Cybersecurity Sees Ups and Downs as We Head Toward 2025
The cybersecurity field experienced significant developments over the past year with new DoD contractor requirements, CMMC program rollouts, and updates to the Federal Acquisition Regulation, setting the stage for further changes in 2025.
Published on April 13, 2025
Over the past year, the cybersecurity landscape has been marked by both progress and challenges. The Defense Department advanced its new contractor requirements and updated the Federal Acquisition Regulation, while incorporating emerging issues such as the impact of artificial intelligence on cyber. Key developments include the finalization and phased rollout of the Cybersecurity Maturity Model Certification (CMMC) program, with initial implementation steps already set into motion in late 2024.
Reports from October to December 2024 indicate a robust push toward secure operations across defense contracting. With the DoD finalizing various CMMC rules—highlighted by sources such as Lockheed Martin, Faegre Drinker, Crowell & Moring LLP, Morgan Lewis, and RSM US LLP—the industry is bracing for significant changes in early to mid-2025. These regulatory updates and phased implementations are expected to reshape how defense contractors manage cybersecurity risks in the coming year.