
August 2026 Cyber AB Town Hall Recap: RFI Results, the Cyber AB's Reform Recommendations, and a Legal Perspective
The August Cyber AB Town Hall was the first session since the Reform Task Force RFI closed on August 14, and the program had a lot to cover. Matt Travis walked through what the publicly available industry responses said, presented the Cyber AB's own RFI submission in detail, and was joined by attorney Eric Crucius of Hunt Andrews & Kirk for a candid legal perspective on the reform effort.
The CMMC program remains operational
Travis opened with a reminder that has been consistent across the last two Town Halls: the CMMC program itself is not paused. Phase 2 contractual requirements were suspended, but the rest of the program continues to operate without interruption.
DFARS 7012 remains in force, C3PAOs are still conducting Level 2 certification assessments, eMASS and SPRS are still processing certifications, the PMO remains staffed, DIBCAC continues assessing candidate and authorized C3PAOs, DCSA is still conducting Tier 3 investigations and FOCI screening, RPOs are still supporting 800-171 implementation, and CAICO and Approved Training Providers continue operating normally.

A summary of publicly available RFI responses
The RFI closed on August 14 with a strong response from the defense industrial base. As of the August Town Hall, the task force had received nearly 1,100 RFI responses, engaged over 1,300 individuals through listening sessions and stakeholder meetings, and collected over 10,500 pages of submitted data.
The DoW Office of the CIO posted on X on August 20 that the task force is working through the feedback using analytical tools to categorize responses, and that it remains on track to deliver final recommendations to CIO Kirsten Davies. Travis noted that task force recommendations were expected by mid-September, though he does not expect those recommendations to be made public immediately given the internal coordination required before any external release. His estimate was that public-facing information could emerge by early October.
Travis was scheduled to meet with CIO Davies in person later that week, and CAICO had a listening session with the task force scheduled for August 27.
Before presenting the Cyber AB's own submission, Travis summarized the themes that emerged from publicly available RFI responses submitted by companies, trade associations, and individuals. He was clear that this represents a general overview of what was visible in public submissions, not a comprehensive account of all responses.

Feedback on specific NIST 800-171 Rev 2 requirements
The security requirements that drew the most feedback as burdensome or disproportionate in their compliance cost relative to security return included:
- FIPS-validated cryptography, particularly challenging for small businesses
- Media sanitization and physical destruction record-keeping
- Media marking and physical labeling
- Audit log management, specifically the requirement for continuous collection, correlation, and manual review
- Controlling wireless access and boundary protection
- System Security Plan and artifact generation
Travis noted that SSP documentation requirements are a NIST 800-171 obligation, not a CMMC-specific one, meaning the burden would exist regardless of whether a C3PAO conducts the assessment.

Broader themes from industry responses
Beyond specific requirements, the publicly available responses pointed to several systemic concerns:
- CUI designations are largely applied improperly by DoW contracting officers, with blanket markings rather than precise identification
- CUI safeguarding costs disproportionately burden small and medium businesses
- FedRAMP creates friction with CMMC and many modern SaaS tools
- NIST SP 800-171 Rev 2 compels too much static documentation

Common industry recommendations
The recommendations that appeared across publicly available responses included enforcing CUI precision and avoiding blanket CUI labeling throughout DoW, holding prime contractors accountable for proper flow-down requirements, recognizing COTS and SaaS tools that already meet certain industry standards, prioritizing which Level 2 contracts actually require C3PAO certification, and providing financial and technical assistance to DIB small and medium businesses.

The Cyber AB's RFI Response
The Cyber AB published its full RFI response on August 14. Travis summarized the submission at the Town Hall, organizing it into three categories: quick wins, longer-term transformational reforms, and overarching perspectives on the program.
Quick wins and low-hanging fruit

1. Reduce the mandatory minimum size of C3PAO assessment teams. Current regulations require at least three CCAs per team. The Cyber AB recommended reducing that to two, which would lower assessment costs and enable more C3PAO teams to operate simultaneously with the existing CCA workforce.
2. Allow for C3PAO continuous monitoring and delta assessments. Under the current framework, a Level 2 certification assessment is a static point-in-time evaluation of all 110 requirements. If an OSC makes a significant change to its environment after certification, it must hire a C3PAO to conduct a full reassessment. The Cyber AB recommended allowing C3PAOs to conduct continuous monitoring engagements and delta assessments covering only changed controls, reducing both cost and the disincentive to modernize or improve a network during the three-year certification cycle.
3. Commercialize CCA and CCP background investigations. DCSA's Tier 3 process is cumbersome and takes a long time to adjudicate. The Cyber AB recommended allowing private-sector security firms to conduct equivalent background checks, which would increase the supply of available CCAs and reduce the cost of Level 2 certification assessments.
4. Eliminate CMMC Level 1. The Cyber AB suggested that the DoW consider whether protecting Federal Contract Information through a Level 1 self-certification requirement passes a rigorous cost-benefit and risk analysis, particularly for small businesses that handle only FCI and not CUI. Travis noted this is a policy question for the DoW to evaluate rather than an advocacy position from the Cyber AB.
5. Fix the FedRAMP problem and clarify ESP requirements. The relationship between FedRAMP and CMMC remains a significant source of confusion. The Cyber AB highlighted that 32 CFR Part 170 provides insufficient guidance to defense contractors about what their CSPs, MSPs, and MSSPs must do to meet CMMC conformity requirements, and that the FedRAMP 20X situation has added uncertainty. The Cyber AB called for clearer policy guidance.
Larger transformational reforms

Travis noted that these items were discussed in the context of the RFI but were not formally included in the Cyber AB's written RFI response, as they fall outside the Cyber AB's immediate accreditation role.
1. Explore AI and technology innovations to make CMMC more efficient. ISO/IEC does not prohibit AI use in assessment, but does establish certain boundaries and protocols. 32 CFR Part 170 as currently written mandates a largely manual approach and is not conducive to incorporating AI tools. The Cyber AB suggested that the rule would need to be rewritten to make AI integration feasible, and that the reform effort provides an opportunity to pursue that.
2. Revisit alternative standards acceptance. Other cybersecurity frameworks may be worthy of partial reciprocity consideration. Living control sets and conformity crosswalks with frameworks such as the Secure Controls Framework could allow organizations to achieve advanced standing rather than treating CMMC as a completely standalone standard.
3. Incorporate OT security requirements. CMMC Level 2 could introduce Operational Technology security annexes, and other security priorities such as zero trust could be introduced as additional advanced annexes.
Overarching perspectives
Beyond specific recommendations, the Cyber AB used its RFI response to make several broader points about the program:
- Third-party certification is fundamental and must be retained. Self-attestation has not been effective, and the second "C" in CMMC reflects the deliberate design of the program. The Cyber AB argued this element should be preserved in any reformed version of the program.
- C3PAOs are small businesses that found a way to meet the requirements. Every authorized C3PAO undergoes its own DIBCAC assessment against NIST SP 800-171 Rev 2. Approximately 80 percent of C3PAOs are small businesses, and they bear those compliance costs without cost reimbursement from the government since they do not hold DoW contracts. The Cyber AB argued this demonstrates that meeting the standard is achievable and that C3PAOs serve as a proof of concept.
- CMMC has been operational for 18 months and is working as designed. Over 2,000 Level 2 final certifications have been issued by C3PAOs. The program was narrowly designed to address one objective, safeguarding CUI, but that does not mean it cannot be expanded.
- There is no third-party assessment bureaucracy within CMMC. NIST SP 800-171 Rev 2 requirements may feel bureaucratic, but the assessment process itself is private sector-led and industry-driven. The Cyber AB noted that engaging in the Marketplace requires no government approval and involves minimal government touchpoints.
- The value of current Level 2 certifications must be preserved. Any transition to a reformed program must protect and retain the value of certifications already issued. The ecosystem experienced a three-year hiatus during the last rulemaking period and cannot sustain another equivalent pause.
- CMMC is an international program. Individuals and companies from over 30 nations are currently participating in CMMC. Any reform measures should factor in the feasibility, risk, and benefit implications for international participants.

Legal perspective: What the reform means for the ecosystem
Eric Crucius, a partner at Hunt Andrews & Kirk who has advised CMMC clients since the program's inception, joined the Town Hall to share a legal perspective on the reform effort.
Should organizations still pursue Level 2 certification?
Crucius said his answer has been uniform across all client conversations: yes. Regardless of whether certification is contractually required, pursuing it lowers security risk, reduces exposure to False Claims Act liability, and remains a differentiator in competitive teaming relationships. He noted that prime contractors continue asking about compliance status even after the Phase 2 pause, suggesting demand for certification has not materially declined. He has not advised a single client against pursuing certification.
Is the False Claims Act a credible substitute for third-party certification?
No, in Crucius's view. The FCA has been available as an enforcement mechanism since the underlying cybersecurity requirements were first put in place, and it has not served as an effective deterrent. The DoD Inspector General's office has conducted multiple reports over the years, including a recent one done in cooperation with the Department of Justice's Civil Cyber Fraud Initiative, and found non-compliance at every contractor examined. Crucius noted that companies tend to assume enforcement will not reach them, and that absent a systematic and well-resourced investigation program, FCA enforcement is too sporadic to drive broad compliance. He described the C3PAO ecosystem as a private-sector solution to a government problem that self-certification and FCA enforcement alone had failed to solve.
How much flexibility does the DoW have to change the underlying standard?
Not much, in Crucius's assessment. NIST SP 800-171 is the established standard, and there are constraints on how far the department can deviate from it. He raised a complication that the reform effort must navigate: the proposed FAR CUI rule, expected to finalize by the end of the year, references NIST SP 800-171 Rev 3, while CMMC remains tied to Rev 2. If the FAR CUI rule finalizes at Rev 3, contractors with both DoW and civilian agency contracts could find themselves subject to two different revision requirements simultaneously. Crucius argued this makes a strong case for the DoW to align with the broader federal direction toward Rev 3, as a uniform standard would lower costs for small businesses operating across multiple agency relationships.
He also noted that joint contracts between the DoW and other agencies (such as NASA or DOE) will face practical complications in the near term, as those contracts will need to designate which regulatory framework governs.
Do C3PAOs and other ecosystem participants have legal recourse if the program changes significantly?
Crucius said C3PAOs would likely have the strongest basis for any legal claims, having been encouraged by the department to invest in building out their organizations in reliance on the program as structured. If the department were to eliminate or significantly curtail third-party assessments, he would not be surprised to see lawsuits filed. He also noted that some of the stated premises for pausing Phase 2, including assessment capacity constraints, have not been borne out by the actual ecosystem statistics, which he suggested could be cited in any such litigation.
FedRAMP 20x: Not accepted under CMMC
Travis provided an additional verbal clarification on FedRAMP 20x, which has been a recurring question. The Cyber AB's position, based on instruction from the DoW, is that FedRAMP 20x does not meet DFARS 7012 or CMMC requirements. C3PAOs have been instructed not to accept FedRAMP 20x as a valid FedRAMP authorization or FedRAMP Moderate Equivalency.
FedRAMP 20x incorporates automated continuous monitoring KPIs but does not satisfy all the controls required by the FedRAMP Moderate baseline. The applicable requirement under DFARS 7012 and the December 2023 DoW CIO memo is that CSPs must either hold a FedRAMP authorization (currently Rev 4 or Rev 5) or demonstrate FedRAMP Moderate Equivalency. FedRAMP 20x meets neither bar as currently defined.
Travis acknowledged this is under active discussion within the DoW and that he expects updated written guidance to be issued later this year. In the meantime, the current position stands: FedRAMP 20x does not meet CMMC requirements.
A reminder for non-certification assessments
Travis also revisited the rules governing non-certification assessments (sometimes called mock, gap, or dry-run assessments), noting that questions on this topic have increased since the Phase 2 pause.
Under Section 3.4 of the Code of Professional Conduct, authorized C3PAOs may conduct non-certification assessments provided they follow the CAP, deliver only met/not-met determinations, and provide a formal written deliverable. A non-certification assessment does not result in a CMMC Certificate of Status and is not reported to eMASS.
The key constraint is that if a C3PAO provides any remediation advice, implementation guidance, or answers to questions about how to address findings, it is conflicted out of subsequently conducting a certification assessment for that OSC for three years. The decision to transition from a non-certification to an advisory engagement is the C3PAO's to make, but the conflict of interest consequence follows immediately.
One direction is permitted and one is not: a certification assessment may be converted to a non-certification assessment if the OSC requests it, as long as the non-certification assessment protocols are then followed. A non-certification assessment cannot be converted into a certification assessment.

Ecosystem growth post-Phase 2 suspension
The program continued to grow in the lead-up to the August Town Hall.

Travis noted that the practitioner community (RPs, RPOs) showed a small dip, which he attributed to some uncertainty from the reform process, though he described the dip as modest and the overall ecosystem as healthy.
CAICO Corner
Todd Gagnon confirmed that CAICO continues to operate fully, with training and certification proceeding without interruption. He noted that the influx of new candidates into the pipeline remains steady, though it may be slightly lighter than earlier in the year. He said it is too early to identify a clear trend.
- CCI transition update: As of the August Town Hall, 76 CCIs have been fully credentialed with 14 applications still in process. The 90-day grace period following the June 30 PI program sunset remains active, and Gagnon expects all open applications to be resolved well before September 30. If all 14 complete successfully, the CCI cadre will reach approximately 90 credentialed instructors.
- Workforce survey forthcoming: CAICO will be sending a survey to certified ecosystem members in the coming week to support PMO and internal workforce analysis. The survey covers role, certification level, and level of activity in CMMC assessments. Gagnon encouraged certified members to complete it and spread the word to maximize response rates.
- CAICO listening session: A listening session with the Reform Task Force was held August 27 at 1:00 p.m. and reached the 1,000-participant Zoom capacity limit.
On the Cyber EF side, Mike Snyder announced that the CyberEF is beginning practitioner councils and committees, with registration rolling out and sessions planned on an approximately weekly to biweekly cadence. Snyder noted the EF is otherwise in a holding pattern on additional updates pending the FAR rule and task force outcomes.
Major program updates are expected within the next month
The task force is expected to deliver initial recommendations to CIO Davies around mid-September, with public-facing information potentially available by early October. Travis committed to keeping the ecosystem updated and noted that a pop-up Town Hall is possible if significant developments warrant it before the next scheduled session on September 29.
We'll continue to track updates and insights from each Cyber AB Town Hall. For ongoing coverage, check out past recaps in the CMMC.com newsroom.