The chief purpose of CMMC 2.0 is to protect unclassified information throughout the defense supply chain from cyber threats. Borrowing from existing frameworks like NIST SP 800-171 and NIST SP 800-172, CMMC 2.0 requires defense contractors to implement standardized cybersecurity practices and processes in order to bid on Department of Defense contracts.
As part of CMMC preparations, contractors that handle controlled unclassified information (CUI) need to implement practices that keep CUI protected. This white paper covers key considerations regarding CUI protection for CMMC 2.0 and how Virtru helps prepare for CMMC 2.0 by protecting CUI shared via email and files throughout the supply chain.