Exclusive Offer: Free CMMC Readiness Assessment
Exclusive Offer: Free CMMC Readiness Assessment
Signed in as:
filler@godaddy.com
Did you know in Title 32 CFR that C3PAO assessments were originally tied to DoW contractors advancing from CMMC Level 2 to Level 3? There is nothing in Title 32 that directly connects the necessity for C3PAO assessments to those contractors seeking Level 2 certification. The same is true In Title 48 CFR. There is nothing that directly connects the necessity of C3PAO assessments to contractors seeking Level 2 certification. Contracting offices added these requirements in their contacts. This may be gray legal and subject to challenge. Contractors could seek legal injunction based on DoW overreach beyond regulations. This is possible with the new DoW ATS, written to transform legacy DoW to a modernized contracting machine. An alternative perspective is this was intentional by the DoW leaving strategic space for the DoW to back away from pressing the need for C3PAOs should the CMMC program get caught up in a performance quagmire as it has.
Added Friday 29 August
CMMC must be conducted with deliberate diligence and not with shortcuts to speed.
We care for you and your ability to deliver to the DoW what it needs to secure our nation.
Our efforts will make a meaningful difference for your business.

CMMC is currently suspended to allow for a full review of its impacts on small and medium sized DIB contractors. However, all DoW DIB contractors must maintain or continue to strive to meet NIST 800-171 r2, FAR, DFARS, ITAR and other federal and DoW compliance requirements. An example is the 7012 security clause requirements in current contracts.
This suspension does not mean you can or should end or pause your CMMC program efforts. New contracts may be limited to CMMC Level 1 or Level 2 Self Assessments. You still have to undergo the rigor of implementing NIST 800-171 r2 as expected in the NIST 800-171 Assessment Guide. However, the contracting office may opt to add CMMC Level 2 C3PAO assessments and certification.
The DoW CIO is looking for "bureaucratic barriers that impede our speed to capability to delivery." The DoW states "our approach must be realistic, business-enabling, scalable, and aligned with our broader strategic goals." The current CMMC program inhibits this approach due to administrative compliance burden.
The DoW is reviewing how to adjust the CMMC program to align with Secretary of War's Acquisition Transformation System (ATS).
For starters, the November 2026 Phase 2 Transition is suspended.
Last updated Friday 29 August, 2026.
Myers Advisory Services' (MAS) Assessment:
It appears the DoW is going to attempt to outpace our adversaries in new weapons systems and technologies versus assuring or validating they are secure. The upside is this approach transfers a portion of security implementation and administrative costs to research and development within SMBs. If our assessment is accurate, this could be a risky strategy. Look for updates here.
Contact us for guidance and updates during this volatile and uncertain CMMC climate change.
We'll help you prepare for a broader range of continuous changes within the DoW CIO security frameworks, models, and compliance.
Maintain your progress in the CMMC program; don't stop and don't regress. Step forward in a less urgent pace but continue forward. Why pay twice for progress when you are already on your way. Security mandates will continue, reporting criteria will change.

Empowering your business with strategic AI augmentation, operational excellence solutions, and CMMC compliance. Contact us to learn more.

Expert in leadership, organizational development, AI solutions, and CMMC compliance, Dr. Myers' personal service and professional approach focuses on you and your goals.
Enjoy a 10% discount on your first consultation when you subscribe.