CMMC's architects make the case for pressing on
Two of the program's builders argue the threat hasn't paused, and neither have the contractors who've already decided the July suspension means they can stop spending.
TL;DR
Stacy Bostjanick and Tara Lemieux, both central to CMMC's development and now at Cybersec Investment, published an opinion piece in Federal News Network arguing the Pentagon's July 2026 phase-two suspension shouldn't be read as permission to abandon compliance. They point to real DIB breach cases as the cost of inaction, cite $20,000, $50,000 in annual sunk compliance investment by small firms, and warn that contractors publicly posting on Reddit that they've halted spending are betting wrong on the direction of the review. The piece is advocacy from the compliance community, not a DoD signal, but with the 60-day review window launched July 13 now closing, the argument lands while the program's fate is genuinely unsettled.

The op-ed (bylined by Stacy Bostjanick, former chief of DIB cybersecurity at DoD and a central figure in CMMC's rulemaking, and Tara Lemieux, a lead CMMC certified assessor) makes a straightforward case dressed in warfighter rhetoric: the cyber threat to the defense supply chain isn't on pause just because the Pentagon's third-party assessment ramp-up is. Both authors now work at Cybersec Investment, a firm whose services portfolio includes CMMC readiness. That doesn't invalidate the argument, but it does locate it.
What makes the piece more than a generic "don't roll it back" plea is its acknowledgment of the program's actual moment. The authors concede CMMC has been "an essential but imperfect journey" from the start, that the shift from NIST SP 800-53 to 800-171 was itself a compromise, and that unnecessary cost and complexity "should absolutely be removed." They're not defending the program as-is. They're defending the validation layer.
That distinction matters because it mirrors where the reform conversation has actually landed. An August FNN report on the CMMC Reform Task Force found widespread agreement that DoD's inconsistent CUI marking is a core cost driver, not the assessment requirement itself. Multiple industry groups and the SBA Office of Advocacy flagged CUI uncertainty as the most frequently cited small-business concern. The op-ed doesn't address that directly, but its framing (keep the validation, fix what's broken around it) is broadly aligned with the task force's incoming comments.
What the piece doesn't do is settle the question contractors are actually asking
The op-ed cites contractors posting on Reddit that they're abandoning compliance efforts post-suspension. It's an anecdote, but it tracks. Eric Crusius, a partner at Hunton Andrews Kurth, told FNN in July that some contractors incorrectly read the headlines as a freeze on all cybersecurity obligations. They're not frozen. Phase one self-assessments remain in force. The underlying 800-171 controls remain contractually required under existing clauses.
The piece's weakness is its treatment of the July 13 Davies memo. The authors frame the review as a debate over cost versus security. The memo actually went further: it described the current CMMC program as "structurally incompatible" with expanding the DIB and cited SBA cost concerns as a reason for the top-to-bottom review. That's a more existential framing than the op-ed acknowledges.
For the practitioner, the op-ed changes nothing operationally. The controls you're already obligated to implement under 800-171 haven't gone anywhere. But the question of whether to keep spending on a third-party assessment pathway that may not survive the review, that question is real, and the op-ed doesn't answer it so much as argue the stakes of getting it wrong.
Published ·Deep Fathom