Pentagon pores over heaps of industry feedback on CMMC reform
Pentagon officials are sorting through a flood of industry feedback about the controversial Cybersecurity Maturity Model Certification program as the department weighs next steps for reform efforts, Defense Department CIO Kirsten Davies said Wednesday.
In July, Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey announced the suspension of CMMC Phase 2 requirements that were set to take effect this fall, which included third-party attestation of compliance. A new CMMC Reform Task Force was established to review the entire program, and the department issued a request for information to gain input from contractors affected by the regulations, which have previously been criticized for being too onerous and costly for small and medium-sized businesses that want to work with the Pentagon.
Responses to the RFI were due Aug. 14.
“We had … over 1,100 responses, which is actually a lot because some of those were from groups like the Cloud Security Alliance, where they had a bunch of folks that came together to provide a response. Over 10,000 pages of documentation that the team is all reading. AI is not reading that. I have humans reading all of the feedback that everybody provided,” Davies said during remarks at the Billington CyberSecurity Summit.
She noted that the department also held meetings across the country that drew more than 3,000 attendees, and Davies also took meetings with the Cyber AB Board, third-party assessor organizations and various small businesses.
The Pentagon is seeing a lot of support for the CMMC Phase 2 pause, she noted.
“More than 50% of the respondents were in favor of us putting this on hold and seeking some level of reform. A lot of this has been very, very positive,” Davies said. “The negative feedback we received was: ‘Why did this even start, why were we required to do this?’ … CMMC was hitting small to medium-sized businesses really, really hard and inappropriately hard. So we have some work to do.”
Meanwhile, the department has also received feedback from the third-party assessor base, she noted.
“They’re concerned, of course, that how are we going to prove … that the defense industrial base is following federal policies? This is still something that we need to resolve for,” Davies said.
During the CMMC pause, DOD is expected to enforce cybersecurity compliance with the NIST Special Publication 800-171 Revision 2 standard through self-assessments and select government-led assessments.
The pursuit of CMMC reform doesn’t mean the Pentagon has become less concerned about cybersecurity, Davies suggested.
“Let me be clear: cybersecurity is of utmost importance, not only inside the building but also across our defense industrial base. So this isn’t about whether cybersecurity is important or not. It is. It’s critical. It’s vital, especially with the advent of frontier AI models and defending against attacks that are at speed, at scale that we’ve never seen before,” Davies said.
The CMMC framework wasn’t dynamic enough, she suggested, and the Pentagon is looking to move away from “point-in-time assessments” of contractors’ cybersecurity posture.
“What we want to do is a couple of things. Compliance equals compliance. Compliance doesn’t equal security. Compliance equals a point-in-time check of where are you right now. We all know that cybersecurity is a dynamic process. It needs to be contiguous and continuous, and it needs to be at … the pace of the threat in and of itself. That’s kind of number one,” Davies said.
The department also has concerns about another potential cybersecurity vulnerability: industry’s operational technology.
“The important point that we have is that our defense industrial base produces things for us. Manufacturers’ operational technology is so critical right now, and nowhere in CMMC was there even mention around how to build cyber resilience for a manufacturing line. It’s all about … data, right? And so information security, 100%, that’s important. That’s also federally mandated elsewhere. But the handling of federal data doesn’t necessarily build cyber resilience for small to medium manufacturing companies. So this is where we’re headed,” Davies said.
The Pentagon has also heard criticisms related to controlled unclassified information, according to a recent LinkedIn post from the CIO’s office, which noted that feedback from the RFI and listening sessions indicated that the department’s “inconsistent” CUI marking has created “operational friction.”
“Industry stakeholders and defense leaders have identified government CUI designation and marking practices as a primary operational challenge for the defense supply chain,” officials wrote in the post, adding that stakeholder recommendations include “enforcing mandatory, disciplined CUI marking and portion marking within government program offices” as well as establishing “clear, standardized guidance on common data types to eliminate ambiguity in CUI scope.”