This is the main content of the page.

National And Media UpdatesPress Releases

Accreditation Body Media

For all communications and media inquiries, please email The Cyber AB at:

Kimberly Kantor
kkantor@cmmcab.org

 

 

Cyber AB News

Please see below the official announcements and communications issued by the Cyber AB regarding significant information updates, official statements or general information for public awareness.

 

CMMC Ecosystem Updates

Official announcements highlighting recent actions taken by the Cyber AB and other newsworthy information. To view Press Releases from 2021 to date, please read below.

 

The Cyber AB's Response to the DoW's "Reforming CMMC and Reducing Compliance Burden (RFI)"

August 14th, 2026

137 National Plaza Suite 300
National Harbor, Maryland 20745
www.cyberab.org

14 August 2026

Leanne M. Condren
Contract Specialist
Washington Headquarters Services (WHS)
United States Department of War
Washington, DC 20301

SUBJECT: Reforming CMMC and Reducing Compliance Burden for the DIB

Dear Ms. Condren:

Thank you for the opportunity to respond to this CMMC Request for Information. The Cyber AB appreciates the Department’s commitment to continued engagement with industry and the CMMC Ecosystem in furtherance of improving this critical supply-chain security program for the defense industrial base.

The Cyber AB is a nonprofit, tax-exempt organization that serves as the exclusive accreditation body for the CMMC Program.

Company Name: Cybersecurity Maturity Model Certification Accreditation Body, Inc.
DUNS: 101838577; UEI: W7GSFCBBE6J1; CAGE Code: 8HGJ5
Point of Contact: Kimberly Kantor, Communications Director
Address: 137 National Plaza, Suite 300, National Harbor, Maryland 20745
Phone number: 888-807-1799
Email: kkantor@cyberab.org

We support the Department’s desire to reform and improve the CMMC Program, which has made significant and measurable progress since its inception. Over the past six years, hundreds of companies and thousands of individuals have responded to the Department’s request to build the CMMC Ecosystem and give launch to the indispensable third-party verification element of this this vital cybersecurity initiative.

The Arsenal of Freedom demands the right balance of security and efficiency to protect and enable our warfighters. CMMC’s private-sector, market-based, industry-led approach is the converse of bureaucracy, but we know there is more innovation and improvement to be found. CMMC stakeholders want to contribute to this reform. We strongly support changes that will enhance operational resiliency of the defense industrial base, as well as those that will reduce unnecessary cost, duplicative documentation, inconsistent conformity interpretations, and administrative friction.

Our response leads with both specific and broad perspectives of the program overall, and then answers the RFI’s seven questions, to which we include our own experiential feedback in implementing the NIST SP 800-171 Rev 2 security requirements and successfully attaining third-party verification.

We look forward to participating in the CMMC Reform Task Force and will remain available to provide additional information and insight for the Department’s CMMC review.

Respectfully Submitted,

Matthew Travis
Chief Executive Officer


Overarching Perspectives:

  • There is absolutely no substitute for third-party verification when it comes to cybersecurity risk management. Self-assessment and self-attestation within the defense industrial base (DIB) have been tried in the past and have proven to be a failed methodology to ensure that cybersecurity requirements are being met. Formal verification of conformity through the certification by accredited third parties—all under the trust and confidence of an established ISO/IEC standard—is the optimal mechanism to manage supply chain risk throughout the DIB. The Department can’t cease contracting with industry, nor can it let its business partners remain negligent in safeguarding CUI to the government’s standard. That leaves only three options: 1) self-assessment/self-attestation; 2) government inspection; or 3) third-party certification. The Department has empirical evidence that self-assessment/self-attestation—even under the presupposed deterrence of the False Claims Act—does not work. And despite the laudatory efforts and effectiveness of the Defense Contract Management Agency’s (DCMA) Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), building an internal cybersecurity audit function at scale within the Department is infeasible. Third-party certification works, and with the needed reforms from this CMMC program review, can work even better, both for the DIB and America’s warfighters.
  • Approximately 80% of Authorized or Accredited C3PAOs are small businesses themselves, and they have largely been able to meet the NIST SP 800-171 Rev 2 implementation requirements without complaint. Most all of the C3PAOs are small businesses companies, and they have the same NIST SP 800-171 Rev 2 requirements as other small defense contractors who need to attain CMMC Level 2 certification.1 But unlike small defense firms, these C3PAOs are unable to: 1) recoup their investments in CMMC as an allowable reimbursable charge back to the government (since they do not hold Department of War contracts); nor 2) use their DIBCAC Level 2 assessment for eligibility to win DoW contracts should they elect to pursue them. These C3PAOs, along with ourselves at The Cyber AB, have proven that small businesses can meet the implementation requirements of NIST SP 800-171 Rev 2 and pass a conformity assessment by a credible third-party (though to be fair, not all the C3PAO candidates have succeeded on this front). But the current C3PAO cadre, along with other small businesses that have achieved Level 2 certification, have set the example that safeguarding CUI and passing an external assessment are not impossible or financially crippling for small businesses.
  • CMMC is currently working as originally scoped and designed, though reform is needed. Since early 2025, approximately 2,000 defense contractors have hired C3PAOs and attained Level 2 certifications. These certifications instill trust and confidence in the improving cybersecurity posture of the DIB. The CMMC Program continues to scale at a growing and steady rate and has been on a capacity-building pace that will result in sufficient C3PAO and CCA participation by the end of the 2028, when the Department’s original three-year CMMC implementation plan was scheduled to conclude and full capacity of the Program would be realized. CMMC is working, and the progress made to date should not be understated or dismissed. The requirement reality for defense contractors must be stated plainly and repeatedly: DFARS 252.204-7012 remains in effect, the obligation to implement NIST SP 800-171 has not gone away. Suppliers must continue working toward full implementation and genuine operational resilience. Reform is about making that path more affordable, addressable, accessible, and attainable, not about diluting or eliminating the requirement. The momentum CMMC has built across the DIB is of tangible value to our warfighters’ security and should not be squandered.
  • The Private Sector has responded to Department’s invitation to engage in CMMC and created a vast supporting Ecosystem. In 2020, the Pentagon had a CUI safeguarding problem and turned to industry partners, individual American citizens, and foreign allies to help solve it. Recognizing that defense contractors were not upholding their requirements under the DFARS 7012 clause and were under-reporting or mis-reporting their conformity status against NIST SP 800-171 Rev 2 implementation, the Department requested that private industry—as well as private citizens—in the compliance, cybersecurity, audit, accreditation, managed services, managed security services, GRC, training, education, and consulting sectors consider investing in this new CMMC program by becoming CMMC assessors, practitioners, C3PAOs, instructors, and publishing partners. The response was immediate. The CMMC Ecosystem began to take shape and, after enduring a protracted three-year federal rulemaking pause, now presents a mature and still-growing powerful resource to assist DoW in ensuring that the Arsenal of Freedom has a secure supply chain for its warfighters. This capable (and patient) community supporting the Department includes the following key elements:

    Over 110 C3PAOs: assesses and certifies defense contractors to CMMC Level 2

    Over 1,100 CMMC Certified Assessors: conduct the conformity assessments for C3PAOs

    Over 2,000 CMMC Certified Professionals: provide apprentice support to assessment teams

    Over 2,000 Registered Practitioners: assist contractors in implementing NIST SP 800-171

    Over 50 Approved Training Providers: conduct official CMMC training courses

    Over 10 Approved Publishing Partners: produce CMMC authorized training materials

    The Cyber AB: authorizes/accredits C3PAOs and enforces the Code of Professional Conduct

    ISACA: operates the CAICO that certifies and credentials CMMC CCAs, CCPs, and instructors

    The Cyber EF: manages the CMMC Marketplace and administers Registered Practitioners

    This is a resilient community of dedicated professionals and companies who have cast their business and financial interests into making CMMC work for the Department. They embrace CMMC reform and merely seek the clarity, policy transparency, and governmental stability that all successful private markets require. With this, the Ecosystem will continue to deliver a continuously improving CMMC Program for the Department’s leadership.
  • The value and/or reciprocity of existing CMMC Level 2 certifications must be preserved during the reform transition. Whatever changes the Department makes to the CMMC Program, it is essential that the Level 2 certifications already awarded will retain meaningful status in a “CMMC 3.0” world and that Level 2 certification assessments can continue apace during the resultant federal rulemaking period that will likely be necessitated. Without these assurances, the CMMC Ecosystem will most surely not be able to endure another extensive hiatus while the rulemaking process is carried out.
  • FedRAMP’s relationship to CMMC remains challenged and fraught with confusion, both within the DIB and throughout the CMMC Ecosystem. For starters, 32 CFR part 170 compels an organization seeking certification (OSC) first to determine (on their own) whether the external services provider (ESP) they might be utilizing is engaged in cloud computing or not, without sufficient guidance as to how this technical determination should be made. Furthermore, if they are able to determine that their ESP is actually a cloud service provider (CSP) and not a managed services provider (MSP) or managed security services provider (MSSP), the OSC then has to ascertain if their CSP’s presence in the FedRAMP marketplace is valid or not (currently, the evolving disposition of FedRAMP v4, v5, and 20x significantly confuse the matter). And if that CSP is not in the FedRAMP Marketplace, with a valid status, then the OSC must examine an extensive body of evidence that might indicate if their CSP meets FedRAMP Moderate baseline “equivalency” as established in a 2023 Pentagon memorandum. Suffice to say, the FedRAMP-CMMC relationship is an area where reform is greatly needed.
  • There is no “third-party assessment bureaucracy” within CMMC. The NIST SP 800-171 Rev 2 standard itself might conjure frustrations of “bureaucratic compliance” with its myriad administrative and documentation requirements, but engaging a C3PAO for a Level 2 certification assessment is not bureaucratic. Defense contractors can easily find the Authorized or Accredited C3PAOs (private sector entities) on the CMMC Marketplace (a private sector resource) and hire them for a Level 2 certification (a private sector business agreement) without having to fill out a government form or seek approval from government employees. The only interaction with “bureaucratic” processes is when the C3PAO is required to upload the certification assessment data and results into eMASS, a Departmental information system. CMMC was designed to be an efficient, market-based, industry-led program, and it very much remains that today as an operational program.
  • CMMC is an international initiative and the program reforms that are taken will impact a growing global CMMC support network to ensure the safeguarding of CUI throughout the DIB. The U.S. military supply chain is global, as is the digital risk to CUI throughout it. Presently, individuals and companies from 30 countries throughout the world have joined the CMMC movement. International partners are adopting the CMMC standards and both individuals and companies within those countries are assuming formal roles within the Ecosystem. The CMMC Reform Task Force should consider this international factor when assessing the feasibility, risk, or benefit of any planned program changes.

1 Small business as defined under the size standard for the NAICS codes 541512 / 541519, “Computer Systems Design / Other Computer Related Services”

Request for Information (RFI) #DoDCIOReformingCMMCforDIB001 Response

Question #1. Identify the top five most prohibitive cost drivers, administrative burdens, or operational challenges your organization has experienced, or anticipates experiencing, when attempting to comply with the CMMC framework and NIST SP 800-171 Rev. 2.

Response #1: The Cyber AB’s CMMC and NIST SP 800-171 Rev.2 requirements are established in our CMMC support contract with the Department of War (contract #HQ003420H0003). Our experience in implementing the security requirements of the NIST SP 800-171 Rev 2 standard and preparing for the corresponding conformity assessment that was conducted by the Defense Contract Management Agency (DCMA) / Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) revealed the following most prominent challenges:

  1. Hiring an External Service Provider (ESP) (Cost Driver): Like most small businesses throughout the defense industrial base (DIB), The Cyber AB has a very limited IT and security staff, making first-time implementation of NIST SP 800-171 Rev 2 a technical and administrative challenge that would have been extremely difficult to overcome alone. We elected to retain the services of an external service provider (ESP) that provides both managed services (MSP) and managed security services (MSSP). The total expenses of our ESP services to facilitate our conformity to the NIST CUI standard—not including our Microsoft software licensing costs—exceeds [redacted] per year. Our agreement with them incorporates their support for addressing approximately [redacted] of the 320 NIST SP 800-171A assessment objectives, along with shared responsibility for an additional [redacted] of the total requirements.
  2. Microsoft Licensing (Cost Driver): Given The Cyber AB’s unique mission, we opted to stand up a compliance-ready CUI environment with architectural segmentation and secured a dedicated enclave with Microsoft’s Government Community Cloud High (GCC-High) tenant. GCC-High is extremely expensive and we incur over [redacted] in annual licensing fees for it. On top of these licensing fees, we additionally pay approximately [redacted] per year for the supporting environment in Azure Government.
  3. Generating Required Documentation (Administrative Burden): Developing initial program documentation such as the risk register, System Security Plan, and multitude of other policies and procedures required extensive and protracted effort from employees from across the organization. NIST SP 800-171 Rev. 2, by its very nature, is a documentation-heavy standard. Developing and maintaining documentation that accurately reflects the CUI environment—including the SSP, policies, procedures, inventories, diagrams, and evidence—is labor intensive. For us, it requires the creation and management of over [redacted] documents. There is a lack of clear guidance within the framework on the proper level of detail needed in the documents, which can motivate “pre-assessment caution overabundance” that compels excessive generation of documentation and the exertion of countless labor hours on revisions. A significant amount of time was spent developing policies and procedures that explicitly address individual practice objectives, as well as conducting exercises solely to satisfy assessment expectations (e.g., environment-specific risk assessments crafted to align with control language and assessor keyword requirements).
  4. Mock Assessment (Cost Driver): We felt strongly that we needed an authentic “practice run” of the NIST SP 800-171 Rev 2 assessment before we subjected ourselves to the official assessment. The mock assessment was extremely helpful but still cost us [redacted].
  5. Maintaining Conformity (Operational Challenge): Even though the DIBCAC performed a “point-in-time assessment” of our environment and validated our conformity to the NIST CUI standard, we obviously retain the responsibility to maintain the security requirements of our assessed network and, if we initiate a significant change, to solicit a reassessment from the DIBCAC. We therefore must shift our operational mindset from a “prepare for the assessment” approach to maintaining an ongoing operational framework. We have been encountering several key operational challenges during this post-assessment sustainment phase:

    Uncontrolled Infrastructure Changes: Introducing new IT assets, cloud services, or software without strict change control can inadvertently alter the assessed boundary or introduce unmonitored entry points for CUI.

    Audit Trail Fatigue: NIST SP 800-171 Rev. 2 requires ongoing operational activity—such as weekly log reviews, vulnerability scans, patch validation, and quarterly access reviews. While a lot of this evidence generation can be automated, it still requires significant human effort to properly organize, monitor, and analyze.

    Updating the SSP: The SSP and associated operational policies must remain living documents, so we have to keep network diagrams, hardware/software inventories, and CUI flowcharts synchronized with real-world updates and adjusting access for any newly added or departed employees.

Question #2: Which specific security controls has your organization found to deliver the most tangible uplift of cybersecurity and actual risk reduction?

Response #2: The controls that deliver the greatest cybersecurity uplift for us are the ones that directly reduce the likelihood and impact of the attacks most frequently used to target the DIB.

  1. Multi-factor authentication (3.5.3) stands out as the single control with the highest leverage against the threats of credential theft, phishing, impersonation, and funds transfer attacks that dominate DIB-reported incidents.
  2. Access control and least privilege (3.1.x) shrink the impact radius of a compromise and limit an adversary's ability to move laterally.
  3. Audit logging and monitoring (3.3.x), when paired with event response automation playbooks, ensures an intrusion is detected and mitigated in minutes versus months.
  4. Patch management (3.14.1) is critical to addressing vulnerabilities once they are identified. General past historical data indicate that most compromises involve unpatched vulnerabilities.

Question #3. Conversely, which specific regulatory requirements or security controls create the highest administrative overhead and financial burden with the least measurable improvement to your actual cybersecurity posture?

Response #3: Overall NIST 800-171 Rev 2 Documentation: Cumbersome documentation detail (e.g., risk register, SSP) is compelled when attempting to comply with all of NIST’s assessment objectives as established in NIST 800-171A. Specifically, the particular verbiage and format that was strongly recommended to us in order to pass our assessment, along with duplicative evidentiary items and redundant risk recitations, are disproportionate to their value in our security posture. In general, most of the documentation and narrative requirements, like policy and procedures documentation for controls that could be otherwise verified, create an administrative burden without a commensurate reduction of risk.

Question #4. Describe how your organization utilizes existing commercial cybersecurity capabilities, platforms, managed services, or any other additional strategies or initiatives to safeguard data, improve operational resiliency, and reduce cybersecurity risk, and how the DoW might better recognize or accept these commercial solutions within a compliance or risk framework.

Response #4: The Cyber AB utilizes the security expertise of our ESP for continuous monitoring, EDR/XDR, vulnerability management, and incident response. Our ESP manages our FedRAMP Authorized cloud environments and compliant enclaves that support shared responsibility control inheritance and our GRC platform that maps evidence to NIST SP 800171 Rev 2 control objectives. In addition to this traditional compliance-recognized environment, we leverage secure commercial offerings to secure our organization and our platform. We utilize multiple security strategies and technologies to bolster our organization’s security stance above and beyond those necessary for compliance.

The Department could more broadly recognize commercial cloud and managed security solutions that meet or exceed required security outcomes even if they do not hold FedRAMP Moderate Authorization or its “equivalent”. Many platforms maintain strong industry-validated certifications—such as ISO 27001, SOC 2 Type II with appropriate scoping, or other independently assessed benchmarks that demonstrate proper security protocols and operational maturity. Rather than requiring full FedRAMP Authorization or “equivalent” for every cloud service provider, the DoW could allow tailored evaluations focused on the specific security controls relevant to the CUI environment or assess the CSP’s offering directly for control sufficiency. This approach could reduce unnecessary cost and complexity, expand viable solution options for OSCs, and preserve strong cybersecurity protections while enabling practical compliance pathways.

Question #5. Regarding Phase I self-assessments, what specific administrative or technical challenges does your organization face in maintaining, verifying, and reporting compliance, and how could this process be fundamentally streamlined? Have your self-assessments led to a more dynamic cyber posture approach, or are they performed only for compliance purposes?

Response #5: Despite our best efforts, our self-assessments lacked the necessary rigor and attention to detail that the subsequent mock assessment and DIBCAC assessment eventually provided. There is generally an inherent conflict of interest that we should all recognize for internal IT and security staff who are tasked with reporting accurate and meaningful self-assessment results to company leadership. Intuitively, any self-reported discrepancies or non-conformities could be interpreted by company leadership as performance shortcomings. Therefore, the biggest challenge of our self-assessment was getting a proper and unvarnished accounting of our overall security disposition and being able to verify compliance accurately.

Question #6. What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically reduce costs and barriers to entry for small, medium, and non-traditional businesses without degrading the protection of federal data?

Response #6: To “drastically reduce costs” to small and medium businesses, the Department has limited options. The standard that NIST has developed for the Federal Government to safeguard CUI compels implementation of 110 security requirements (that need to satisfy 320 assessment objectives contained within NIST SP 800-171A). The standard is the standard, and without question the most daunting costs to defense contractors are the costs to implement and maintain the CUI security requirements. It follows, then, that the only likely ways to reduce costs of implementation in a significant fashion would be either or all of the following:

  1. Tax-credits or grants to support NIST SP 800-171 Rev 2 implementation that would offset the costs of the small-business defense contractors; and/or
  2. Provision of a government or prime contractor’s secure data environment on which small businesses could store, process, or transmit CUI in furtherance of their contractual tasks.

On a related note, there would also likely be substantial relief if the Department were to reconsider the security requirements to safeguard Federal Contract Information (FCI):

  1. Elimination of CMMC Level 1. The Department could determine, from a risk management perspective, that the protection of Federal Contract Information (FCI) is not worth the costs that essentially all small businesses within the DIB have to incur in order to meet CMMC Level 1 requirements, which often have different scoping and security measures than that within the CUI boundary.

Since none of the abovementioned options are areas of expertise for The Cyber AB, we will refrain from offering specific policy implementation recommendations.

It is important to also note that any exemption, alleviation, or “waiver” of certain small businesses’ responsibilities to safeguard CUI in accordance with the NIST standard would, by definition, degrade the protection of federal data, but that might be another risk-management decision that the Department would make if the benefit of waiving CUI security requirements (i.e., retention of small business within the DIB or attraction of new start-up businesses into the DIB) were determined to outweigh the inherent security benefits of imposing the standard on ALL defense contractors.

As it pertains to the costs of CMMC certification, however, the Department currently has at its disposal several policy mechanisms or “dials” that it could adjust now to lower CMMC-specific costs to defense contractors. While none of these measures would “drastically reduce costs” to small businesses, they would nonetheless provide some meaningful and tangible reductions to the costs of a C3PAO Level 2 certification.

  1. Reduce the 32 CFR part 170 requirement for C3PAOs to assign a minimum of three (3) CMMC Certified Assessors (CCAs) to every CMMC Level 2 certification assessment. Many small defense contractors have a tightly bounded CUI environment, may rely heavily on an experienced ESP, and/or are very well organized with their evidence and documentation. In these instances, a CMMC assessment team of two (2) CCAs may not be needed and a single Lead CCA could efficiently and effectively complete the assessment single-handedly (along with the engagement of the second quality assurance CCA). The Department should lower the minimum manning threshold from three (3) CCAs to two (2) CCAs for a C3PAO assessment team.
  2. Eliminate the requirement for all CCAs and CMMC Certified Professionals (CCPs) to undergo a Tier 3 background investigation and receive a favorable determination therefrom as a condition of professional certification and C3PAO assessment team eligibility. Defense contractor personnel (both W-2 employees and 1099 consultants) routinely store, process, and transmit CUI—all without a Tier 3 background investigation by the Defense Counterintelligence and Security Agency (DCSA). Yet, CCAs and CCPs on C3PAO assessment teams—who will likely not encounter any CUI during most CMMC level 2 certification assessments—are required to undergo the DCSA Tier 3 investigations. Moreover, within the FedRAMP program, 3PAO assessors are not required to undergo a DCSA Tier 3 for the Low and Moderate baseline assessments. These Tier 3 investigations take several months and have led to a bottleneck in the production of CCAs and CCPs that could be working in the CMMC Ecosystem much sooner. More CCAs and CCPs will add more capacity to the C3PAO labor pool and as a result, increase the supply of assessment teams, thereby lowering costs to defense contractors in their CMMC Level 2 certification assessments. The DCSA Tier 3 could be replaced by a commercially contracted background investigation, many of which today provide equivalent scope, rigor, and scrutiny. The CMMC Reform Task Force should explore this option.
  3. Allow for C3PAOs to conduct continuous monitoring and “delta” assessments. CMMC Level 2 is assessed as a point-in-time activity. And any time a defense contractor with a previously certified information system makes a significant change to that network, they are required to hire a C3PAO again to conduct another complete Level 2 certification assessment. Not only does this introduce the non-trivial expense of needing multiple C3PAO certification assessments within a single three-year certification window, it also serves as an acute disincentive for a defense contractor who is contemplating making modernization improvements, innovation introductions, or security enhancements to their system.

    Moreover, operational resilience is decided by what happens every single day between assessments. The Department should create clear recognition, and where possible, reduced assessment or reporting burden for companies that demonstrate continuous control monitoring through managed detection and response, security incident and event management (SIEM), endpoint telemetry, and automated configuration and vulnerability monitoring. Rewarding continuous visibility turns CMMC from a periodic snapshot into a living security posture, and it directly improves the DIB's ability to detect and respond to attacks in real time rather than discovering a compromise months later. This is the reform that most closely aligns compliance with day-to-day cyber resilience.

    Presently, 32 CFR §170.17(a)(1) states that “The OSC must complete and achieve a MET result for all security requirements specified in §170.14(c)(3) to achieve the CMMC Status of Level 2 (C3PAO).” For continuous monitoring and “delta” assessments to be permitted within the CMMC Program, this language would need to be revisited and modified. We believe the CMMC Reform Task Force should explore this prospective policy change.

  4. Revisit Standards Acceptance for CMMC. The Department should reconsider the issue of reciprocity of other cybersecurity conformity frameworks and explore the incorporation of advance standing of satisfied security requirements to independent, accreditation-backed certifications that a defense contractor or ESP may already hold. CMMC and other assessments performed by independent third parties should recognize certifications backed by a recognized accreditation scheme. These certifications reflect rigorous, independently accredited evaluation and carry the same third-party accountability that makes CMMC credible. Not all controls will map one-for-one, and CMMC's specific CUI requirements won't always be fully satisfied by another framework, but where meaningful overlap exists it should be recognized, not ignored. The cost to assess an OSC under CMMC should be reduced where that OSC already holds an accreditation-backed cybersecurity certification. Re-proving controls that have been independently assessed by a third-party adds cost and time without adding security. Publishing clear crosswalks would allow assessors to focus on the gaps that matter and reward companies that have already invested in mature, validated programs with a reduced assessment scope.
  5. Explore the use of AI and other potential technology innovations to make CMMC certification assessments more efficient. While the deployment of artificial intelligence (AI) in ISO/IEC-sanctioned inspection activities is strictly governed by fundamental conformity principles, it is not altogether prohibited. The newly released ISO/IEC 17020:2026 standard explicitly incorporates technological systems, remote tools, and AI into its requirements and establishes imitations, boundaries, and prohibitions regarding its use.

    Conformity assessment is defined by professional judgment and fitness-for-purpose evaluation. AI tools cannot act as the sole authority in issuing a CMMC certification, determining conformity, or rendering final professional technical cybersecurity conclusions. Human competence, oversight, and ultimate responsibility remain mandatory under an ISO/IEC regime. Notwithstanding that, the CMMC Program should explore how and where AI and other automated tools might best be incorporated. Presently, the manner by which 32 CFR part 170 was written mostly compels a manual approach to assessing conformity to NIST SP 800-171 Rev 2. To make CMMC validation more efficient and near-real time, prospective uses of advanced technology should be explored and considered by the governing parties of CMMC.

Question #7. What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically improve operational resilience against cyber-attacks at your organization?

Response #7: To the extent “operational resilience” remains framed within Hon. Davies’s four core principles of 1) Eliminating Technical Debt; 2) Zero Trust; 3) Maintaining Functionality in Disconnected, Denied, Intermittent, and Limited (DDIL) Environments; and 4) Hardening Operational Technology, the CMMC Reform Task Force should consider the following:

  1. Incorporate OT security requirements into CMMC Level 2, as appropriate and applicable.
  2. Incorporate adversarial testing in CMMC. Third-party penetration testing can be a powerful way to identify weaknesses, as well as confirm controls in place are effective in their deployment against external threats, proving that controls stand up against a real adversary. But operational testing is costly and, as a result, often ignored by defense contractors. The Department should explore pathways to access sanctioned, affordable penetration testers and incident response testers for the DIB. This could include a vetted, cost-shared, or price-controlled roster of qualified providers, ideally tied to the same service provider validation and grant models. Alongside this, the incident response and business continuity testing requirements within NIST SP 800-171 Rev 2 should be expanded beyond box-checking exercises into genuine, periodic validation: live simulations, backup and system restoration testing, failover, and RTO/RPO verification, scaled to the size of the business. But this only works if the testing is affordable. If the Department raises the bar on adversarial and recovery testing without making qualified testers accessible, it simply becomes another cost burden. Raising the standard while introducing grant-funded testers ensures this critical validation mechanisms are taken seriously rather than skipped for budget reasons.