Talk to an Expert
Blog · September 15, 2021

UPDATED: Get Ready for More CMMC Changes

The DoD weighed in yesterday with a promise of additional changes, and soon, to the Cybersecurity Maturity Model Certification (CMMC) program.

We are told these changes will reflect industry feedback plus “internal government activities”. It appears they are a result of ongoing and wide-ranging reviews of the CMMC program that started this past spring.

All aspects of the CMMC program are under consideration in this review. This includes all levels of cybersecurity compliance as well as the role of the independent, third-party CMMC “Accreditation Body” of industry representatives overseeing auditors to review DIB companies’ cybersecurity practices.

The CMMC Accreditation Body has been criticized both generally and in comments considered in this review as being opaque and characterized by a lack of clarity in results and direction. This criticism perhaps led to the statement by Christine Michienzi, CTO of Defense, at a recent conference in Maryland that even the process of independent auditors versus DOD certification versus self-certification are all being reviewed as the best mechanism to use. Choosing the latter two would constitute a departure from the CMMC as it has been rolled out over the last few years, perhaps making the efforts of the accreditation body superfluous.

The best advice we can give right now is this:
Stay tuned because there is one thing we know for sure. There will be changes to the CMMC and those will change as well.

UPDATE 09/20/2021:

We told you there would be changes. According to InsideCybersecurity.com, the Department of Defense is not planning to release the final rule cementing CMMC until the end of 2021, due to ongoing internal reviews. As is tradition, that could also change at any minute. We’ll be sure to keep you updated with any additional changes.

See the enclave in action.

The Compliant Computing Enclave keeps CUI inside one boundary, with your endpoints out of scope and the evidence trail already built.

Talk to an Expert
Keep reading

More from the blog

September 3, 2026

Week 6: Too Embedded to Reject

How GCC High vendor lock-in changes the decision Last week, we examined the assessor problem. This...

Read it →

August 26, 2026

Week 5: FedRAMP’s Assessor Problem

Why FedRAMP assessor independence matters Last week, we examined the larger architecture problem. This week, we...

Read it →

August 20, 2026

Week 4: The Problem Did Not Stop with Encryption

Why GCC High security architecture matters Last week, we focused on the encryption question. This week,...

Read it →