The Cyber AB laid out its case for preserving third-party certification in the Cybersecurity Maturity Model Certification program during its August CMMC town hall Tuesday. It summarized public responses to the Department of War’s reform request for information and detailed its own recommendations.
The department’s CMMC Reform Task Force request for information closed Aug. 14. It drew responses from companies, trade associations and individuals, Cyber AB CEO Matthew Travis told members. The task force is reviewing the program after the department paused CMMC phase two in July and ordered a 60-day review.
Travis said the most frequently cited burdens in the public responses centered on specific NIST 800-171 Revision 2 requirements: FIPS-validated cryptography, media sanitization and physical destruction, media marking and labeling, and audit log management. Respondents also urged the department to prioritize which Level 2 contracts actually need third-party certification. They asked the department to help small businesses with tax breaks or dedicated secure environments to meet the requirements.
Cyber AB’s recommendations
The Cyber AB posted its own response on its website Aug. 14. Among its recommendations, Travis said:
Keep third-party certification
Retain third-party certification as fundamental to the program. “That second C in CMMC, the program was created to add that third-party independent validation of conformity,” Travis said.
Travis pushed back on the idea that the program is bureaucratic. He noted that CMMC is private sector-led and that the only required government interaction is uploading assessment data into the Enterprise Mission Assurance Support Service (eMASS). He also said more than 80% of authorized and accredited assessment organizations are small businesses. They implemented the standard and passed their own assessments without being able to charge the cost back to a government contract.
Cut assessment team size
Give assessment organizations flexibility to field two assessors per team instead of the three currently required by Title 32 of the Code of Federal Regulations. That would free up certified assessors and lower certification costs.
Expand beyond CUI
Travis said the program is working, with Level 2 certifications issued over about 18 months. He argued CMMC could expand beyond safeguarding controlled unclassified information to cover operational technology. “It doesn’t mean it couldn’t be expanded to do other things like OT, and we would certainly support that,” Travis said.
Whatever reforms are adopted, Travis said, the transition plan must respect and retain the value of certifications already issued.
Other recommendations in the written response
The written response also recommends several changes Travis did not detail during the town hall:
- Ease background investigation requirements. The response asks the department to drop the requirement that all certified assessors and certified professionals undergo a Defense Counterintelligence and Security Agency Tier 3 background investigation, which it says has created a bottleneck in producing assessors. It suggests a commercially contracted background check could substitute.
- Allow continuous monitoring and “delta” assessments. The response argues that requiring a full new Level 2 assessment after any significant network change is expensive and discourages modernization, and asks the department to recognize companies that demonstrate continuous control monitoring.
- Recognize other accredited certifications. The response urges the department to accept reciprocity for other accreditation-backed cybersecurity certifications where controls meaningfully overlap, rather than re-proving them.
- Explore using artificial intelligence. The response says AI and automated tools could make assessments more efficient, while noting human judgment must remain the final authority under ISO/IEC rules.
- Eliminate CMMC Level 1. The response suggests the department could decide, from a risk-management perspective, that protecting federal contract information is not worth the cost of Level 1 compliance for small businesses.
Attorney: False Claims Act is no substitute for certification
Eric Crucius, an attorney with Hunton Andrews Kurth, told members his clients have been asking whether they should still pursue certification during the pause. His answer, he said, has been uniformly yes. Certification lowers security risk and reduces exposure to False Claims Act and whistleblower actions.
Asked whether enforcement lawsuits could substitute for certification, Crucius said no.
“There’s a reason why the department moved to third-party certifications a number of years ago, and that is because the threat of a False Claims Act suit … has not deterred companies from not being compliant,” Crucius said. He cited Defense Department inspector general reports. They found that every contractor examined was not complying with the underlying security controls.
Crucius also said he would not be surprised to see lawsuits if the department eliminates or significantly curtails third-party assessments. He argued that assessment organizations relied on the department’s rulemaking to set up their businesses and could claim damages. He said the premise for pausing phase two — including insufficient assessment capacity — “was based on an incorrect set of facts.”
On standards, Crucius said the department has limited flexibility to deviate from NIST 800-171. He urged it to move toward Revision 3 if the rest of the government does. He noted the Federal Acquisition Regulation controlled unclassified information rule is expected by the end of the year as part of the FAR overhaul.
Ecosystem updates
Jessica Morin, now CEO of conference organizing partner Form Makers, said CS5 East is set for October at National Harbor, with more than 430 people registered. Pre-conference training for certified CMMC professionals and assessors, an executive leadership class and a golf tournament are planned. Speaker and roundtable facilitator invitations go out this week. Volunteer applications close Monday.
Todd Gagnon, executive director of CAICO, the Cybersecurity Assessor and Instructor Certification Organization, said a listening session with department officials scheduled for Thursday had already hit its 1,000-registration capacity. He said the CMMC workforce continues to grow steadily. A survey of the more than 2,000 certified workforce members will go out within the week.
Mike Snyder of the Cyber Engagement Forum said Bridget Wilson has joined as director of ecosystem engagement. He said practitioner councils and committees are beginning to meet, with sessions planned every week to two weeks.
Q&A highlights
During the question-and-answer session, Travis said FedRAMP 20X is not currently considered to meet the FedRAMP moderate equivalency requirement in the DFARS 252.204-7012 clause. He relayed the Pentagon’s position that equivalency requires meeting all moderate baseline security requirements.
Travis also said the Cyber AB is continuing to hire and grow despite the pause. He said it has seen no withdrawals among candidate assessment organizations. He said there are no plans to change the certification fee model, but the organization would revisit it if program changes require.
The next town hall is scheduled for 6 p.m. Eastern time Sept. 29. Travis said the organization would hold a pop-up session before then if the task force releases recommendations.