
September 2026 Cyber AB Town Hall Recap: Task Force Timing, ISC2 Survey Results, and Possible CMMC Reforms
The September Cyber AB Town Hall came as the CMMC Reform Task Force moved into drafting its recommendations. Matt Travis covered where the task force stands, a new GAO report on cybersecurity regulatory harmonization, and ISC2 survey results on how the defense industrial base has responded to the Phase 2 pause.
Travis and Mike Snyder of the CyberEF then led an extended discussion on what a reformed CMMC program could look like, which both presenters framed as their own speculation. The session also included a CAICO update on the upcoming certification renewal window, a CyberEF update, and a Q&A covering NIST SP 800-171 Rev 3, CPE requirements, and OT security.
The CMMC program remains operational

Travis opened by restating that the CMMC program itself is not paused. The July 13 announcement paused the Phase 2 contractual requirements, and the rest of the program continues to operate as of the September Town Hall:
- DFARS 7012 requirements remain in force
- C3PAOs are still conducting Level 2 certification assessments
- CMMC eMASS and SPRS are still processing Level 2 certifications
- The CMMC Program Office (PMO) remains staffed and operational
- DIBCAC continues to assess candidate and authorized C3PAOs, as well as OSCs
- DCSA is still conducting Tier 3 background investigations and FOCI screening
- RPOs continue to support 800-171 implementation and CMMC preparation
- CAICO and Approved Training Providers continue operating without interruption
Where the CMMC Reform Task Force stands
Travis noted that the Cyber AB is not part of the task force's internal deliberations and has no inside information on its recommendations. Based on his understanding, the task force's 60-day review period has ended, and it is now in the roughly 15-day window for drafting recommendations, working with DoW CIO Kirsten Davies and her front office.
Once the CIO approves any recommendations, Travis expects additional coordination before anything is made public, including review by the DoW General Counsel's office and Small Business office, followed by OMB and the White House. He said he does not have a timeline for public release. His personal estimate was the back half of October at the earliest.
GAO report on cybersecurity regulatory harmonization
Travis placed the reform effort in a broader context, noting that CMMC is one of many cybersecurity requirements facing government contractors and that Congress has shown interest in harmonizing them. He highlighted GAO-26-108606, Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements, published July 22, 2026, along with a series of three GAO industry panels on the same topic. The last of those panels was published the week of the Town Hall.

As summarized by the Cyber AB, the report identifies three core challenges: multiple regulatory baselines across agencies and sectors, duplicative audits of the same underlying controls, and conflicting incident reporting timelines ranging from 4 to 72 hours. Its findings point to compliance overhead that pulls resources away from threat hunting, a lack of formal reciprocity between agencies, and sector-specific customization of baselines like NIST SP 800-53 and the NIST CSF that breaks interoperability.
The report's recommendations include establishing common baselines anchored to national standards such as the NIST CSF, institutionalizing reciprocity so agencies can accept equivalent assessments from other recognized bodies, and strengthening the Office of the National Cyber Director's role in leading cross-agency alignment.
ISC2 survey: how the DIB is responding to the Phase 2 pause
Travis shared results from an ISC2 survey conducted over the summer, Navigating Cybersecurity Regulatory Requirements and the CMMC Pause. According to Travis, the survey drew a little over 200 respondents, primarily cybersecurity professionals involved in CMMC work. The full results are available on the ISC2 website.

Reactions to the suspension. 76% of respondents agreed that a CMMC program is necessary to ensure cybersecurity standards are being met. Respondents were more divided on the pause itself: 42% disagreed with pausing Phase 2, while 38% supported it.

Impact on day-to-day work. 66% of respondents said CMMC preparation increased their workload, and 62% reported both increased documentation requirements and expanded job responsibilities.

Impact of the pause on work and career plans. 68% of respondents said they have continued CMMC-related work despite the uncertainty. 34% reallocated time to other priorities, 26% delayed or canceled assessment preparation, and 15% changed their professional development or career plans.
CMMC reform: what the Cyber AB is watching
This portion of the Town Hall was a conversation between Travis and Snyder, and both were emphatic that it reflects their own thinking. They stated that they have no inside information on the task force's work, that the DoW has not seen their slides, and that nothing in the discussion should be read as a hint about forthcoming policy. Travis described the exercise as connecting the dots from public DoW remarks and publications. Every slide in this segment was labeled "speculative."
What the Cyber AB believes the DoW OCIO does and does not like

Based on public statements from Davies and other DoW leaders, Travis and Snyder shared their read on the aspects of the current program the OCIO views unfavorably. These include treating CUI safeguarding as the DIB's highest cybersecurity priority, point-in-time assessments that go stale quickly, the "checklist" nature of NIST SP 800-171 Rev 2, "bureaucracy," over-marking of CUI, high implementation and certification costs, and the Risk Management Framework (RMF).
On CUI, Travis said he believes the department is more concerned about threat actors disrupting key DIB suppliers than about data exfiltration alone. On bureaucracy, he attributed the perception to the administrative requirements of 800-171, and he described CUI over-marking as a government problem.

On the other side, Travis and Snyder pointed to industrial resiliency and supply chain agility, inclusion of operational technology (OT), continuous validation, automation and advanced technology, Brilliant at the Basics for IT and OT, NIST CSF 2.0, and reciprocity with or advance standing from other frameworks.
Brilliant at the Basics
Travis pointed to Brilliant at the Basics as the clearest published statement of DoW cybersecurity priorities for the DIB. It consists of two top-10 lists of best practices, one for IT and one for OT.


Snyder noted that many of the practices crosswalk to NIST SP 800-171 and other NIST standards. On the OT side, he pointed to recent breaches involving manufacturing controllers and the risk to the supply chain when a small contractor that makes a single critical part is taken offline. Travis suggested that a partial 800-171 assessment mapped to these priorities is one possible direction.
The Cybersecurity Risk Management Construct
Snyder also highlighted the Cybersecurity Risk Management Construct (CSRMC), which the DoW announced on September 24, 2025 as its internal replacement for legacy RMF processes. The CSRMC replaces "snapshot in time" assessments with dynamic, automated, and continuous risk management through a five-phase lifecycle and ten foundational tenets. Travis and Snyder said the CSRMC and NIST CSF 2.0 may offer clues about how the department wants DIB companies to manage risk.

Possible future conformity concepts

The final slide in this segment was labeled "really speculative." Travis and Snyder walked through concepts they said would not surprise them in a future version of the program:
Active cyber defense
Continuous monitoring, compliance-as-code, and adversarial testing. Snyder described compliance-as-code as government-provided configuration requirements in OSCAL format for common products, similar to how STIGs are used on the classified side.
Compliance scaling with risk
Requirements that scale with what a company does and makes, with Snyder noting that business risks such as personnel, physical security, and workplace safety could factor in alongside IT risk.
A role for DISA
Possible functions include telemetry analysis and live risk scoring for some critical manufacturers, OSC training, C3PAO IDIQs, and a central repository for OSCAL content.
The role of C3PAOs and RPOs
Travis described a possible hybrid model in which C3PAOs assess a priority subset of the 110 controls and the rest are self-attested, along with potential roles in red teaming and penetration testing validation. Snyder said he does not expect a major reduction in assessment costs and would expect that time to shift toward on-site review of critical areas.
Status scoring, FedRAMP, and Rev 3
Other concepts included a possible move toward Continuous Monitoring and Risk Scoring (CMRS), FedRAMP integration, and NIST SP 800-171 Rev 3. Travis called the current relationship between FedRAMP and CMMC a source of confusion and frustration that he expects any reform to address.
Retained value of Level 2 certificates
Travis stressed the importance of any transition plan preserving the value of existing Level 2 certificates. He suggested awarding extra evaluation credit in solicitations to certified companies as one possible approach, and Snyder said he expects SPRS scoring to reflect lower risk for organizations assessed by a third party.
CMMC ecosystem growth
Certification numbers continued to climb in September, with final Level 2 certificates reaching 2,362, up 12% from August. Conditional certificates rose 7% to 71, while Level 2 assessments in progress dipped 5% to 151.


The ecosystem also held steady or grew across most roles. Authorized or accredited C3PAOs rose to 117, four of which are now fully accredited to ISO/IEC 17020. CCAs, CCPs, and Lead CCAs each grew 3 to 4%, and there are now 81 CMMC Credentialed Instructors. Registered Practitioner numbers were roughly flat, and Approved Training Providers declined from 53 to 49. Travis noted that these figures reflect data as of the end of the prior week and may differ from the real-time Cyber AB Marketplace.
CAICO updates: the renewal window and CPE requirements

Todd Gagnon focused on the upcoming certification renewal process as CAICO moves all CMMC certifications to ISACA's January 1 calendar-year cycle. The renewal window opens November 1 and closes December 31, with renewals processed January 1. A 30-day grace period runs through January 30, after which certifications that have not been renewed will expire. Certification holders with anniversary dates between April and December of this year have already been moved to the January 1 cycle, and those who renewed with the Cyber AB between January and March will be aligned next year.
Renewal requirements
CCPs need to submit their annual CPEs and pay the renewal fee. CCAs must also maintain an underlying DoD 8140 certification at the intermediate or advanced level. Lead CCAs must maintain their CCA and a DoD 8140 certification at the advanced level, and have no separate CPE requirement. Gagnon clarified that holding a CCP is not required to maintain a CCA. Active CCAs who want to keep their CCP can do so at no additional fee by applying their CCA CPEs to both.
CPE requirements
CCPs and CCAs certified before January 1, 2026 begin their three-year cycle this year and need at least 20 CPEs by December 31, 2026. Those certified during 2026 begin their cycle in 2027. Each year requires a minimum of 20 CPEs, with 120 due over the full cycle, so CAICO recommends earning 40 per year. Under an updated policy, 90 of the 120 must be domain-specific, and the remaining 30 can come from broader professional development such as leadership or management training.
Training content update on hold
CAICO had planned to release new training content and exams at the start of 2027. That work is paused until the DoW CIO's office announces its decisions, so CAICO can confirm alignment with any new requirements. Gagnon expects the release to shift within the first quarter of 2027.
CyberEF update
Snyder outlined the CyberEF's three webinar series: one for OSCs focused on implementation and risk, one for the practitioner community, and one open to the full ecosystem. The DIB Collective kicks off for OSCs on September 30, led by Allison Giddens. On October 15, Snyder will lead an ecosystem-wide session on AI and the future of CMMC.

Q&A highlights
When will CMMC move to NIST SP 800-171 Rev 3?
Travis said the PMO had drafted a rule amendment with a Rev 3 transition plan before the Phase 2 pause, which has been held in abeyance since July 13. He expects Rev 3 to be incorporated into the reformed program. Snyder pointed to the proposed FAR CUI rule and noted that the Rev 3 organization-defined parameters (ODPs) have already been published.
Will organizations certified under Rev 2 need to recertify immediately under Rev 3?
Travis said this cannot be answered until a transition plan is published. He would expect a grace period or grandfathering clause, as is typical of transition plans, but stressed there is no guarantee.
Are the DoW CIO website FAQs authoritative?
Travis said the CMMC program rules carry the weight of law, and the CMMC Assessment Process (CAP) is authoritative for C3PAOs. The FAQs are official supplemental guidance that can be relied on, but they do not carry the weight of law.
If OT security is added, what framework would it be based on?
Speaking speculatively, Snyder said he does not expect a new requirement. He expects guidance from NIST and CISA, and expects OT to be addressed as a separate layer that would apply to organizations with manufacturing environments regardless of whether they handle CUI.
Will future DIB requirements address integrity and availability?
Snyder said yes, connecting it to the broader focus on governance and risk.
Can a prime recover the cost of requiring C3PAO certification from its subs?
Travis said this is an acquisition question for contracting officers and outside the Cyber AB's scope. He added that the recent class deviation codified what was announced on July 13, with nothing new affecting the CMMC program.
Do CCIs need to keep their CCP?
No. CCIs must retain their CCA, which covers the CCP.
How do CPEs work across multiple certifications?
A single CPE can be applied to multiple certifications through an ISACA profile. Gagnon said CPEs earned for related certifications like CISM will most likely apply to the CCP and CCA, and most cybersecurity-related training, webinars, and conferences qualify. Performing normal job duties, such as guiding an OSC through Level 2 requirements, does not. Delta training, available on the ISACA website, counts for two CPEs.
We'll continue to track updates and insights from each Cyber AB Town Hall as guidance evolves. For ongoing coverage and past recaps, visit the CMMC.com newsroom.