Cyber AB Identified Potential CMMC Program Changes

The accreditation body for the Pentagon's cybersecurity initiative flagged adjustments as industry awaits a Defense Department review.

Updated on Oct. 6, 2026 in Cybersecurity

Isometric editorial illustration of a clean, monolithic steel pillar representing defense cybersecurity architecture against a neutral background.
The Cyber AB has identified potential structural changes to the Pentagon's cybersecurity certification program as the Defense Department continues its formal review. AI Illustration. Upload story photo >

Live Poll

Should the federal government require mandatory third-party cybersecurity certifications for all defense contractors?

The Cyber AB, which serves as the official accreditation body for the Pentagon's Cybersecurity Maturity Model Certification (CMMC) program, has identified potential changes to the initiative. These updates were surfaced by leadership during a recent town hall meeting.

Why it matters

The program is currently under a formal review by the Defense Department, creating an uncertain timeline for defense contractors who must meet these standards. Stakeholders across the defense industrial base are waiting for the final results of this institutional assessment.

The Cyber AB identified potential modifications to the CMMC accreditation framework currently under evaluation. The specific technical requirements and implementation metrics remain unfinalized pending the conclusion of the Defense Department review.

The players

Cyber AB

The official accreditation body responsible for overseeing the Pentagon's Cybersecurity Maturity Model Certification program.

Matthew Travis

The CEO of the Cyber AB who provided updates on the program during a recent town hall.

Defense Department

The United States executive department responsible for coordinating and supervising all agencies and functions related to national security.

The details

The Cyber AB acts as the designated accreditation body responsible for managing the certification process for the Pentagon's cybersecurity program. During a recent town hall meeting, leadership highlighted potential shifts in the program's structure. These changes are expected to align with the ongoing assessment by the Defense Department, which dictates the security requirements for defense contractors.

Timeline

  1. October 6, 2026: The Cyber AB signaled potential program changes.

The Tech Race

This development follows the established trajectory of the Defense Department's CMMC program as stakeholders await finalized certification criteria. The accreditation body is navigating a transition period as the military updates its security requirements for contractors.

Defense contractors and their IT departments should prepare for potential adjustments to their compliance workflows. The official requirements remain subject to the ongoing Defense Department review, meaning firms should monitor forthcoming federal guidance.

The takeaway

The industry is in a holding pattern while the Defense Department conducts its comprehensive program review. Contractors should track the final audit results to determine if current security infrastructure remains compliant with pending CMMC standards.

Further reading

For broader context on current defense industry requirements, visit the Cybersecurity section.

Source note: This article includes information reported by Inside Cybersecurity.

Live Poll

Should the federal government require mandatory third-party cybersecurity certifications for all defense contractors?