cmmctrade-pressNewsThe Broadside2 min read

CMMC pause puts point-in-time assessments on the block

The pause leaves nearly 2,000 already-certified contractors wondering what their Level 2 certification is worth as DoD rethinks the point-in-time model.


TL;DR

The Defense Department has frozen new CMMC third-party assessment requirements and launched a reform task force, suspending the Phase 2 ramp that was scheduled to begin November 2026. Phase 1 self-assessment requirements remain in force, but the freeze leaves nearly 2,000 contractors holding Level 2 certifications uncertain about their status. Cyber AB CEO Matt Travis, in a Federal News Network interview, outlined reform proposals that include replacing point-in-time audits with continuous monitoring and reducing assessment teams from three assessors to two for smaller firms, changes he said could be implemented without new rulemaking.

CMMC pause puts point-in-time assessments on the block
Editorial illustration · drawn by The Broadside

DoD Chief Information Officer Kirsten Davies didn't mince words in her July 13 memo suspending Phase 2 of CMMC: the current program, she wrote, "imposes significant and often prohibitive burdens on the DIB, particularly the small and non-traditional businesses that are the engine of American innovation." That's a remarkable admission from the office that spent the better part of five years shepherding CMMC through two federal rulemakings. The reform task force Davies established is now collecting industry feedback on a replacement framework that would "replace prohibitive, third-party compliance models with scalable, realistic security measures." That language puts the point-in-time assessment model, the program's architectural centerpiece, squarely on the block.

Cyber AB CEO Matthew Travis, whose organization accredits the C3PAOs and assessors who conduct those certifications, told Federal News Network he sees reforms that wouldn't require new rulemaking. The biggest: replacing one-shot audits with continuous monitoring. Under the current rule, a contractor who modernizes its network post-certification must commission a full new assessment. There's no delta-assessment mechanism. "FedRAMP has it," Travis said. "I think CMMC should look at that as well." He also wants DoD to reconsider the three-assessor requirement. Well-organized smaller firms relying on knowledgeable MSPs or MSSPs, he argued, don't need three people on site. Cutting to two assessors for those engagements would reduce the cost passed through to contractors.

The assessor pipeline itself is part of the problem. Mandatory training and background investigations have created a backlog that's constraining the labor pool. More assessors means more supply and lower costs, but Travis says the background-check process needs streamlining to get there.

Travis also flagged the "fraught" relationship between CMMC and FedRAMP as a persistent source of confusion for defense contractors trying to meet NIST standards. The same problem extends to CUI marking. Federal News Network reported in August that industry groups identified DoD's inconsistent marking practices as the single biggest cost driver in the program. When contractors can't reliably determine what's CUI, they tend to over-scope their compliance boundaries, turning a targeted security requirement into a blanket expense.

The most urgent open question is what happens to the roughly 2,000 contractors who already hold Level 2 certifications. "I would hate to see an environment where companies who did the right thing, who followed the guidance of the department, got certified at Level 2, and now realize that may not be worth what I thought it was worth," Travis said. He called for a transition plan that preserves the value of existing certifications through reciprocity or standards acceptance. That commitment hasn't been made. In the meantime, Phase 1 self-assessment requirements remain in force, and new certifications continue. But for anyone mid-audit or preparing for one, the ground has shifted.


Published ·Deep Fathom