{"id":770338,"date":"2026-07-18T14:16:13","date_gmt":"2026-07-18T14:16:13","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/770338\/"},"modified":"2026-07-18T14:16:13","modified_gmt":"2026-07-18T14:16:13","slug":"dod-plans-cmmc-listening-sessions-as-questions-swirl-around-review","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/770338\/","title":{"rendered":"DoD plans CMMC listening sessions as questions swirl around review"},"content":{"rendered":"<p>The Pentagon wants to move quickly with its review of the Cybersecurity Maturity Model Certification program, but plenty of questions swirl around what defense officials can do differently this time to balance compliance concerns for small businesses with the need to enforce cybersecurity requirements.<\/p>\n<p>The CMMC review team met for the first time on Thursday, July 16, Defense Department Chief Information Officer Kirsten Davies told reporters that same day following a tour of the factory floor at Kform, a small defense manufacturer based in Sterling, Va.<\/p>\n<p>Davies was joined on the tour by Small Business Administrator Kelly Loeffler and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey.<\/p>\n<p>Davies said small business considerations were central in the decision to <a href=\"https:\/\/federalnewsnetwork.com\/cybersecurity\/2026\/07\/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program\/\" rel=\"nofollow noopener\" target=\"_blank\">suspend CMMC third-party assessment requirements<\/a> and launch a \u201ctop-to-bottom\u201d review of the program. The goal is to address cost and compliance concerns that Davies, Loeffler and Duffey said are creating barriers for smaller companies to compete for defense contracts.<\/p>\n<p>]]><\/p>\n<p>\u201cWe took this action because data, including the reports from the Small Business Administration, makes one thing very clear: our planned compliance requirements progression was creating prohibitive costs and unacceptable burdens to the defense industrial base,\u201d Davies said.<\/p>\n<p>DoD has published <a href=\"https:\/\/sam.gov\/workspace\/contract\/opp\/89ef9bfb0834473791e991c712698d94\/view\" rel=\"nofollow noopener\" target=\"_blank\">a request for information<\/a> on the CMMC review. And officials will also hold listening sessions across the country to get feedback from defense contractors, \u201cespecially the small businesses, and from the cybersecurity operators and executives who serve your companies,\u201d Davies said.<\/p>\n<p>\u201cWe want to hear back from the defense industrial base, we want to hear back even from Cyber [Accreditation Body], from the assessors themselves, to hear what their ideas are for how to again increase and uplift cybersecurity and operational resiliency, but also improve the speed, the innovation, and the delivery of the capabilities to the warfighters,\u201d she said.<\/p>\n<p>Davies said the review team has 60 days to gather feedback and review the program, then 15 days to provide a report with recommendations to herself and Duffey.<\/p>\n<p>That timeline would see the CMMC review finalized by late September.<\/p>\n<p>\u201cWe\u2019re hoping shortly thereafter that we\u2019ll be able to make that report public along with the recommendations,\u201d Davies said.<\/p>\n<p>During the review, DoD has suspended CMMC third-party assessment requirements that were on track to become standard in many defense contracts starting Nov. 10.<\/p>\n<p>]]><\/p>\n<p>Davies and other officials over the past week have been highly critical of CMMC\u2019s third-party assessment approach. She called CMMC assessments a \u201cburdensome, red-tape ridden, check-the-box, point-in-time view of a company\u2019s handling\u201d of sensitive data.<\/p>\n<p>But Davies did not say whether the review would get rid of third-party assessments altogether.<\/p>\n<p>\u201cIt could include everything from an overhaul to small tweaks here and there,\u201d she said. \u201cBut what we\u2019re not going to do is death by a thousand cuts and just change for the sake of change. We are going to listen to what the defense industrial base has to say, especially small and innovative companies. And we are going to incorporate the voice of small companies to make sure that we are truly reducing barriers to entry for them to do business with [DoD].\u201d<\/p>\n<p>To support the ongoing suspension, Duffey issued a <a href=\"https:\/\/dowcio.war.gov\/Portals\/0\/Documents\/Library\/ImplementingSuspensionCMMC-PhaseII.pdf\" rel=\"nofollow noopener\" target=\"_blank\">memo<\/a> directing program officers to remove any CMMC third-party certification requirements from active solicitations.<\/p>\n<p>And if the department does decide to overhaul the program following the review, officials could use class deviations or interim rules to quickly change direction, according to Sandeep Kathuria, a partner at the law firm Saul Ewing.<\/p>\n<p>\u201cWe have seen in many areas that this administration can move very quickly to make regulatory changes,\u201d Kathuria said.<\/p>\n<p>D\u00e9j\u00e0 review<\/p>\n<p>DoD first began developing the CMMC program in 2019, during the first Trump administration, to verify compliance with existing cybersecurity requirements. Inspector general audits and other reports had found defense contractors were falsely self-attesting to meeting the requirements.<\/p>\n<p>\u201cThe rulemaking is largely based on the fact that the self attestations were not working, and proof of that were the significant cybersecurity incidents that the department has been a victim of through various nation state actors,\u201d Eric Crusius, partner and government contracts practice chair at Hunton Andrews Kurth, told Federal News Network.<\/p>\n<p>The latest CMMC review comes five years after the Biden administration launched its own review of the program, which was <a href=\"https:\/\/federalnewsnetwork.com\/cybersecurity\/2021\/06\/pentagon-cmmc-review-aims-to-address-small-biz-cost-concerns-restore-trust-in-assessment-processes\/\" rel=\"nofollow noopener\" target=\"_blank\">also motivated in large part by small business compliance concerns.<\/a><\/p>\n<p>]]><\/p>\n<p>The outcome of that review was to simplify the CMMC standards and <a href=\"https:\/\/federalnewsnetwork.com\/defense-main\/2021\/11\/pentagon-strips-down-cmmc-program-to-streamline-industry-cyber-assessments\/\" rel=\"nofollow noopener\" target=\"_blank\">reduce the number of companies that would require a third-party certification.<\/a> DoD officials called the revised program \u201cCMMC 2.0.\u201d<\/p>\n<p>DoD finalized the CMMC 2.0 program rule in 2024 and the associated <a href=\"https:\/\/www.acquisition.gov\/dfars\/252.204-7021-contractor-compliance-cybersecurity-maturity-model-certification-level-requirements.\" rel=\"nofollow noopener\" target=\"_blank\">contracting rules<\/a> last year. DoD was phasing in the new requirements, starting with CMMC self assessments. But voluntary third-party assessments started picking up steam last year, while some DoD program offices have also elected to include the \u201clevel two\u201d CMMC third-party assessment requirements in their solicitations this year.<\/p>\n<p>According to the <a href=\"https:\/\/cyberab.org\/News-Events\/Press-Releases\/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements#!\" rel=\"nofollow noopener\" target=\"_blank\">Cyber AB,<\/a> \u201cnearly 2,000\u201d defense contractors have been certified at CMMC level two.<\/p>\n<p>During the ongoing review, DoD is still enforcing the requirements for CMMC self-assessments. And DoD is not changing associated requirements for contractors to secure data in line with National Institute of Standards and Technology controls for protecting controlled unclassified information (CUI).<\/p>\n<p>Davies also emphasized that DoD can still step in and evaluate a contractor\u2019s cyber compliance through its Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).<\/p>\n<p>She also pointed to the cybersecurity services that are available to defense contractors through the National Security Agency\u2019s Cybersecurity Director, as well as <a href=\"https:\/\/www.dc3.mil\/About-DC3\/Capabilities-and-Services\/\" rel=\"nofollow noopener\" target=\"_blank\">services<\/a> provided by DoD\u2019s Cyber Crime Center<\/p>\n<p>\u201cWe need to be thinking much more creatively, cleverly, and holistically at how we support vendors, contractors, and DIB companies who supply for us, who produce for us,\u201d Davies said.<\/p>\n<p>But the services provided today by the NSA and DC3, respectively, only meet a small portion of the required NIST controls.<\/p>\n<p>And DoD established the Cyber AB and its network of CMMC third-party assessment organizations (C3PAOs) because the department itself doesn\u2019t have the capacity to audit tens of thousands of defense contractors.<\/p>\n<p>\u201cIf DoD concluded that it was in the DIB\u2019s best interest to rely more heavily on self-assessments than the original CMMC 2.0 had envisioned, it would be a notable return to the original system that the department said was insufficient, and that necessitated the creation of CMMC 1.0 under the first Trump administration,\u201d Kate Growley, a partner at the law firm Crowell &amp; Moring, told Federal News Network.<\/p>\n<p>In the absence of third-party assessments, DoD has relied on a limited number of reviews by DIBCAC and the Justice Department\u2019s <a href=\"https:\/\/www.akingump.com\/en\/insights\/alerts\/top-doj-false-claims-act-official-confirms-significant-upward-trajectory-in-cybersecurity-enforcement\" rel=\"nofollow noopener\" target=\"_blank\">expanding enforcement<\/a> of cyber standards using the False Claims Act (FCA).<\/p>\n<p>As DoD forges ahead with the self-assessment requirement, Growley said contractors should be aware of the legal risks.<\/p>\n<p>\u201cAny time where you are relying on your own assessment and representation instead of one of an accredited third party \u2014 which the DoD has stood up an entire ecosystem to create assurances around the evaluation and the reliability of that third party \u2014 that will create FCA risk for contractors who are misrepresenting what that score should be because they are relying on the self-assessment methodology,\u201d Growley said.<\/p>\n<p>Costs, assessor capacity<\/p>\n<p>Pentagon officials are pointing to CMMC compliance costs and assessor capacity as key barriers for small businesses. But those figures are likely to be debated as DoD\u2019s review unfolds.<\/p>\n<p>For instance, Davies said the program is constrained by a \u201csevere shortage of third-party assessors.\u201d<\/p>\n<p>But the Cyber AB, the nonprofit organization that has a DoD contract to oversee C3PAOs and other parts of the CMMC \u201cecosystem,\u201d has been <a href=\"https:\/\/federalnewsnetwork.com\/it-modernization\/2025\/12\/cyber-accreditation-bodys-matt-travis-on-scaling-the-cmmc-ecosystem\/\" rel=\"nofollow noopener\" target=\"_blank\">working to build assessor capacity for years.<\/a><\/p>\n<p>In a <a href=\"https:\/\/cyberab.org\/News-Events\/Press-Releases\/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements#!\" rel=\"nofollow noopener\" target=\"_blank\">statement<\/a> released by the Cyber AB this week, chief executive Matthew Travis said the group is \u201cboth surprised and disappointed in yet another momentary pause to this original and vital Trump administration program.\u201d<\/p>\n<p>But he added that the Cyber AB is \u201cconfident that the continued and measurable progress of CMMC, the immense investment that companies throughout the DIB and within the CMMC ecosystem have already made in its future, and the absolute criticality of third-party verification of cybersecurity conformity will prove itself indispensable under a rigorous review.\u201d<\/p>\n<p>According to the Cyber AB, the program now has \u201cover 1,000\u201d CMMC certified assessors, who are responsible for carrying out the third-party audits.<\/p>\n<p>Last year, Travis said the program likely needs between 2,000 and 3,0000 certified assessors to meet the demand for CMMC to be fully implemented across all applicable defense contracts, which DoD projected would not happen until late 2028.<\/p>\n<p>Trump administration officials have also pointed to burdensome costs on small businesses. For instance, Loeffler said CMMC compliance costs \u201cexceeding half a million dollars\u201d were driving small firms out of the defense industrial base.<\/p>\n<p>But Crusius said many people have conflated the costs of implementing the required NIST cybersecurity controls with CMMC certification costs. He <a href=\"https:\/\/www.hunton.com\/government-contracts-intelligence-briefing\/dow-suspends-cmmc-phase-ii-nist-sp-800-171-self-assessment-becomes-the-interim-standard-with-rising-false-claims-act-exposure\" rel=\"nofollow noopener\" target=\"_blank\">pointed<\/a> to DoD\u2019s estimate that a level two C3PAO assessment would cost $105,000.<\/p>\n<p>\u201cThe industry has been gearing up for this for quite a few years now, and while there have been complaints about cost and capacity, those complaints have largely been satisfied with how this program has performed over the last nine months or so,\u201d Crusius said. \u201cThere have been more assessments completed than were anticipated in the rulemaking, and there are a lot of C3PAOs that offer fairly cost-effective assessments, especially in instances where small businesses have small environments where they don\u2019t really need to have an expansive assessment done across their whole organization.\u201d<\/p>\n<p class=\"article-copyright\">Copyright<br \/>\n                            \u00a9\u00a02026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.\n                    <\/p>\n","protected":false},"excerpt":{"rendered":"The Pentagon wants to move quickly with its review of the Cybersecurity Maturity Model Certification program, but plenty&hellip;\n","protected":false},"author":2,"featured_media":761440,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[28,328797,325973,328798,328799,127684,325974,289012,328800,130743],"class_list":["post-770338","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-business","tag-cyber-accreditation-body","tag-cybersecurity-maturity-model-certification","tag-eric-crusius","tag-kate-growley","tag-kelly-loeffler","tag-kirsten-davies","tag-michael-duffey","tag-sandeep-kathuria","tag-small-business-administration"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/770338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=770338"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/770338\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/761440"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=770338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=770338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=770338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}