Contact us at (571) 408-8810 • Authorized C3PAO • CMMC L2 Certified • GTIA Trustmark Assured Status

NIST 800-171 Implementation

Confidently navigate the 800-171 process

Assessments for Contractors

Mock assessments, pre-assessments, readiness assessments or CMMC Level 2 Assessments.

Assessments for MSPs

Get yourself, and your clients, CMMC ready.

800-171 Compliant Managed IT

Stay secure, compliant, and operational with DIB focused managed IT services.

Our Company

Learn about our mission and company history.

Our Process

A simple, transparent, and proven path to CMMC readiness.

Why Choose Resilient IT?

We're mission oriented, focused on building resilient technology, compliance, and cybersecurity solutions.

CMMC Level 2 Certified MSP and Authorized C3PAO

The CMMC Crystal Ball: What the Program May Look Like After the Review

Written by Kevin Mann

September 13, 2026

The current CMMC Phase 2 pause increasingly looks less like a temporary delay and more like an opportunity for the Department of War to reconsider how cybersecurity assurance across the Defense Industrial Base should actually work.

No final CMMC Reform Task Force recommendations have been publicly released as of September 12, 2026.

What follows is therefore a prediction, not a description of an announced future program, but the direction is becoming easier to see.

Official acquisition actions, the planned transition to NIST SP 800-171 Revision 3, Cyber AB recommendations, CUI guidance, Department cybersecurity strategy, public statements from senior DoW cyber leadership, and market behavior are beginning to point toward a common architecture.

Our view remains:

  • CMMC is unlikely to disappear, but CMMC 2.0 is increasingly unlikely to return exactly as originally designed.
  • NIST SP 800-171 will likely remain the foundational CUI security baseline, while the current Revision 2 structure evolves with the planned transition to Revision 3.
  • Independent verification will probably survive, but it will be applied more selectively according to actual information, program, and mission risk.
  • Continuous evidence and delta validation are increasingly likely to supplement traditional point in time assessments.
  • Additional tiers, sublevels, or assurance categories are increasingly plausible because the current Level 1 to Level 2 jump does not reflect the very different risk profiles across the DIB. A new numbered level is possible, but no longer appears necessary.
  • Mission resilience, Integrity, Availability, recovery, and OT are increasingly likely to matter where operational consequence justifies them, with NIST SP 800-172 Revision 3 now providing an official enhanced-security framework for critical programs and high-value assets.
  • The transition could extend materially through 2027, with the existing 2028 implementation boundary becoming increasingly important.

The future model may therefore look less like:

Pass an assessment, receive a certificate, and return three years later.

And more like:

Establish a trusted security baseline, continuously demonstrate that the baseline remains effective, and independently revalidate it when risk or material change warrants doing so.

The Original Problem Still Exists

CMMC was not created because NIST SP 800-171 did not exist. Defense contractors had already been required to implement the NIST requirements. The problem was assurance. The Department did not have sufficient confidence that every contractor claiming compliance had actually implemented the required security protections. That underlying problem has not disappeared.

Any meaningful reform still has to answer a basic question:

How does the Department independently establish that an organization claiming to protect CUI is actually doing so? A complete return to self attestation risks recreating the exact assurance problem CMMC was designed to address.

That is why we continue to believe independent verification survives.

What is much more likely to change is:

  • who receives independent verification;
  • how much verification is required;
  • how frequently it occurs;
  • what triggers reassessment;
  • which controls can be demonstrated through automation;
  • and how the Department evaluates security between formal assessment events.

NIST SP 800-171 Will Likely Remain the Foundation, but Revision 2 Will Not

One of the most important recent developments is the Department’s official regulatory plan to move CMMC from NIST SP 800-171 Revision 2 to Revision 3. That means the current 110 requirement architecture should no longer be viewed as the permanent CMMC baseline.

Revision 3 introduces a reorganized security baseline, greater specificity, organization defined parameters, and corresponding changes that will require the Department to revise CMMC Level 2 and Level 3 assessment objectives.

The enduring prediction should therefore be:

  • NIST SP 800-171 remains the CUI cybersecurity foundation.
  • Revision 3 eventually replaces Revision 2 (I think we all see this coming).
  • The current 110 requirement and 320 objective architecture changes accordingly.
  • DoW will have to reconcile the new baseline with scoring, POA&M rules, SPRS, assessment depth, ODPs, continuous evidence, and whatever additional reforms emerge from the current review.

The foundation survives. The implementation architecture around it evolves.

NIST has also finalized SP 800-172 Revision 3 and SP 800-172A Revision 3. That matters because 800-172 provides a selectable enhanced layer for CUI associated with critical programs or high-value assets, explicitly addressing Confidentiality, Integrity, Availability, and cyber resiliency. Its assessment companion allows self, independent third-party, and government-sponsored assessments with agency-defined depth and coverage. This gives DoW an existing federal framework for risk-based assurance rather than requiring an entirely new control model.

CUI Identification May Become the First Gate

One of the clearest themes emerging from the review is that CMMC cost is often being driven by poor CUI identification and unnecessary scope.

If the government or a prime cannot clearly identify:

  • what information is CUI;
  • what CUI the contractor will actually receive;
  • what contractor generated information becomes CUI;
  • where that information will flow;
  • who needs access;
  • and which systems actually process it;

then the contractor is forced to make conservative assumptions.

Those assumptions often expand the security boundary.

The result can be larger enclaves, more licensing, broader MSP and ESP scope, more systems subject to assessment, and significantly higher implementation cost.

The future assurance process therefore makes more sense if CUI identification occurs before the cybersecurity verification burden is assigned.

A logical sequence would be:

  • The contract identifies the actual CUI.
  • The contractor defines the systems, users, applications, providers, and suppliers that process it.
  • The government and contractor determine mission and information risk.
  • The appropriate verification level is then assigned.

Better CUI identification could reduce CMMC burden substantially without weakening a single security requirement.

The Current Level Structure May Be Too Coarse

One of the structural weaknesses in CMMC 2.0 is the size of the jump between its levels.

At Level 1, the organization protects FCI using a relatively small set of basic safeguarding requirements.

At Level 2, the organization moves to the full NIST SP 800-171 CUI baseline.

Level 3 then addresses a much smaller population requiring enhanced protection against advanced threats.

That creates a large middle ground.

A small supplier handling relatively limited CUI and a major contractor supporting highly sensitive engineering or mission critical production can both fall under the broad Level 2 label even though their risk profiles are dramatically different.

That makes the return of additional levels, sublevels, or verification tiers plausible. We do not expect DoW simply to recreate the five level CMMC 1.0 maturity model.

A more logical architecture would distinguish three separate questions:

  • What cybersecurity baseline applies?
  • How much independent assurance is required?
  • Does mission consequence require additional resilience or advanced protection?

That distinction could produce additional levels without unnecessarily creating another enormous universal control framework.

What a Future Assurance Structure Could Look Like

The new NIST material makes a layered assurance model more plausible than simply adding progressively larger numbered levels. One possible structure would look like this.

Level 1: FCI Basic Safeguarding

This would remain the entry point for organizations handling Federal Contract Information but not CUI, with basic safeguarding, self assessment, annual affirmation, and government enforcement.

CUI Baseline: NIST SP 800-171 Revision 3

Organizations handling CUI would implement the applicable SP 800-171 Rev. 3 baseline. The major distinction would then become how much independent assurance the government requires, not necessarily a different control set for every contractor.

  • Lower-risk environments could rely primarily on self assessment, SPRS or its successor, annual affirmation, continuous technical evidence, and targeted government validation.
  • Higher-risk environments could require independent C3PAO validation of the same CUI baseline, followed by continuous evidence and delta validation between full assessments.

Enhanced CUI: NIST SP 800-172 Revision 3

For CUI associated with a critical program or high-value asset, NIST now provides an official enhanced layer. SP 800-172 Rev. 3 supplements SP 800-171 with selectively applied requirements supporting advanced-threat resistance and cyber resiliency.

  • The enhanced requirements expressly address Confidentiality, Integrity, and Availability rather than confidentiality alone.
  • Federal agencies are not expected to select every enhanced requirement; selections are intended to reflect mission and business needs and ongoing risk assessments.
  • SP 800-172A Rev. 3 allows self assessment, independent third-party assessment, or government-sponsored assessment with varying rigor based on agency-defined depth and coverage.

Mission Resilience Overlay where operational consequence warrants it

Because SP 800-172 Rev. 3 already provides an enhanced CIA and cyber-resiliency layer, DoW may not need to create a new universal Level 4. A mission resilience overlay could instead be applied where loss of production, OT, recovery capability, or critical supplier availability creates meaningful defense consequence.

  • Potential emphasis areas include OT security, manufacturing continuity, recovery and restoration, cyber survivability, segmentation, supply chain resilience, and mission continuity.

This would let two contractors protect CUI to the same baseline while applying substantially different assurance and resilience requirements based on actual mission risk.

Levels May Become Assurance Tiers Instead of Larger Control Sets

There is another possibility that may make even more sense.

Rather than treating each level as a progressively larger control set, DoW could separate the cybersecurity baseline from the assurance tier and from any mission-resilience overlay.

For example:

Security Baseline

  • FCI Baseline
  • CUI Baseline
  • Enhanced CUI / Critical Program Baseline (selected SP 800-172 Rev. 3 requirements)
  • Mission Resilience Overlay where operational consequence warrants it

Assurance Tier

  • Self Assessed
  • Government Validated
  • C3PAO Validated
  • Enhanced Government and/or C3PAO Validation

That could produce combinations such as:

  • CUI Baseline + Self Assessed
  • CUI Baseline + C3PAO Validated
  • CUI Baseline + Government Validated
  • CUI Baseline + Mission Resilience Overlay + C3PAO Validated
  • Enhanced CUI Baseline + Government and/or C3PAO Validation

This may ultimately be more logical than simply numbering everything Level 1 through Level 5 (Like CMMC 1.0 had). The security requirement and the assurance mechanism solve different problems. One defines what must be implemented. The other defines how much evidence the government needs before it trusts the claim. Separating them could make the program significantly easier to scale.

Level 2 May Therefore Become a Risk Category Rather Than One Broad Verification Population

Whether DoW uses additional numbered levels or assurance tiers, the likely outcome is more deliberate differentiation among contractors.

Risk factors could include:

  • sensitivity and type of CUI;
  • program criticality;
  • mission consequence;
  • supply chain position;
  • threat exposure;
  • manufacturing dependency;
  • OT dependency;
  • history of cybersecurity incidents;
  • security posture history;
  • quality of continuous security evidence;
  • major architecture changes;
  • and government threat intelligence.

That creates a more logical assurance model.

A contractor handling limited CUI for a lower consequence activity might use the CUI baseline with self assessment and government oversight.

A contractor supporting a critical weapons program, sensitive engineering activity, or mission essential manufacturing capability may require independent C3PAO validation.

A contractor experiencing a major incident or material deterioration in security posture could be temporarily moved into a higher assurance tier even if it would not ordinarily require that level of scrutiny.

The important change is that verification follows risk.

C3PAOs Probably Survive, but Their Role Changes

From our perspective as a C3PAO, eliminating independent verification does not solve the underlying problem. The more logical reform is to use independent verification more intelligently. The future C3PAO may be less focused on repeatedly performing the same broad assessment against a large population every three years.

Its role could increasingly include:

  • establishing the initial trusted baseline;
  • validating system and CUI scope;
  • verifying inheritance and ESP dependencies;
  • conducting higher risk certification assessments;
  • validating the reliability of automated evidence;
  • performing technical testing;
  • conducting delta assessments;
  • investigating degraded posture;
  • assessing significant architecture changes;
  • performing event driven reassessments;
  • and validating critical suppliers.

The Cyber AB has now explicitly recommended continuous monitoring and delta assessments rather than automatically repeating complete assessments following significant changes.

That makes this portion of the prediction considerably less theoretical.

Continuous Assurance Is Becoming One of the Strongest Indicators

The strongest overall trend may be the movement away from point in time cybersecurity. This is now supported by both official Department policy direction and CMMC-specific leadership comments. In September 2025, the DoW CIO’s Cybersecurity Risk Management Construct formally called for a shift from snapshot assessments to dynamic, automated, and continuous risk management, with automation, continuous monitoring, cyber survivability, inheritance, and real-time risk visibility as core tenets. In September 2026, CIO Kirsten Davies applied the same principle directly to CMMC, saying cybersecurity must be continuous and operate at the pace of the threat.

Automation and AI are also becoming part of the broader DoW cybersecurity direction. At the September 2026 Billington CyberSecurity Summit, Davies said the Department cannot continue solving cyber scale primarily by adding people and must use technology ranging from automation to machine learning and AI. That is not an announced CMMC requirement or an indication that AI will replace assessors. It is, however, a meaningful signal that automated evidence collection, analysis, anomaly detection, and risk prioritization could become part of a future continuous-assurance model.

Sources: DoW CIO, Cybersecurity Risk Management Construct, September 24, 2025; DefenseScoop, September 9, 2026; Nextgov/FCW, September 10, 2026.

The future program could continuously evaluate measurable conditions such as:

  • endpoint protection health;
  • MFA and identity posture;
  • privileged account status;
  • logging coverage;
  • configuration drift;
  • vulnerability exposure;
  • patch status;
  • encryption status;
  • backup verification;
  • security tool deployment;
  • network segmentation;
  • incident detection capability;
  • and evidence currency.

That does not necessarily mean every contractor streams raw telemetry to the government.

A more practical model would define approved security indicators and evidence sources whose reliability is validated independently.

The Three Year Cycle Could Survive While the Assessment Changes

Continuous assurance does not necessarily eliminate the existing three year concept. It could fundamentally change what happens within that period.

Year 1: Full Baseline Validation

Year 1 establishes the trusted baseline.

For an organization requiring independent verification, the assessment could validate:

  • CUI and system scope;
  • SSP accuracy;
  • security requirement implementation;
  • technical configuration;
  • policies and procedures;
  • inherited controls;
  • CSP and ESP dependencies;
  • evidence generation;
  • continuous monitoring capabilities;
  • telemetry reliability;
  • recovery;
  • and resilience or OT requirements where applicable.

Year 2: Continuous Assurance and Delta Validation

Year 2 would focus primarily on whether the trusted baseline remains valid.

Review could concentrate on:

  • changed controls;
  • degraded conditions;
  • new systems;
  • new providers;
  • CUI flow changes;
  • security incidents;
  • significant vulnerabilities;
  • configuration drift;
  • POA&M activity;
  • sampled requirements;
  • and objectives requiring human judgment.

A stable environment with healthy evidence should require substantially less assessment effort than Year 1.

Year 3: Continuous Assurance and Risk Based Validation

Year 3 could provide broader confirmation that the original baseline still accurately represents the organization.

The review could consider:

  • security posture trends;
  • significant architecture changes;
  • recurring weaknesses;
  • incident history;
  • resilience and recovery testing;
  • previously degraded controls;
  • random sampling;
  • and higher risk requirements.

The next cycle would then refresh the full baseline.

Material Events Could Trigger Reassessment at Any Time

Cybersecurity risk does not follow an assessment calendar.

Potential triggers could include:

  • cloud migration;
  • replacement of a major CSP or ESP;
  • major network or identity changes;
  • merger or acquisition;
  • expansion of the CUI boundary;
  • significant cyber incident;
  • persistent telemetry loss;
  • repeated degraded conditions;
  • major manufacturing or OT changes;
  • and government threat intelligence.

The future program could therefore be both calendar based and event driven.

It could also allow the contractor to move temporarily between assurance tiers when risk changes.

Continuous Assurance Creates the Need for Operational Status

Continuous monitoring creates another problem with today’s binary mentality. A validated environment will occasionally experience temporary technical failures. That does not necessarily mean the security requirement was never implemented.

A logical operational status structure might therefore include:

  • Compliant: The validated baseline is operating normally.
  • Degraded: A limited temporary deficiency has been detected and is actively being corrected.
  • Remediation Required: A more significant or persistent deficiency requires formal corrective action.
  • Suspended: Current security risk exceeds the acceptable threshold and the organization’s validated status is temporarily restricted.
  • Failed or Noncompliant: The organization no longer satisfies the required cybersecurity baseline.

These labels are our prediction, not an announced DoW model.

The underlying need, however, becomes increasingly logical if continuous monitoring is adopted.

Baseline Conformity and Operational Posture Should Be Separate

The planned transition to Rev. 3 means the current 110 point score should not be assumed to survive unchanged. A cleaner future model separates two measurements.

Baseline conformity answers:

Has the required security baseline been implemented?

Operational posture answers:

Is that validated baseline currently operating effectively?

An organization could therefore be:

  • Validated + Compliant
  • Validated + Degraded
  • Validated + Remediation Required
  • Validated + Suspended
  • Failed + Noncompliant

That model is also compatible with multiple assurance levels.

An organization could retain the same underlying CUI security baseline while moving between assurance tiers or operational states according to risk.

Additional Levels and Operational Status Solve Different Problems

This distinction is important.

A Level or Assurance Tier should answer:

How much cybersecurity and independent assurance does this contractor require?

Operational Status should answer:

What is the current condition of the validated environment?

For example:

A contractor could be:

Level 2B / C3PAO Validated / Compliant

then temporarily become:

Level 2B / C3PAO Validated / Degraded

without automatically dropping to Level 2A.

If a major event materially changes its risk profile, however, the government could require stronger validation or move the contractor into a higher assurance category.

That is much more flexible than using one number to describe security requirements, assessment rigor, and current cybersecurity condition.

Integrity and Availability May Become More Important

CMMC has historically focused primarily on confidentiality because protecting FCI and CUI is its central purpose. But mission cybersecurity is larger than confidentiality. A manufacturer can protect every engineering drawing while ransomware prevents it from producing a critical component. A supplier can preserve confidentiality while compromised configurations undermine product integrity. An organization can meet information protection requirements while an unavailable system prevents delivery of the mission.

The future model may therefore increasingly recognize:

  • Confidentiality: Can sensitive information remain protected?
  • Integrity: Can the Department trust that information, systems, configurations, and outputs have not been improperly altered?
  • Availability: Can the contractor continue supporting the mission during and after a cyber event?

SP 800-171 Rev. 3 Does Not Create a Full CIA Program, but SP 800-172 Rev. 3 Provides an Official Enhanced Layer

NIST SP 800-171 Revision 3 remains the foundational CUI protection baseline and should not be treated as a universal mission-resilience standard.

NIST SP 800-172 Revision 3 changes the prediction materially. NIST finalized it in May 2026 as a supplement for CUI associated with critical programs and high-value assets, and it explicitly provides enhanced protection for Confidentiality, Integrity, and Availability while supporting cyber-resiliency objectives.

This gives DoW a ready-made mechanism to apply stronger requirements selectively, based on mission and business need, rather than imposing another large universal control set on every contractor handling CUI.

Our prediction therefore shifts from a new Level 4 being the likely answer to a more flexible structure: SP 800-171 Rev. 3 establishes the baseline; selected SP 800-172 Rev. 3 requirements provide the enhanced resilience layer; and assurance rigor is determined separately according to risk.

Class Deviation 2026 O0025 Revision 3 Changes the Timing Picture

The current class deviation does not repeal CMMC, amend 32 CFR Part 170, or officially move Phase 2 to 2028. But it does make the suspension operational within the acquisition process. November 10, 2026 therefore cannot simply arrive and automatically restore the original Phase 2 architecture. DoW must affirmatively determine what comes next.

Why 2028 Is Becoming Increasingly Relevant

November 2028 was already the original full implementation boundary. Nothing published to date says that Phase 2 resumes in 2028.

But a significant transition through 2027 and potentially toward the existing 2028 implementation boundary is increasingly plausible because:

  • the acquisition system has been adjusted for the suspension;
  • Rev. 3 still needs to be integrated;
  • major program changes may require rulemaking;
  • the Task Force is reconsidering foundational assumptions;
  • and existing acquisition structures still recognize a post 2028 environment.

That gives DoW time not merely to restart CMMC, but potentially to restructure the level and assurance model itself.

What the Most Likely Post Review Architecture Looks Like

Based on the cumulative indicators, our current prediction looks approximately like this. The are not levels but layers

Layer 1: Information Classification and Scope

The government accurately identifies FCI, CUI, and the information boundary before assigning cybersecurity requirements.

Layer 2: CUI Security Baseline

The contractor receives the appropriate baseline, with NIST SP 800-171 Rev. 3 becoming the likely CUI foundation.

Layer 3: Mission and Risk Classification

Information sensitivity, supplier criticality, threat exposure, operational consequence, OT dependency, and security history determine the level of assurance required.

Layer 4: Assurance Tier

The contractor is assigned self assessment, targeted government validation, C3PAO validation, or enhanced government and third party assurance.

Layer 5: Initial Trusted Baseline

The appropriate assessment establishes confidence that scope, implementation, architecture, and evidence mechanisms are trustworthy.

Layer 6: Continuous Security Evidence

Technical evidence continuously demonstrates whether validated cybersecurity capabilities remain operational.

Layer 7: Operational Status

The contractor maintains a current posture such as Compliant, Degraded, Remediation Required, Suspended, or Failed.

Layer 8: Delta Validation

Years 2 and 3 concentrate on changes, degradation, sampled controls, and areas requiring human judgment rather than blindly repeating the entire original assessment.

Layer 9: Event Driven Reassessment

Material system changes, incidents, acquisitions, provider changes, CUI changes, or security deterioration trigger additional validation.

Layer 10: Enhanced Security and Mission Resilience Overlay

Critical programs and high-value assets can receive selected SP 800-172 Rev. 3 enhanced requirements, with additional OT, manufacturing continuity, recovery, or mission-resilience requirements where operational consequence warrants them.

What This Means for the Future “Levels”

If DoW retains numbered CMMC levels, the most defensible prediction is a simpler structure than the earlier Level 2A/2B/3/4 ladder:

  • Level 1 remains the FCI basic-safeguarding tier, primarily self assessed.
  • Level 2 remains the CUI baseline, increasingly based on SP 800-171 Rev. 3, but with assurance rigor determined separately as self, targeted government, or C3PAO validated.
  • Level 3 or an equivalent enhanced tier uses selected SP 800-172 Rev. 3 requirements for critical programs, high-value assets, advanced threats, and stronger CIA or cyber-resiliency needs.

A separate Mission Resilience Overlay could then address OT, manufacturing continuity, recovery, and availability where operational consequence justifies it. This is now more plausible than creating another universal Level 4 control set.

The cleaner long-term model is therefore: Security Baseline + Assurance Tier + Operational Status + Resilience Overlay.

For example: CUI Baseline / C3PAO Validated / Compliant, or CUI Baseline + Enhanced Resilience Requirements / Government and C3PAO Validated / Degraded.

That is a more precise representation of cyber risk than treating two very different organizations as equivalent merely because both are labeled CMMC Level 2.

What This Means for C3PAOs

A more granular model could actually strengthen the purpose of the C3PAO while reducing unnecessary assessment volume. C3PAOs would focus where independent trust matters most.

Their role could include:

  • initial certification;
  • higher assurance tiers;
  • delta assessment;
  • evidence validation;
  • event driven reassessment;
  • technical testing;
  • critical supplier reviews;
  • and validation of degraded or remediated environments.

Independent assessment becomes targeted rather than indiscriminate.

What This Means for OSCs

Contractors would receive a security and assurance burden that better reflects actual risk. A smaller organization handling limited CUI might no longer face the same verification burden as a critical manufacturer supporting a weapon system. Conversely, a mission critical supplier could face requirements beyond basic CUI confidentiality because the Department also needs confidence that the supplier can continue operating. That is arguably a more defensible model for both security and cost.

The Crystal Ball Today

The cumulative indicators now point toward a program that retains the original purpose of CMMC while substantially changing the mechanism used to achieve it.

The strongest trends are:

  • NIST SP 800-171 remains the foundation while Revision 3 replaces the current Revision 2 architecture.
  • CUI identification becomes a prerequisite to determining compliance scope.
  • Additional assurance tiers or sublevels remain plausible, but NIST SP 800-172 Rev. 3 now provides a stronger case for a selectable enhanced-security overlay rather than another universal numbered level.
  • Risk determines both the cybersecurity baseline and the intensity of independent verification.
  • C3PAOs remain relevant, but independent assessment becomes more targeted.
  • Continuous evidence supplements point in time certification.
  • Automation, machine learning, and AI increasingly appear likely to support continuous evidence analysis and risk prioritization, while human assessors remain responsible for professional judgment, scope, architecture, and assurance decisions.
  • Delta and event driven reassessment replace unnecessary repetition.
  • Operational status distinguishes temporary degradation from failure of the security baseline.
  • Integrity, Availability, and cyber resilience now have a direct NIST foundation in SP 800-172 Rev. 3 for critical programs and high-value assets, while OT and manufacturing continuity remain likely mission-specific extensions where consequence warrants them.
  • The implementation transition could extend materially through 2027 and potentially toward the existing 2028 boundary.

What Makes the Most Sense

The best solution is probably not eliminating CMMC. It is fixing what CMMC was trying to accomplish. The Department needs assurance that contractors actually protect sensitive information and can support the defense mission. Contractors need requirements that are understandable, properly scoped, technically meaningful, and economically sustainable.

A mature program should not treat:

A small supplier with limited CUI
and
A critical manufacturer whose compromise could interrupt weapons production as identical risks simply because both technically fall under Level 2.

The most logical future model therefore separates:

  • the cybersecurity baseline, likely SP 800-171 Rev. 3 for CUI;
  • the level of independent assurance;
  • the current operational posture;
  • selected SP 800-172 Rev. 3 enhanced requirements and mission resilience overlays where risk warrants them.

The simplest description may still be the best:

Year 1: Establish trust.

Years 2 and 3: Continuously demonstrate trust.

Material change: Revalidate trust.

Temporary degradation: Correct the problem before trust is lost.

Persistent or systemic failure: Suspend or revoke trust.

And above all:

Risk determines how much trust must be independently verified.

That would transform CMMC from a predominantly point in time compliance program into something much closer to what cybersecurity assurance should actually provide:

A continuously defensible, risk based cybersecurity assurance model for the Defense Industrial Base.

That is where the indicators are increasingly pointing.

From our perspective, it is also where the program makes the most sense.

 

You May Also Like…