Skip to Main Content Subscribe

Where the Pentagon’s CMMC Overhaul Could Go Next

Share

The agency is reviewing its mandatory cybersecurity certification as defense vendors and officials weigh the program’s future.

7m read
Written by:
Small Business Administration Administrator Kelly Loeffler, Under Secretary of War for Acquisition and Sustainment Michael Duffey and DOW CIO Kirsten Davies listen to Kform CEO Callye Keen during a factory tour of Kform in Sterling, Virginia, on July 16, 2026.
Small Business Administration Administrator Kelly Loeffler, Under Secretary of War for Acquisition and Sustainment Michael Duffey and DOW CIO Kirsten Davies listen to Kform CEO Callye Keen during a factory tour of Kform in Sterling, Virginia, on July 16, 2026. Photo Credit: War Department

The War Department’s decision last week to pause implementation of the Cybersecurity Maturity Model Certification (CMMC) program leaves one question: what should replace it?

During the next 60 days, a Pentagon task force will evaluate the future of the program and what cybersecurity compliance entails. The task force already held its first meeting last week.

“We are in the 60 days. [The task force is] actually stood up. They had their first meeting today at the hallway across from my office,” DOW CIO Kirsten Davies said during a July 15 visit to Kform, a defense manufacturer in Sterling, Virginia.

Based on interviews with defense industry experts, three issues appear to dominate next steps: reducing costs for small businesses, scaling the program and measuring accountability.

Reducing Costs

One of the biggest concerns with small and medium-sized businesses has been cost of mandatory third-party assessments. During the tour at Kform, Under Secretary of War for Acquisition and Sustainment Michael Duffey cited department estimates for average Level 2 compliance to be roughly $150,000 per contractor — money he argued could be spent on actual cybersecurity investments and manufacturing.

Davies acknowledged CMMC’s goal to fulfill the department’s cybersecurity goals, but noted the program had veered from its original national security purpose.

“What it has become, though, is otherwise a burdensome red tape-driven check-the-box point-in-time view of a company’s handling of this federal data,” Davies said. “It is costly for third-party assessments, and especially so for small businesses like this one today. It is duplicative of other federal and contractual requirements for that very same data, and it is causing time lag to complete this compliance work.”

During DOW’s visit, Kform CEO Callye Keen noted how compliance costs compete directly with investments in manufacturing equipment, automation and engineering talent.

“Year after year we have to make the decision: Do I buy another piece of equipment? Do I invest in another robot? Do I hire another engineer, or do I meet CMMC compliance or yet another piece of compliance?” Keen said.

The department is seeking public input through a request for information on sam.gov, asking contractors and Certified Third-Party Assessor Organizations (C3PAOs) to provide data on the financial and operational impacts of CMMC. Officials said the feedback will help identify where compliance requirements create unnecessary burdens while maintaining appropriate cybersecurity protections.

Scaling the Program

Scaling the program has been difficult in its early stages. The DIB includes approximately 50,000 prime contractors and a substantial number of subcontractors and suppliers, according to a Warfighting Acquisition University study. With a limited number of assessors, demand and costs rise, noted Summit Seven Cybersecurity Director Jacob Hill.

“If they cut third-party assessment, they’re taking a tool out of their toolbox, a scalable tool. They still can assess through DIBCAC, but they are limited auditors,” Hill said.

Hill argued the importance of the assessment process for documenting shortcomings in contractor self-reporting.

“I don’t quite understand why they view third-party assessment as bureaucracy,” Hill told GovCIO Media & Research. “The defense industrial base has shown a track record of not implementing the security requirements consistently. It’s been proven through multiple DCMA cybersecurity assessments. They’ll go in there … the contractor will report a high score. DIBCAC will say, ‘Actually, you were probably 100, 150 points less than what you thought you were.'”

Matthew Travis, CEO of one third-party assessor, Cyber AB, said independent verification remains essential to ensuring contractors meet cybersecurity requirements and said the organization would cooperate with the review.

“We are confident that the continued and measurable progress of CMMC, the immense investment that companies throughout the DIB and within the CMMC ecosystem have already made in its future, and the absolute criticality of third-party verification of cybersecurity conformity will prove itself indispensable under a rigorous review,” Travis said.

Measuring Accountability Through Outcomes

Former War Department Principal Deputy CIO Leslie Beavers noted the importance of accountability in cybersecurity.

“The task force needs to find an innovative approach to not just do the oversight, but to do the certification and/or the accountability,” Beavers told GovCIO Media & Research. “The government [needs to] be confident that the companies are doing what they say they’re doing and securing the information following the [National Institutes of Standards and Technology] directives, but to do it in more of a continuous fashion and one that I think needs to be measured at the outcome level, instead of compliance steps.”

Beavers added that there are other ways for CMMC to safeguard controlled classified information, including a system for DOW to monitor easily accessible information in addition to self-attestation.

“There could be some kind of a scan or something on the the public-facing side. You’d have the self-assessment signing it off. The companies are legally accountable for those actions that you did, what you said you were going to do, and then the government scans, and then you have a little bit of a check and a verify,” Beavers suggested. “It may not be 100%, but it’ll get you 80% or 90% there … That could be done at scale, that would fundamentally increase the confidence in the outcome.”

The pause on mandatory third-party certification for contractors does not eliminate existing cybersecurity obligations. Self-assessments and contractual security requirements remain in effect while the review is underway.

Davies emphasized that the suspension should be viewed as an effort to develop a more effective and scalable approach to protecting the DIB.

“There’s a notion that I’ve always subscribed to, which is you can outsource the work, but you can’t outsource the risk,” Davies said. “We need to be thinking much more creatively, cleverly and holistically at how we support vendors, contractors and DIB companies who supply for us, who produce for us.”

Related Content