CMMC – Will the COTS Exception Apply to Me?
Summary
CMMC, DOD’s Capability Maturity Model Certification, will require almost all government contractors doing business with the Department of Defense to be independently certified by a third party as meeting one of five cyber security standards. This requirement will apply to every link in the government’s supply chain – including OEMs, distributors and resellers. Under NIST SP 800-161, COTS is defined as “Software and hardware that already exists and is available from commercial sources.” Under FAR 2.101, COTS means any item of supply, other than real property, that is: • Of a type customarily used by the general public or by non-governmental entities for purposes other than governmental purposes, • Sold in substantial quantities in the commercial marketplace • Offered to the government without modification It would seem, then, that any company that provides services – on a standalone basis or in combination with IT products – would not qualify for this exception. This grey area probably makes it prudent for contractors, which otherwise might only be providing COTS items, to consider at least a Level 1 certification. First, even if the exception does firmly apply, it still may be wise to obtain a Level 1 certification to avoid any argument (and risk losing business) with a contracting officer or prime contractor at the order level if they disagree on the nature of the items you are providing (e.g., COTS versus a commercial item).