Don’t Scrap CMMC. Fix How It Is Enforced.
By Zach Walker & Shawn Kotoske
As published on RealClearDefense.com
August 7, 2026
On July 13, the Pentagon suspended the planned Phase II expansion of its Cybersecurity Maturity Model Certification (CMMC) program and gave a task force 60 days to rethink the approach. As a C3PAO, we think the Pentagon got it half right and offer our candid advice on the circumstances.
Since 2017, defense contractors handling covered information under applicable contracts have been required to protect sensitive defense information such as blueprints, technical data, and logistics details our adversaries actively steal. For years, enforcement relied largely on the honor system: companies graded their own security and reported the score. It did not work.
A 2024 survey of the Defense Industrial Base (DIB), entitled Defense on the Brink, found that only 4% of contractors believed they were ready for certification and the average self-reported score remained well below a passing mark of 110. The reality was that much of the supply chain wasn’t sufficiently securing the data.