CMMC compliance faces its third-party reckoning
CMMC compliance is about to get an answer it has needed for two years: whether the Pentagon's mandatory third-party audit at Level 2 survives a reform process whose public comment window closes this month, with the Task Force's own recommendations due by mid-September 2026.
By Katie Delaney · 2026-08-18 · 13 min read
Why CMMC compliance just hit a fork in the road#
Somewhere in the Pentagon this month, a comment period is quietly closing, and the outcome could reshape CMMC compliance for every contractor with a badge and a network diagram. The Cybersecurity Maturity Model Certification Reform Task Force is deciding whether CMMC compliance at Level 2 still needs a mandatory third-party audit, the C3PAO assessment that has defined the programme since its earliest drafts, or whether self-attestation can carry more of the weight than it already does. ClearanceJobs broke the story on 17 August 2026, and the answer is due by mid-September.
The Department of Defense's own CMMC programme page frames the model plainly: three tiers of cyber hygiene, scaled to how much controlled unclassified information a contractor actually handles, building on the Department of War's original 2021 CMMC 2.0 framework. Phase 2 of the rollout, the stage that would have made third-party assessment mandatory for most Level 2 primes, is already suspended while a Reform Task Force works out a steadier strategic direction, per ClearanceJobs's reporting. That pause is precisely why the audit question now sits so exposed.
What CMMC level 2 requirements actually ask of a contractor#
Strip away the acronym and CMMC level 2 requirements map closely onto NIST SP 800-171, the roughly 110 controls that have governed defence-adjacent data handling for years. A contractor with genuinely sensitive controlled unclassified information is meant to prove those controls hold, either by self-attesting against them or by inviting a Certified Third-Party Assessment Organisation into the burrow to check the paperwork against the practice. The Reform Task Force's question is not whether the controls stay, nobody is proposing that, it's whether an outside auditor with a clipboard remains the price of entry.
NIST owns the underlying standard; the Pentagon owns the enforcement mechanism sitting on top of it, largely through the DFARS clause that makes CMMC compliance a condition of contract award. Two agencies, two jobs, one shared standard: NIST writes the controls, the Pentagon enforces them through contract language, and the contractor sits in the middle trying to satisfy both without a single unified rulebook to point to.
One quiet procedural detail is worth a sentence for anyone tracking the process closely: this particular reform effort carries no formal Federal Register docket number. It is running through the Task Force's own request-for-information and public-comment channel rather than the numbered notice-and-comment process that produced the original CMMC rule, the kind of process that would normally show up on the Federal Register's Defense Department listings. That is not necessarily sinister, task forces often work faster this way, but it does mean the paper trail is thinner than usual.
For prime contractors, subcontractors, and the vendors who sell into either, CMMC compliance has stopped being a distant clause buried in a solicitation and started being an active budget line. Legal teams are watching the Reform Task Force's comment period the way hunters watch a hedgerow at dusk, alert for the moment the policy actually moves rather than merely rustles. Whatever the Task Force recommends in September, the direction of travel already tells contractors something: CMMC compliance requirements are not going away, only the enforcement mechanism sitting on top of them is genuinely up for debate.
The reform push did not appear from nowhere. Contractors, industry associations, and members of Congress had spent over a year flagging the same complaint from different angles: a compliance regime that took years to reach Level 2 primes was still finding its footing on cost, timeline, and workforce capacity even before the ink dried on the first assessments. The Task Force exists because the gap between the rule on paper and the rule in practice had grown too wide to ignore, not because anyone in the Pentagon has gone soft on cyber standards.
The audit gap behind CMMC compliance requirements#
The Government Accountability Office has already done the counting, and the numbers explain why the Reform Task Force has a genuine dilemma rather than a rubber-stamp decision. As of December 2025, only 92 C3PAOs were authorised nationally to perform the third-party assessments that CMMC compliance requirements are meant to rest on. Meanwhile 69% of defence contractors currently self-attest their own compliance, and just 30% have been validated by an actual third-party assessor. The gap between what the rule demands and what the assessor market can deliver is the whole story.
Ninety-two firms cannot credibly audit the tens of thousands of contractors who touch the defence supply chain, and the GAO found that DoD has not documented how it plans to handle that shortfall. Every contractor waiting for an assessor slot is, in effect, self-attesting by default, not by choice, and that distinction gets lost whenever the debate turns political. A vulpine kind of cunning has crept into the system: contractors keep their compliance story tidy enough to survive a paper review while the actual den of controls, the access logs, the patch cadence, goes largely unchecked.
C3PAOs authorised nationally, as of December 2025
It's worth being precise about what these percentages do and do not say. A 69% self-attestation rate is not proof of 69% non-compliance, most of those contractors may well be meeting CMMC compliance requirements in good faith. What it proves is something narrower and arguably more important: the programme currently has no reliable way to tell the difference between a contractor who has earned its clean bill of health and one who has simply never been checked. That distinction is precisely what a mandatory third-party audit was built to resolve, and precisely what the Reform Task Force must now decide is worth the cost of keeping.
For a prime contractor, the audit gap is not an abstract policy puzzle, it is a live subcontractor-management problem. Primes are increasingly expected to flow CMMC compliance requirements down to every subcontractor touching CUI, yet many of those smaller firms have no realistic path to a C3PAO slot before their next contract renewal. That leaves primes choosing between accepting a subcontractor's word, absorbing the compliance burden themselves, or quietly working around smaller vendors altogether, none of which is a comfortable position for a programme meant to raise the floor rather than shrink the field.
Three failure modes, one blunt post, and the GAO's own numbers#
Not every useful analysis comes from a formal report. On 17 August 2026, defence-sector commentator @ChadMG1720 put the whole debate in one blunt post: "The goal was admirable & needed in some form. But the way this was set up was impossible to administer, especially once CPAs and attorneys ran from it. And the largest entities were the ones that were exempt anyway." Read against the GAO's numbers, that is not a hot take, it is a fairly precise diagnosis.
The goal was admirable & needed in some form. But the way this was set up was impossible to administer, especially once CPAs and attorneys ran from it. And the largest entities were the ones that were exempt anyway.
Three separate failures sit inside that one post. An unadministerable design shows up directly in the 92-C3PAO capacity crunch: a system built to assess an entire defence supply chain cannot run on a hundred firms. A professional exodus, accountants and attorneys retreating from an ambiguous liability, helps explain why 69% of contractors land on self-attestation as the path of least resistance rather than active evasion. And uneven application, the largest primes carrying enough leverage to negotiate around requirements that smaller subcontractors absorb in full, is the quiet undercurrent beneath every CMMC compliance conversation in the industrial base.

The exemption point in that post deserves its own line. Waivers, national-security carve-outs, and negotiated timelines have historically clustered around the primes with the deepest government-relations teams, the ones best equipped to argue for flexibility. Smaller subcontractors, by contrast, tend to encounter CMMC compliance as a rigid pass or fail gate with far less room to negotiate, which is precisely the kind of uneven application that erodes trust in a programme meant to apply evenly across the defence industrial base.
None of this makes the case for scrapping oversight altogether, and nobody serious is arguing that. It makes the case for an assessor market sized to match the promise the programme makes. A rule that only a hundred firms can enforce is a rule that will always run behind the contractors it is meant to police, no matter how sound the underlying controls look on paper.
There is a second track for contractors handling the most sensitive information: the Defense Industrial Base Cybersecurity Assessment Center runs its own high-assurance reviews outside the C3PAO market entirely, a reminder that the defence supply chain is a genuinely critical piece of national infrastructure, formally recognised as such by CISA. The stakes of getting the audit question wrong are not abstract.
What CMMC level 2 requirements mean for the buyers already asking#
While the Task Force deliberates, the questions coming up the supply chain have not paused for anyone. Buyers, compliance officers and nervous subcontractors are all trying to settle the same two things at once: what applies to them, and when. A marketing team that treats this policy fight as background noise is leaving genuinely warm, high-intent attention to a competitor with a faster content calendar.
None of this is especially crowded ground to write about, which is unusual territory for a topic this consequential. That gap between how hard it is to be found on the subject and how high the business stakes are is exactly the kind of opening a sharp content strategy exploits before a larger competitor notices it. Cybersecurity vendors who publish clearly on CMMC compliance now, rather than waiting for the Reform Task Force to settle the question for them, are the ones whose pages will already be indexed and trusted when the recommendations land in September.
It is also worth noticing where these searches increasingly land. Compliance officers researching what is CMMC or CMMC compliance requirements are just as likely to ask an AI assistant for a quick summary as they are to click through ten blue links, which means clear, source-linked, quotable answers matter as much as traditional rankings now. A page that states the GAO's numbers plainly, with the source attached, is the kind of page a generative answer engine can lift directly, badge and all.
The narrowest question tells the sharpest story. Almost nobody asks what CMMC compliance actually costs, but anyone who does is close to a buying decision, budgeting for an assessor, a consultant or a compliance platform rather than idly researching. That is exactly the kind of low-traffic, high-intent question worth building a dedicated page around, the sort of work our SEO and GEO team tracks alongside broader content marketing and PPC pushes for cybersecurity clients.
How defence contractors should prepare while the CMMC compliance question hangs open#
Waiting for mid-September is not a strategy, it is a delay dressed up as one. Contractors serious about CMMC compliance should treat this comment period the way a fox treats a change in scent on a familiar trail: worth noticing, not worth abandoning the den over. Map your controlled unclassified information now, stress-test your system security plan against the current NIST SP 800-171 baseline, and decide deliberately whether you are self-attesting because you have genuinely earned it or because the assessor market simply has not reached you yet.
The marketing side of this story matters just as much as the compliance side. Buyers researching CMMC compliance requirements are reading vendor sites for confidence signals long before they pick up a phone, and a brand that explains its posture clearly, the kind of clarity our brand strategy work is built around, earns trust that a generic compliance badge never will. It sits alongside the same policy-watching discipline behind our pieces on the Cyber Resilience Act's reporting deadline and the EU AI Act's robustness rules, two more dated clocks currently running on cybersecurity teams.
Keep an eye on the wider hedgerow too, not just this one policy thread. The Cyber Resilience Act, the EU AI Act, and now the CMMC Reform Task Force are all running on their own clocks, and a contractor tracking only one of them is planning with half the map. The organisations that treat compliance monitoring as a standing discipline, not a quarterly fire drill, are the ones who will read September's recommendations calmly rather than scrambling.
Treat the next month as a genuine prowl rather than a passive wait. Read the recommendations the day they land, brief leadership on what changes for your specific contract vehicle, and update customer-facing compliance language the same week rather than the same quarter. The contractors who move fastest after mid-September will look, to everyone watching, like the ones who saw this coming. In a sense, they did.
Frequently asked questions#
What is CMMC?
CMMC (Cybersecurity Maturity Model Certification) is the Department of Defense's tiered framework for verifying that contractors handling controlled unclassified information meet baseline cyber standards. It has three levels, with Level 2 built largely on NIST SP 800-171 controls, and CMMC compliance is currently required in some form for most defence contracts touching sensitive data.
What does CMMC compliance cost?
Costs vary widely by company size and CUI footprint, but typically include gap-assessment consulting, remediation of technical controls, staff training, and, if a third-party audit is required, the C3PAO assessment fee itself. Search interest in CMMC compliance cost is low in volume but high in intent, since it's usually typed by someone already budgeting.
Will CMMC Level 2 still require a third-party audit?
That's exactly what the Reform Task Force is deciding. Its public comment period has closed and recommendations are due by mid-September 2026. Nothing is confirmed yet: the mandatory C3PAO assessment could survive, shrink to fewer contract types, or give way to broader self-attestation.
What happens if a contractor self-attests incorrectly?
Inaccurate self-attestation under CMMC compliance requirements can expose a contractor to False Claims Act liability, not just a failed audit. That legal exposure is part of why the GAO's finding that 69% of contractors currently self-attest matters so much to the reform debate.
Is CMMC Phase 2 still suspended?
Yes. Phase 2, the stage that would make third-party assessment mandatory for most Level 2 contracts, remains suspended while the Department of War and its Reform Task Force settle on a steadier strategic direction for the programme.
When will the CMMC Reform Task Force publish its recommendations?
The Task Force's recommendations are due by mid-September 2026, according to ClearanceJobs' reporting on the comment period. There's no confirmed public release date beyond that window yet.
Does the Reform Task Force affect CMMC Level 1 or Level 3?
The current debate centres on Level 2, since that's where the mandatory third-party audit question lives. Level 1 has always relied on self-assessment, and Level 3 assessments are handled directly by the government rather than a C3PAO, so both sit largely outside this particular reform question.
Read more on this topic#
Twenty five days until the cyber resilience act starts counting hours
Another dated compliance clock, this one from Brussels rather than the Pentagon.
Read the pieceNobody touched the turbine. They took the office.
1,140 industrial cybersecurity incidents in Q2, and not one reached a control system.
Read the pieceAI Penetration Testing Just Scored 95%: What GPT-5.6-Cyber Actually Changes
OpenAI's offense-grade model completes 95% of advanced pentest tasks. Who audits the vetting?
Read the piecePatch Tuesday, Exploited Wednesday: What Vulnerability Management Services Must Prove Now
Five CVEs this week collapsed the gap between patch and active exploitation.
Read the piece
Need help telling your CMMC compliance story clearly?
Our team at folkfox helps defence-adjacent and cybersecurity brands turn dense policy shifts like this one into content buyers actually trust and search engines actually rank.