GSA Implements New Cybersecurity Framework for Contractors Aligned with CMMC Standards
DEFENSE
The General Services Administration (GSA) has enacted new cybersecurity requirements for contractors, aligning them with the Department of Defense's Cybersecurity Maturity Model Certification (CMMC) standards. Effective immediately for contracts involving controlled unclassified information, contractors must comply with NIST 800-171 and specific 800-172 controls, undergoing independent assessments by approved organizations. The implementation will occur in phases, starting with contractors identifying information types and meeting with GSA.

Jan 30, 2026, 3:53 PM