ARLINGTON, VIRGINIA — Chief Information Officer Kirsten Davies formally announced the creation of the task force on a Monday, and the group held its first meeting on a Thursday at the Pentagon. The task force includes leadership from the Department of Defense directorates for acquisition and sustainment, intelligence and security, the Office of the CIO, general counsel, public affairs, and legislative affairs, along with participation from the Small Business Administration and the White House. The group will report to Davies' principal deputy.
Phase 2 CMMC requirements were scheduled to take effect on November 10 and would have required defense contractors to receive accreditation from a Certified Third-Party Assessor Organization to meet Level 2 CMMC compliance for contract awards. The Department of Defense also issued a request for information to solicit feedback from defense industrial base companies and assessment organizations. That request seeks input on the burden of CMMC compliance, existing commercial cyber solutions used to safeguard data, and how the department might recognize or accept these solutions within a compliance or risk framework. The task force said in a podcast interview it will use responses to the request for information to form its final recommendations on the CMMC program.
The review will examine the CMMC program through the lens of NIST framework requirements, DFARS requirements, and the cyber threat landscape. Despite the pause on Phase 2, Defense contractors must continue to self-attest to meeting NIST 800-171 Rev. 2 standards for handling controlled unclassified information during the pause. Phase 1 self-assessment obligations remain in effect during the pause, along with SPRS score submissions.
The DFARS requirement to protect controlled unclassified information remains fully in effect during the pause as well. The Department of Defense retains the ability to conduct in-person or documentation assessments of the defense industrial base based on contractual regulations.
Kirsten Davies stated the task force will have approximately 15 days after the 60-day period to synthesize recommendations and industry feedback. The CMMC Reform Task Force is scheduled to report recommendations by mid-September. Davies committed to making the task force report publicly available when ready. "We are going to listen to what the defense industrial base has to say, especially small and innovative companies, and we are going to incorporate the voice of small companies to make sure that we are truly reducing barriers to entry for them to do business with the department," Davies said.
The Cybersecurity Maturity Model Certification program was designed to ensure that defense contractors handling controlled unclassified information maintain adequate cybersecurity protections. With more than 100,000 companies in the defense industrial base and only approximately 100 authorized Certified Third-Party Assessor Organizations available, the bottleneck in assessor capacity raised concerns about whether the program could function as intended when Phase 2 went into effect. Defense officials cited concerns that compliance costs were pushing smaller firms out of the defense industrial base.
The 60-day pause provides time for the task force to gather industry feedback and examine whether the program's requirements align with the capacity of both the assessor ecosystem and the companies it regulates. The review will consider existing commercial cyber solutions and how they might be recognized within a compliance or risk framework, potentially offering alternatives to the current third-party assessment model.
Defense manufacturing contractor Kform in Sterling, Virginia, hosted a tour by Kirsten Davies, Undersecretary of Defense for Acquisition and Sustainment Michael Duffey, and Small Business Administration head Kelly Loeffler. Callye Keen, CEO of Kform, described the competing financial priorities faced by small manufacturers. Year after year, we have to make the decision: Do I buy another piece of equipment?
Do I invest in a robot? Do I hire another engineer? Or do I meet CMMC compliance, or yet another piece of compliance? Keen said.
Chris Nyhuis, CEO of Vigilant, expressed support for the Phase 2 suspension while noting the urgency of cybersecurity requirements. "Speed done securely is a security requirement now, not a nice-to-have," he said. "Our adversaries move in days." He described the timeline constraints imposed by the current third-party audit process and its impact on smaller suppliers. "When it takes a small defense supplier a year and six figures to clear a third-party audit before it can even bid, we're not protecting the mission, we're slowing it down," Nyhuis said.
forum Comments (0)
No comments yet. Be the first to comment.