
July 2026 Cyber AB Town Hall Recap: The CMMC Reform Task Force, DoW RFI, and What Comes Next
The July Cyber AB Town Hall was dominated by one topic: the Department of War's July 13 announcement pausing Phase 2 of CMMC implementation and launching a comprehensive review of the program. Matt Travis and the Cyber AB team spent the bulk of the session explaining what the announcement means, what remains in effect, and how the Reform Task Force is structured. The session also included an industry panel of certified OSCs sharing their perspectives, a CAICO update, and a Q&A covering a range of questions from attendees within the ecosystem.
The July 13 DoW policy announcement
On July 13, 2026, DoW Chief Information Officer Kirsten Davies and Undersecretary for Acquisition and Sustainment Michael Duffey jointly announced a major policy change to the CMMC program.
The announcement included two primary actions:
Immediate Pause of CMMC Phase 2 requirements. The Phase 2 requirements, which had been scheduled to take effect on November 10, 2026, have been paused indefinitely. This includes revocation of pending Phase 1 Level 2 C3PAO certification requirements that had already been incorporated into some solicitations.
Launch of a comprehensive review of the CMMC program. The review is aimed at aligning the program with Secretary Hegseth's "Arsenal of Freedom" initiative. As part of the review, the DoW commissioned the CMMC Reform Task Force and released a public Request for Information (RFI) soliciting industry input on the program.



The Cyber AB emphasized that the CMMC program itself has not been paused. What's on hold are the Phase 2 contractual requirements. The following remain in effect and operational as of the July Town Hall:
- DFARS 7012 requirements remain in force. Organizations with DFARS 7012 in their contracts are still required to conform to NIST SP 800-171.
- C3PAOs are still conducting Level 2 certification assessments.
- CMMC eMASS and SPRS are still processing Level 2 certifications.
- The CMMC Program Office (PMO) remains staffed and operational.
- DIBCAC continues to assess candidate and authorized C3PAOs, as well as OSCs.
- DCSA is still conducting Tier 3 background investigations and FOCI screening.
- RPOs continue to support 800-171 implementation and CMMC preparation.
- CAICO and Approved Training Providers continue operating without interruption.
Travis also noted that existing Level 2 certifications should be unaffected by the pause and that there is no expected change to their three-year validity period, based on information available at the time of the Town Hall.
The CMMC Reform Task Force
The DoW's Office of the Chief Information Officer (OCIO) has commissioned a Reform Task Force charged with analyzing industry responses to the RFI and developing CMMC reform recommendations. Acting Deputy CIO J. Aaron Bishop will lead the task force.
The task force has a 60-day mandate to conduct its review, followed by approximately 15 days to write up recommendations for Davies and Duffey. Based on those timelines, Travis estimated that recommendations could be expected by early October 2026, assuming the process proceeds on schedule.
The task force is structured in four tiers:

Travis noted that the Cyber AB has been informed it will be invited to participate in Tier 4, though formal contact had not yet been made as of the Town Hall. He also stated that Davies has indicated she is willing to let the task force and industry do their work, and that nothing in the review is pre-determined.
The Cyber AB, along with the CyberEF, confirmed they will both be responding to the RFI and will make their responses public, consistent with how they handled public comments during the 32 CFR and 48 CFR rulemaking processes.
Likely drivers behind the reform, as presented by the Cyber AB
Travis shared the Cyber AB's understanding of the concerns driving the reform review. He was clear that these represent the Cyber AB's interpretation of what it is hearing from Pentagon, SBA, and other officials, and do not represent official DoW positions. The drivers as presented include:

Travis noted that several of these drivers reflect a broader goal of making the DIB faster and more productive, consistent with themes from the Secretary of Defense's office, rather than concerns specific to the CMMC program itself.
The legal context: CUI governance and the 2020 NDAA
Travis provided context on two aspects of the legal landscape that will shape what the Reform Task Force can recommend.
CUI governance structure
CUI requirements originate from Presidential Executive Order 13556, signed in 2010, which charges the executive branch with safeguarding CUI. The National Archives and Records Administration (NARA) serves as the executive agent and charges NIST with authoring the technical standard for CUI safeguarding, which is NIST SP 800-171. Executive branch agencies enforce that standard through DFARS and the FAR. Travis noted this context as relevant to discussions about changing the underlying standard.
The 2020 NDAA
Section 1648 of the FY2020 National Defense Authorization Act tasked the Secretary of Defense with developing a consistent framework to enhance the cybersecurity of the defense industrial base. That framework is explicitly required to include a process for third-party independent assessment and certification of compliance. Travis noted that this provision remains public law and has not been amended or withdrawn by Congress. He indicated the Cyber AB views this as relevant to the task force's consideration of any recommendations regarding third-party certification requirements.

Industry panel: OSC perspectives on the Phase 2 pause
Mike Snyder of the CyberEF moderated a panel of three certified OSCs sharing their perspectives on how the July 13 announcement is affecting their organizations and supply chains.
- Amanda Webb, Information Systems Security and Compliance Officer at Level 1 Fasteners: Webb noted that many of her organization's suppliers and vendors have not yet achieved CMMC certification, and that the pause may provide some additional time for those companies to get ready.
- Whitney Palacios, CISO, VP Cybersecurity at BigBear.ai: Palacios noted that from a security standpoint, nothing about her organization's posture has changed, because the core obligation to secure systems and data under DFARS 7012 are still in effect. She also noted that prime contractors and government customers continue to ask about CMMC compliance status despite the pause, suggesting that demand signal for certification has not disappeared.
- Alison Giddens, President of Operations at Win-Tech, Inc.: Giddens noted that DFARS 7012 and NIST 800-171 flowdown obligations have not changed, and she has begun pushing back up the chain for clarification on CUI markings rather than assuming her sub-tiers are managing their obligations correctly.
A note on terminology: "CMMC Implementation"
Travis revisited a recurring terminology issue, flagging "CMMC implementation" as an inaccurate phrase that continues to circulate in the ecosystem. The Cyber AB's position is that there is no such thing as "CMMC implementation." Defense contractors implement the security requirements of NIST SP 800-171. CMMC is strictly the verification mechanism for conformity to that standard. The costs of implementing 800-171 are separate from the costs of hiring a C3PAO and preparing for certification, and conflating them leads to inaccurate representations of what CMMC actually requires.

CMMC ecosystem growth
The CMMC ecosystem continues to grow. Assessment capacity remains available and that the program's infrastructure is intact.


CAICO updates
Todd Gagnon confirmed that CAICO is continuing all operations without change. Training, certification exams, and applications through ISACA remain fully available. All Approved Training Providers are continuing to offer CCP and CCA training.
As of the July Town Hall, 73 CCIs have been fully credentialed, with 21 applications still in process. Gagnon noted that CAICO is prepared to adjust content and skill sets if the task force's recommendations result in changes to the program.
Q&A highlights
Several questions from the session and the live Q&A chat are worth noting for DIB contractors and members of the ecosystem.
How can prime contractors verify that a subcontractor's Level 2 certification is legitimate? The Cyber AB's recommended method is to request a SPRS PDF export directly from the subcontractor. This provides a verifiable record of their entry in SPRS.
Do subcontractors still need CMMC Level 2 self-assessments? Yes. Subcontractors with DFARS 7012 in their contracts are still required to complete a CMMC Level 2 self-assessment. The pause applies to C3PAO certification contractual requirements, not to the underlying NIST SP 800-171 conformity obligation or self-assessment requirements.
Does FedRAMP 20x meet CMMC or DFARS 7012 requirements? No. Travis confirmed that FedRAMP 20x does not currently meet CMMC or DFARS 7012 requirements. He noted that the topic is under active discussion within the DoW, and that written guidance to C3PAOs is expected to follow. FedRAMP Rev 4 and Rev 5 remain the accepted standards, though those authorizations are expected to sunset at the end of the calendar year. Travis anticipated that updated FedRAMP policy, including potentially an updated FedRAMP Moderate Equivalency policy, would be in place by that time.
Will existing C3PAO certifications be grandfathered? Based on information available at the time of the Town Hall, existing certifications should not be affected. No change to the three-year validity period is expected.
Should CCP and CCA candidates continue pursuing certification? Yes. Both Travis and Gagnon confirmed there is no reason to pause pursuing CCP or CCA certification. If the task force's recommendations result in program changes, CAICO will adjust accordingly.
What is the status of the OSC certification badge or emblem? Steve Medellin confirmed via the chat that the Cyber AB continues to work through issues related to traceability and forgery prevention, as well as the annual affirmation requirement. More information is expected in the coming months.
Does a CMMC Level 2 certification have value under the current pause? Travis's position was yes, for two reasons: it remains the strongest protection against False Claims Act risk, and it continues to serve as a differentiator when teaming with prime contractors who are still asking about compliance status.
We'll continue to track updates and insights from each Cyber AB Town Hall as guidance evolves. For ongoing coverage and past recaps, visit the CMMC.com newsroom.