CMMC Works. Now let’s sharpen it.

https://cdn.nextgov.com/media/img/cd/2026/08/17/GettyImages_2287542899/open-graph.jpg

Kevin Carter/Getty Images

ByKatie Arrington,
Former official performing the duties of the Pentagon CIO

August 17, 2026 03:19 PM ET

COMMENTARY | This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change.

I built the Cybersecurity Maturity Model Certification because self-attestation was failing our war industrial base. Contractors could simply promise they were following basic cybersecurity practices, with no verification behind that promise. Our adversaries noticed that gap long before Washington did — and they have not eased up since. If anything, the opposite is true.

Nation-state actors and the ransomware crews they tolerate or direct are more aggressive, better funded, and faster than they were five years ago. This is not the moment to loosen the standard. The Defense Federal Acquisition Regulation Supplement requirements behind CMMC should not change, and I would not support it if they...

Copyright of this story solely belongs to nextgov.com. To see the full text click HERE

Read more