Regulation
,
Standards, Regulations & Compliance
Defense Cyber Vendors Blindsided by Pause to Program 7 Years in the Making

The deadline for industry comments on how to fix the Cybersecurity Maturity Model Certification process at the Department of Defense is at the end of this week, setting the stage for a battle royale over the future of the program.
See Also: OnDemand | Windows 10 End of Support in OT: Practical Strategies for Secure and Resilient Operations
“It feels a bit like a rug-pull,” said Matt Travis, CEO of the Cyber Accreditation Board, of an abrupt halt ordered last month to CMMC, the seven-years-in-the-making process for ensuring that defense contractors have mandatory cybersecurity controls in place to protect American innovation and intellectual property (see: Pentagon Halts Contractor Cyber Certification Program).
“This is a stab in the back for the most security-forward companies in the [Defense Industrial Base, or] DIB,” said one former defense official who worked on the CMMC issue and was not authorized by current employers to speak to the press.
The Cyber AB is the official accreditation organization for CMMC, and an institutional voice for the private sector ecosystem of third-party assessors, advisors and other professionals that’s sprung up around the program. CMMC was created at the end of the first Trump administration to enforce compliance with long-standing cybersecurity standards by around 300,000 companies doing business with the Department of Defense.
“Markets like certainty,” said Cyber AB CEO Travis, a former deputy director of CISA. The defense industrial base saw CMMC rules as “the government committing to this, and it’s ensconced in the Code of Federal Regulations. Let’s move out. And for the past eight months, everyone was moving out.”
The Pentagon published the CMMC final rule in 2024, starting a phased implementation last year. It set up a three-tier system: Self-attestation for the large majority of contractors, third-party accreditation by private sector assessors for up to 80,000 companies handling more sensitive information in level two and government audits for fewer than 3,500 companies with very sensitive data on level three.
Critically, CMMC depended on a private sector ecosystem of third-party certification and assessment organizations – C3PAOs – employing CMMC Certified Assessors – and CCAs – to conduct level two assessments. More than 100 companies, including tier one defense contractors like Booz Allen and Kratos, and many start-ups sought and achieved certification as C3PAOs.
On July 13, calling the CMMC level two third-party process a “bureaucratic barrier,” and an example of “red tape,” Pentagon CIO Kirsten Davies paused implementation and announced a reform task force to conduct a top-to-bottom review of the program, making it clear CMMC might not survive in its current form.
Self-attestation and government audits would continue in the meantime, she added, reminding contractors that the underlying requirement – to implement the 110 cybersecurity controls laid out in NIST Special Publication 800-171 – remained in force and only the third-party certification process was on hold.
Davies said she was seeking industry input through a request for information published by her office. Responses are due Aug. 14, but some have not waited for the deadline.
“Many of the contractors who heeded DoW’s call now feel betrayed,” wrote James Goepel, CEO and chairman of the CUI Institute, in a letter accompanying the institute’s comments on the program. He used the three letter abbreviation for Department of War, as the administration has rebranded the cabinet agency still legally titled the Department of Defense.
The CUI Institute, a Pennsylvania-based 501(c)(3) nonprofit educational organization which teaches defense contractors about CMMC requirements, noted in its comments that since the third-party assessment regime went live in January, “nearly 2000” defense contractors had paid approximately $50,000 each for a third-party certification, in order to get ahead of CMMC requirements, which were scheduled to come into force in November. The institute is named for controlled unclassified information, the category of government data the NIST 800-171 controls are designed to protect.
“It’s not just the C3PAOs that have been rug-pulled,” said the former defense official, pointing out that contractors that had invested in compliance ahead of the requirement now felt cheated.
“There is this sense of frustration” on the part of those early adopters, explained Kate Growley, a partner at legal powerhouse Crowell and Moring, specializing in cybersecurity, especially for the defense sector.
These companies had “invested aggressively and did the preparation,” to meet the NIST standard and get third-party certification before it was actually required and many of them now felt that they were being punished for that, she said.
“I think a lot of them feel that there was an expectation set [by the rulemaking] that this [certification] would be a requirement to stay in the defense supply chain,” Growley said, giving them a head start over competitors.
The cost of assessment and certification varied, depending on the size and complexity of the IT networks that were in scope, Growley said, agreeing that $50,000 was a reasonable median, especially for a small- and medium-business. But that number didn’t include the cost of compliance with the NIST controls in the first place, or the costs of preparing for the assessment, which itself could run from $10,000 to $20,000.
Early adopters of the CMMC now face a dilemma whether to maintain their investment, at some ongoing expense, or save the money and allow it to atrophy, she added.
That dilemma is a result of the fact that the defense contracting system does not incentivize security investments, argued the CUI Institute in their comments, echoing the views of veteran security experts.
“DoW procurement policies have, for decades, discouraged contractors from investing in information security unless those investments provide a competitive advantage,” the comments said. “DoW’s traditional ‘best value’ procurement approach neither rewards implementation of NIST SP 800-171 nor recognizes the associated costs, effectively disadvantaging contractors that make those investments.”
The CMMC pause came out of the blue, from industry’s point of view, Growley said. Such a major announcement would typically have been preceded by “a lot of unofficial, and sometimes official, dialog” with stakeholders.
That didn’t appear to have happened in this case, she said. “From what we have heard and seen ourselves, that dialog may not have been as robust as we would have expected, and that was one of the reasons why so many people were caught off guard.”
There was also a wary sense of deja vu, said Travis: CMMC had been paused before. After the program was initially launched in 2019, during the first Trump administration; the Biden administration hit the pause button in March 2021.
“A 60-day review, that turned into a six-month review and then turned into three years of rulemaking,” said Travis of the Biden administration pause, which resulted in a CMMC version 2.0. The final rules implementing CMMC 2.0 were published in October 2024 and September 2025, and there is concern among contractors that the administration might unpick that yet again, necessitating more delays.
“Markets don’t like uncertainty,” Travis pointed out. “So what is the effect of this? [Companies] might start to think, ‘Well maybe the department’s not committed to this program that eight months ago they seem committed to.'”
The Cyber AB will submit comments to the RFI, Travis said. “The one principle that we certainly want to make sure is respected and protected is the role of the third party.” There had to be some middle ground between self-attestation and randomized government audits on a small percentage of level three contractors, he said. Third-party certification is the best way to “assure confidence in the security of the supply chain.”
As to who should be covered by the third-party requirement and how certification would be implemented, “We are certainly open to turning those dials in terms of who needs to be assessed by a third party, what needs to be looked at and the structure of all that,” Travis said.
He added that Davies had talked about how CMMC, and its underlying standards, didn’t cover operational technology and didn’t address resiliency, so he expected those issues to come up in the reform conversation.
“I think it’ll be interesting,” he said, adding, “We’ve got a good connection into the department through the program management office and the office of the CIO.” He hoped that the C3PAO community and the broader DIB would “have a role in providing inputs and ideas on how the program can be improved.”
He said Davies had already been meeting with C3PAOs. “I do get a sense that there is going to be an open dialog, which is encouraging,” he told ISMG.
Another objective of Cyber AB’s comments to the RFI, Travis said, will be to combat misinformation he said was circulating. It was “an opportunity to make sure that there’s accurate information out here about the current state of the program in terms of how C3PAOs have been accredited and how many CCAs, and how many assessments have been conducted,” he said.
Numbers released by the Cyber AB show they certified just over 100 C3PAO organizations. But the assessments are actually carried out by individual CCAs and lead CCAs, and the board had certified almost 1,000 of them.
CMMC expert Jacob Horne used these numbers to pour scorn on DOD CIO Davies’ assertion that, “The math just simply doesn’t math,” when it came to third-party assessments, which she said would be required by 100,000 companies as part of their level two certification.
If almost 1,000 CCAs had been working even at 50% of their capacity, more than 3,000 companies would have been certified by July 13, Horne said.
The fact that only just over 1,700 had actually been certified, showed that the bottleneck was not assessment capacity, but rather contractor readiness. He said anyone who wanted could get an assessment just by telephoning a C3PAO. “Call them and ask,” he wrote on LinkedIn, “I’ll wait.”
“‘Not enough assessors’ is what people say when they haven’t looked at the data, don’t understand what the phased roll-out is and/or want to cover for their lack of assessment readiness,” Horne added.
“‘There aren’t enough CMMC assessors’ is a big fat lie,” he said.
Growley added that a reason contractor readiness has formed a bottleneck was that, on the ground, the certification process turned out to be more involved than people had anticipated. Because the program gives third-party assessors so much discretion in how they measure companies’ compliance with the NIST 800-171 security controls, she said, “a lot of contractors, as they would describe it [chose to] over prepare.”
Contractors wanted to be sure they had every piece of evidence the assessor might ask for, Growley explained, and “That prompted them to often do some pretty exhaustive preparations that was sometimes viewed as ‘assessment theater,’ and created a lot of excessive costs in the preparation process.”
