Bills/H.J.Res. 40

Providing for congressional disapproval under chapter 8 of title 5, United States Code, of the rule submitted by the Department of Defense relating to "Cybersecurity Maturity Model Certification (CMMC) Program".

Providing for congressional disapproval under chapter 8 of title 5, United States Code, of the rule submitted by the Department of Defense relating to "Cybersecurity Maturity Model Certification (CMMC) Program".

In CommitteeDefenseHouseHouse Joint Resolution · 119th Congress
Bill Progress · House
Introduced
Committee
Passed House
Passed Senate
Passed Both
Signed

Plain Language Summary

# Summary of HJRES 40 **What It Would Do** This bill would cancel a cybersecurity rule that the Department of Defense finalized in October 2024. The rule created the Cybersecurity Maturity Model Certification (CMMC) Program, which requires defense contractors and their subcontractors to meet specific security standards when handling sensitive government information. If passed, HJRES 40 would eliminate these requirements, preventing the DOD from enforcing the new cybersecurity certification program. **Who It Affects** The bill directly impacts defense contractors and subcontractors—companies that work on government defense contracts. These businesses currently must comply with the CMMC standards to protect federal contract information and classified government data on their computer systems.

The bill would also affect the DOD's ability to oversee cybersecurity across its supply chain of private contractors. **Current Status** HJRES 40 was introduced by Representative Andrew Clyde (R-GA) and is currently in committee. The bill uses Congress's authority under federal law to reject executive agency rules (known as the Congressional Review Act). Supporters of canceling the rule argue it may be burdensome for contractors, while those supporting the CMMC program contend it strengthens national security by ensuring contractors adequately protect sensitive defense information from cyber threats.

CRS Official Summary

This joint resolution nullifies the Department of Defense (DOD) rule titled Cybersecurity Maturity Model Certification (CMMC) Program (89 Fed. Reg. 83092) and published on October 15, 2024. Among other elements, the rule establishes the Cybersecurity Maturity Model Certification Program. The program institutes policies regarding the protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) that is processed, stored, or transmitted on defense contractor and subcontractor information systems during defense contract performance. The rule also identifies entities to which the rule applies and describes DOD implementation of the program.

Advertisement

Latest Action

February 12, 2025

Referred to the House Committee on Armed Services.

Subjects

Administrative law and regulatory proceduresComputer security and identity theftCongressional oversightDepartment of DefenseIntelligence activities, surveillance, classified informationPublic contracts and procurement

Sponsor

Key Dates

Introduced
February 12, 2025
Last Updated
February 12, 2025
Read Full Text on Congress.gov →
Advertisement