Leadership1 distinct publisher3 min readPublished
The Department of War took the third-party assessment requirement out of the November contract cycle and asked a task force to rethink the program. Suppliers now decide alone how much remediation to keep funding.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
A suspended clause and a suspended obligation are different line items, and the July 13 memorandum touched only the first. What came out of the November contract cycle was the third-party assessment requirement [1]. Heather Wishart-Smith, writing in Forbes, made the case that the pause reaches the assessment and not the risk behind it [18]. Most of the practitioners she has been arguing with since her first column on the subject say the binding constraint was never assessor supply but contractor readiness [17][23], and readiness is the one input a supplier controls, which is exactly why it is the easiest thing to defer.
So the calendar carries the decision. The requirement sat 120 days out when it was pulled [4]. If the reform task force reports to the department's chief information officer on schedule around September 13 [3] and the original date is reinstated, a supplier that stood its program down in July would have 58 days to get back to where it was [5]. Cash saved in the interim is real, and so is the premium on a compressed restart, but only the first of those is easy to forecast.
A finance-side skeptic would say the program has been cost-justified out of existence and the honest move is to stop spending. The stated grounds support half of that: the announcement cited prohibitive compliance costs and bureaucratic burdens, along with Small Business Administration data on companies leaving the defense industrial base [2]. It did not say the security requirement was wrong, and a 60-day review reporting to the department's own CIO [3] is the shape of a redesign rather than a repeal. What the recommendations will say, we do not know, and no one outside the task force does either.
The capacity argument matters here less for who wins it than for what it shows about verifiability. Thomas Graham of Redspin worked from roughly 550 to 560 certified assessors divided by the three-person minimum team [6], which implies something like 183 to 187 parallel teams [21]. Secureframe's April figures set at least 80,000 organisations needing assessment against about 100 accredited assessment organisations registered by CyberAB, the nonprofit accreditation body the department authorised [7][8]. David Koran's May paper counts 766 assessors, which at three per team produces the 255 concurrent teams he claims [9][19], or roughly 314 organisations queued per team [20]. Jacob Horne of Summit 7 reads the same registries as surplus rather than shortfall [10]. Koran's objection to the memorandum is the narrower and more useful one: the department asserted severe assessment shortages, published none of the analysis, and did not reconcile the assertion with its own Table 8 projections [11]. A supplier weighing how much to believe about the next date should note that the last one moved on an undocumented premise.
The people who will absorb the pause first are the ones the department describes as scarce. Becoming a lead assessor takes years of audit and cybersecurity experience, an advanced professional qualification and a Tier 3 federal background check [12], and Jason Palmer's figures put that work at $125 to $200 an hour against $200 to $250 for readiness consulting, reseller and managed service work that needs little specialised training [13], about 28 percent less at the midpoints [22]. By his own estimate, drawn from his network rather than published data, fewer than half of roughly 659 lead assessors are realistically available for independent work once instructors, prime contractors' captive staff and assessment-organisation employees are excluded [14][15], which puts the pool under 330 people [16].
The question a program manager answers this quarter, then, is how much of the remediation effort to keep warm at the company's expense, knowing the restart bill lands on the company whichever way the task force goes.
Ranked by verification strength, evidence, and original report placement.
The announcement cited "prohibitive compliance costs and bureaucratic burdens" and referenced Small Business Administration data confirming "that CMMC compliance is forcing innovative companies out of the Defense Industrial Base, which will delay the delivery of critical capabilities to the warfighters."
Contractor readiness, not assessor capacity, is the constraint most consultants, assessors and C3PAOs point to.
Eight months earlier, the author's column on the CMMC assessor shortage drew immediate pushback from assessors and consultants who argued the real constraint was contractor readiness, not assessor capacity.
On July 13, 2026, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification program, pausing the third-party assessment requirement that was set to appear in contracts on November 10, 2026.
A CMMC Reform Task Force has 60 days to review the program and report back to the department's CIO, with recommendations expected around September 13.
CyberAB is the nonprofit accreditation body authorized by the Department of War for the CMMC process.
Distinct publishers with included, body-backed reporting in this cluster.
forbes.com
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
CMMC Phase 2 is suspended. DFARS 252.204-7012 is not.1 distinct publisher
security
Defense suppliers' cyber scores hit a five-year high just as the audits were paused1 distinct publisher
security
CMMC Phase 2 Assessments Are Paused. The False Claims Act Is Not.1 distinct publisher
security
ICIT's Eftekhari tells CISOs to plan for a working CISA and a state-by-state AI patchwork1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Firm on the memo, one-sided on the math
The policy spine is solid: a dated suspension, a quoted rationale, a 60-day clock, all attributable to the department's own announcement. Everything downstream rests on practitioners who published their work - Koran's paper, Horne's podcast, Secureframe's April numbers - and on one estimate Forbes openly labels as a personal-network guess. What is missing is the government's side of the arithmetic: the SBA data and the Table 8 projections are invoked, never shown.
A real contract change, uncounted assessments
The suspension itself is as concrete as adoption gets: a clause pulled from the November cycle, with contractors already redirecting remediation spend. But the ecosystem is described almost entirely by headcount - 766 certified, 659 lead, roughly 100 assessment organizations against 80,000 organizations said to need certification - and nobody in this reporting says how many assessments have actually been completed. Counting certified people is not the same as counting work delivered.
Shortage asserted, capacity math runs the other way
The overstatement here is the government's, not the reporting's. A program was suspended partly on a claim of severe assessment capacity shortfall, and the two people in this story who have actually published numbers - Koran and Horne - conclude the ecosystem is years ahead of what the rollout needs. Forbes deserves credit for revisiting its own earlier shortage framing rather than defending it, and for flagging that ISI's survey respondents chose themselves. Palmer's rate argument survives all of it: scarce credentials that bill below generic IT work is a real signal, just not the one the memo claimed.
Everyone quoted bills into CMMC
There is no disinterested voice in this story. Redspin and the assessment organizations sell assessments; Summit 7 and Secureframe sell readiness; ISI surveyed contractors through its own public tool and its CEO worries aloud about lost revenue; Palmer's central complaint is that his own rate is too low; Koran holds a CyberAB credential and authored the paper under discussion. The department has its own interest in a rationale that justifies pausing an unpopular program. Positions are disclosed and the arguments are checkable, which is why this scores as loaded rather than compromised.
Sure what happened, unsure whose numbers hold
Take the suspension, the dates and the task force as settled; treat the capacity verdict as open. Three different assessor counts circulate, one availability estimate is explicitly anecdotal, and the department has not published the analysis that would let anyone reconcile them. With a single newsroom on the story and every source commercially attached to it, the safe reading is the narrow one: the deadline moved, the obligation did not.