
The Cyber EF Just Gave a CMMC Practitioner Program Update: What Defense Contractors Should Know
At a Cyber Engagement Forum held for Registered Practitioner Organizations (RPOs) today on July 30, 2026, the Cyber EF laid out a quarter-by-quarter plan to rebuild the CMMC practitioner program between now and mid-2027. The plan covers new training, a rebuilt marketplace, practitioner councils, and a validation system for RPO services.
For defense contractors, the takeaway is simpler. While C3PAO assessments and other parts of the CMMC ecosystem remain operational during the Phase 2 pause, the practitioner side is being restructured, vetted, and strengthened in order to better help the DIB meet the underlying implementation requirements that remain firmly in place.
That last point matters more than any calendar.
What is changing in the CMMC practitioner program?
The Cyber Engagement Forum (Cyber EF), a wholly owned nonprofit subsidiary of The Cyber AB, committed to a phased rebuild of the RP, RPA, and RPO programs running through the second quarter of 2027.
An overhaul of the Registered Practitioner program has been promised since the November 2025 Town Hall, but today’s forum was the first time dates have been attached.
- Q3 2026: Surveys to RPOs on tools, frameworks, and the implementation work they actually perform, used to shape the revised program. Webinars about how to implement the DoW’s "Brilliant at the Basics and how the practitioner councils and committees will function
- Q4 2026: Cyber EF website launch, an updated learning management system with the new RP course released module by module for pilot feedback, and expanded RPO resources delivered through third-party partnerships
- Q1 2027: A validation system for RPO services and products, intended to confirm that an organization actually delivers the service it advertises
- Q2 2027: Reaching a “steady state,” meaning the new program, marketplace, and resources are running without further build-out
Two takeaways that stand out:
- Training modules will ship as they are finished rather than waiting for a complete course, with selected RPOs piloting them first.
- The revised program is being built from practitioner survey input rather than from the CMMC rule text, which is a stated correction of how the last two versions were written.
These highlight the industry-first approach the Cyber EF is taking to this program overhaul, similar to FedRAMP 20x.
Why the Cyber EF is standing up RPO councils
The Cyber EF said it will spend the following two weeks forming practitioner councils and committees so the RPO community speaks to the government with one voice. These councils will be modeled on the existing C3PAO advisory council but with more councils to cover the range of implementation work, including managed service provider and external service provider requirements.
The reason given was direct: federal government stakeholders want to hear from practitioners and assessors rather than from the accreditation body translating on their behalf, and the current channel is individual emails and calls that do not add up to a collective position. A webinar is scheduled later in August to explain how the councils will operate.
What the Cyber EF said about the Phase 2 pause
The answer echoed what we’ve heard from the DoW, primes, and other industry stakeholders: no implementation requirement has been removed.
The pause stops third-party assessment requirements from being written onto new contracts by a DoW contracting officer. It does not remove existing obligations to protect federal data, including DFARS 252.204-7012, NIST SP 800-171, and the Phase 1 CMMC self-assessment and affirmation requirements, which are already in contracts and still being put in awards. It also does not stop primes from flowing requirements down to their supply chain on their own schedule.
The Cyber EF speculated that one possible direction of the CMMC program review and proposed reform will be shifting from checklist- to risk-based.
Under this model, a contractor and its practitioner may focus on implementing the most high-risk requirements and document why others are not yet met, what compensating controls are in place, and what the remediation path is, instead of treating all 110 requirements as equally weighted. Future assessments would be more likely to focus on critical requirements and on validating that testing was performed against the environment where CUI actually lives.
Will the RP and RPA designations change?
Existing credentials are expected to carry forward through a transition or delta process rather than a recertification. The Cyber EF was explicit that practitioners will not be pushed out and forced to requalify, though there will be revised training.
The structure underneath is likely to change. The original plan kept Registered Practitioner and Registered Practitioner Advanced as two designations split by framework, with RP mapped to NIST SP 800-171 and RPA mapped to NIST SP 800-172. The Cyber EF said it will most likely scrap that split in favor of a single practitioner designation with framework-specific training underneath it, and is seeking practitioner feedback before finalizing.
Two other planned changes affect how contractors will find and evaluate practitioners:
- Practitioners get staffed under their RPO in the new marketplace. An RPO will manage its RPs and RPAs, their training records, and role-based permissions inside one organizational account rather than through individual affiliations.
- Training is being built to NIST SP 800-171 Rev 3. The Cyber EF said new practitioner training is written to Rev 3, with delta training held in reserve for contracts that still cite Rev 2.
What CMMC RPO changes mean for defense contractors
Nothing in this roadmap changes what you owe under an existing contract. It changes how you should evaluate the people you hire to help you meet it.
- Ask how an RPO is involved in the program overhaul. An RPO that is participating in the surveys, councils, and training pilots will have more input and visibility into any revised requirements or implementation methods than one that is not.
- Ask about Rev 3 readiness. With practitioner training being written to Rev 3, a firm that can only speak to Rev 2 will be working from the older baseline.
- Wait for the validation layer before treating a listing as vetting. Until the Q1 2027 validation system exists, references, interviews, and proof of experience remain the real due diligence when vetting practitioners in the CMMC ecosystem.
- Keep implementing. The scope of your CUI boundary, your System Security Plan, your POA&M, and your SPRS score are all work that still needs to be completed, regardless of the pause and program review.
Secureframe is a Registered Practitioner Organization with CMMC Registered Practitioners that built and continue to maintain Secureframe Defense to automate the implementation work that the pause left fully intact: scoping, control implementation, current documentation, evidence collection, SPRS scoring, continuous monitoring, and more.
If you have questions about any part of the process or existing requirements, talk to a CMMC expert.