The Cyber AB used its September town hall Sept. 29 to speculate — heavily and repeatedly disclaimed — on what a reformed “CMMC 3.0” might look like, while confirming the program is not paused and celebrating a milestone: the first non-U.S. certified third-party assessment organization, authorized from Taiwan.
CEO Matthew Travis and Cyber EF acting executive director Mike Snyder stressed that their discussion reflected no inside information from the department’s CMMC Reform Task Force, whose report remains unreleased. “We do know that change is coming,” Travis said.
Program status: not paused, and still growing
Travis repeated a standing correction for newcomers: “The CMMC program is not paused.” He cited continued growth in certifications: more than 2,300 Level 2 certificates of CMMC status issued, up 12% from August, and 71 conditional certificates, up 7%.
He also shared results from an ISC2 survey of defense industrial base companies. Among respondents, 68% are continuing CMMC-related work despite the uncertainty. Another 34% reallocated time to other projects and 26% delayed or canceled assessment preparation.
In what Travis called a landmark announcement, the Cyber AB authorized the first non-U.S. C3PAO, from Taiwan. He declined to name the company to avoid showing favoritism, and the listing was still processing in the Cyber AB Marketplace at the time of the event.
What the department seems to want
Travis framed the fireside chat with Snyder around signals from department officials, particularly Kirsten Davies, the Department of War’s chief information officer. Themes they identified:
- Industrial resiliency and supply chain agility — ensuring the defense industrial base can keep supplying warfighters even under attack, rather than focusing solely on protecting controlled unclassified information.
- Operational technology — OT is unaccounted for in the current iteration of CMMC. Snyder pointed to breaches in manufacturing through shop-floor controllers, and to adversaries reverse-engineering firmware updates to identify vulnerable equipment.
- Continuous validation — moving away from the point-in-time nature of conformity assessment toward ongoing monitoring, potentially with a role for AI.
- “Brilliant at the basics” — Snyder said the department’s priority list of fundamental IT and OT security practices crosswalks to much of NIST 800-171 and is likely a preview of what the department actually cares about.
- The cybersecurity risk management construct — the department’s internal replacement for the Risk Management Framework, which Snyder praised for its speed. He suggested the department may try to extend that continuous-risk approach to the private sector.
- NIST Cybersecurity Framework 2.0 — Snyder’s personal take, he cautioned: the framework could serve as the governance layer with CMMC or a data-security layer on top of it.
- Reciprocity — Travis noted department officials have expressed interest in giving advanced standing to existing frameworks and crosswalks.
The speculative list: what CMMC 3.0 might include
Both speakers stamped the remainder as doubly speculative.
Compliance as code. Snyder predicted machine-readable, STIG-like configuration guidance — possibly in OSCAL format and centrally maintained by DISA — so contractors are not “guessing” at how to meet a requirement.
A bigger role for DISA. Both said the agency appears positioned to do more, potentially serving as a central repository for continuously updated OSCAL content and, in some cases, providing telemetry analysis — Travis suggested that could apply to critical manufacturers, if not every contractor.
Changes to the C3PAO model. Travis speculated that assessors could take on red-teaming or pen-test validation roles. He also floated a hybrid assessment model: eyes-on validation of perhaps the top 20 to 40 controls aligned to department priorities, with the rest self-attested.
Partial assessment to cut costs. “Something’s got to give,” Travis said, noting a desire to lower certification costs. Snyder added he does not expect a major cost reduction so much as a reallocation of it — back on site, focusing on the critical controls — and possibly combining Level 2 and Level 3 work in a single visit.
Scoring changes. Snyder said he expects changes to SPRS scoring, on the theory that a company a third party has assessed is less of a risk than one that self-assessed. Travis said scoring may move toward a CMRS-style model, possibly with multiple scores.
FedRAMP and Revision 3. Travis called the relationship between FedRAMP and CMMC “fraught with some confusion and frustration,” and said it will have to be addressed. On NIST 800-171 Revision 3, he noted the program office had authored a draft transition rule before the task force pause, and said he expects any transition plan to include a grace period so existing Level 2 certificates retain their value.
Incentives instead of mandates. Travis suggested a future model might drop a Level 2 certification requirement from contracts but award extra points in solicitations to certified companies — “an incentive that would almost have the same effect as a regulatory contractual requirement,” and economically a better outcome for companies that invested in certification.
CAICO: renewal season and CPEs open Nov. 1
Todd Gagnon, director of CAICO, the Cybersecurity Assessor and Instructor Certification Organization, walked through the first calendar-year renewal cycle for CMMC certifications. The renewal window opens Nov. 1, when ISACA will notify certificate holders.
Key points:
- All CMMC certifications have been migrated to a Jan. 1 renewal cycle. Certifications due between April and December of this year were pushed to year-end.
- Certified professionals who certified before Jan. 1 of this year owe a minimum of 20 continuing professional education credits by Dec. 31. Anyone who certified this year owes none in 2026, with their three-year cycle starting next year.
- CPEs can be applied across multiple certifications held in the same ISACA profile. Most cybersecurity-related training, webinars and conferences qualify. Delta training counts for two CPEs.
- Only the CCP and CCA — the two ISO/IEC 17024-accredited certifications — require CPEs. LCCA status is maintained by holding the CCA.
- Guiding an organization toward Level 2 compliance as one’s normal job does not count for CPE credit.
Gagnon agreed with Travis that the assessor role is likely to change under program reform, which is partly why CAICO held off finalizing its continuing education program until now.
Ecosystem updates
Jessica Morin, CEO of conference organizing partner Forum Makers, said CS5 East is less than 30 days away — Oct. 22–23 at National Harbor — with more than 650 registered and attendance trending slightly above last year. Regular pricing ends Thursday at midnight. She reminded attendees that self-assessment to NIST 800-171 Rev. 2 is still required while the task force report is pending. The charity golf tournament benefiting Folds of Honor is Wednesday, Oct. 21, at the Country Club at Woodmore.
Snyder previewed Cyber AB Engagement Forum webinar tracks — one for OSCs, one for practitioners and one for the full ecosystem — and said the DIB Collective’s first OSC kickoff is Sept. 30, led by Allison Giddens. He also announced an ecosystem-wide webinar on AI for Oct. 15 and said a session on source code and CUI designations is planned after CS5 East.
Q&A highlights
- Rev. 3 transition: Travis said he would expect a grace period or grandfathering clause for companies certified under Revision 2, while stressing no guarantee exists until a transition plan is published. Snyder pointed to the FAR CUI rule as the direction the rest of government is moving.
- Authoritative sources: Asked whether the department CIO’s FAQ page is authoritative, Travis said the only authoritative sources are 32 CFR, NIST 800-171 and 800-171A; FAQs are reliable official guidance but “does not carry the weight of law.”
- Class deviation: On whether primes can recover the cost of requiring subcontractor C3PAO certifications after the July class deviation, Travis deferred to contracting officers, noting the deviation simply codified what officials announced July 13 — nothing more, nothing less.
- OT framework: Snyder speculated OT security would arrive as a separate layer rather than inside CMMC, with guidance drawing on NIST and CISA documentation.
The next town hall is Tuesday, Oct. 27. Travis said he hopes by then to be “talking about the changes of the program, but no guarantees.” Recordings of past town halls are available on the Cyber AB website.