download="" aria-describedby="wp-block-file--media-6c1499ab-e21c-40cb-ad7f-4915abbfc3b4">Download</a></span></div>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">The DFARS Final Ruling was published in Federal Register on 9/10/2025:  <a style="color: #000000;" href="https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of">https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of</a></span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"> </p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">As federal surety bond experts, we&#8217;re proud to support contractors navigating these new federal mandates.</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"> </p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">Florida Surety Bonds is honored to secure success for our clients building America’s national infrastructure and critical defenses. Let us know if you have questions that we can help you with.</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"> </p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">Written by Sarah O’Linn, former civilian DOD Source Selection Evaluation Lead and Lead Systems Engineer.</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"> </p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">Florida Surety Bond Construction Bond Agent and Principal</span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"> </p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;"><a style="color: #000000;" href="mailto:sarah@floridasuretybonds.com">sarah@floridasuretybonds.com</a> | 407-755-6353 | <a style="color: #000000;" href="https://www.linkedin.com/in/sarah-o-linn/">Sarah’s LinkedIn</a></span></p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"> </p>
<p><span style="color: #000000;"></span></p>
<p class="wp-block-paragraph"><span style="color: #000000;">#CMMC #CMMC2 #DoDCompliance #FederalContracting #Cybersecurity #ConstructionBusiness #Federal Contracting #DODContractors #FloridaSuretyBonds #GovCon #DFARS</span></p>
<p><span style="color: #000000;"></span></p>								</div>
				</div>
					</div>
				</div>
		<div data-particle_enable="false" data-particle-mobile-disabled="false" class="elementor-element elementor-element-e46fbb4 e-flex e-con-boxed e-con e-parent" data-id="e46fbb4" data-element_type="container" data-e-type="container">
					<div class="e-con-inner">
				<div class="elementor-element elementor-element-8c051c3 elementor-widget elementor-widget-heading" data-id="8c051c3" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Add Your Heading Text Here</h2>				</div>
				</div>
					</div>
				</div>
				</div>
		<p>The post <a href="https://floridasuretybonds.com/cmmc-2-0-cybersecurity-compliance-for-dod-contracts/">Cmmc 2.0 Cybersecurity Compliance For Dod Contracts</a> appeared first on <a href="https://floridasuretybonds.com">Florida Surety Bonds</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Minified using Disk

Served from: floridasuretybonds.com @ 2026-06-09 17:16:09 by W3 Total Cache
-->