PSC renews call for single cyber standard in CMMC reform comments
Seven years and multiple program pauses later, the trade group is still asking why a contractor serving both DoD and DHS faces two different sets of cybersecurity rules.
TL;DR
The Professional Services Council filed comments on the latest CMMC reform proposal, reiterating three longstanding concerns: inconsistent cybersecurity standards across federal agencies, the cost of demonstrating compliance versus actually improving security, and what happens to companies that already earned certifications under prior versions of the program. The consistency argument is the sharpest, a contractor serving both DoD and DHS faces different rules for fundamentally the same work, and PSC has been raising it since CMMC's inception.
The Professional Services Council's comments on the latest CMMC reform proposal landed last week, and if the arguments sound familiar, that's because they are. PSC has been making the same three points since the program's inception seven years ago. The persistence is the story.
The strongest of the three is consistency. A contractor doing cybersecurity work for both DoD and DHS answers to two different sets of rules. PSC president Stephanie Kostro put it plainly in an interview with Federal News Network: "doesn't it make sense to have common cybersecurity standards across the board?" It does, and the fact that the question still needs asking in 2026 says something about how the federal government approaches cybersecurity as an enterprise, which is to say, it doesn't.
The cost argument is legitimate but carries the weight of self-interest you'd expect from a trade association. PSC wants the government to "think through the costs it's imposing on companies" and distinguish between compliance activities and actual security improvements. Fair enough. But the line between necessary compliance cost and unnecessary paperwork burden is drawn differently depending on which side of the contract you're on.
The third argument is the most pragmatic for practitioners: what happens to companies that already earned CMMC certifications under prior program versions? Kostro's framing (that an existing certification "should be treated as an asset") will resonate with any contractor that spent months and significant money getting certified under an earlier rubric. If the reform invalidates or diminishes those certifications, the early movers get punished for moving early. That's the kind of signal that makes companies wait out the next program iteration rather than engaging with the current one.
PSC represents roughly 400 member companies, many of them technology firms that live or die on federal contracts. Its comments on CMMC are predictable in the best sense: the positions haven't changed because the underlying problems haven't changed. Whether this round of reform addresses them is the open question.
Published ·Updated ·Deep Fathom