Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

GAO Raises Concerns Over CMMC Assessor Capacity Amid Phased Rollout

by Kristen Smith
March 13, 2026
in Cybersecurity, News
GAO Raises Concerns Over CMMC Assessor Capacity Amid Phased Rollout

GAO Raises Concerns Over CMMC Assessor Capacity Amid Phased Rollout

The Department of War's Cybersecurity Maturity Model Certification 2.0 program is officially underway, but a new federal watchdog report warns that its long-term success is threatened by a critical lack of planning for external market pressures. 

Table of Contents

    • You might also like
    • Trump Releases National Security Systems Cybersecurity Policy
    • Space Systems Command’s Angela Lindenmuth on International Agreements
    • From Agentic AI to Next-Gen Air Defense: A Guide to the Latest Army Contract Opportunities
  • What Is the CMMC Program?
  • What Risks Could Affect the CMMC Assessment Ecosystem?
    • GAO: DOW Still Evaluating Training Needs
  • How Prepared Is the Defense Industrial Base for CMMC Compliance?

You might also like

Trump Releases National Security Systems Cybersecurity Policy

Space Systems Command’s Angela Lindenmuth on International Agreements

From Agentic AI to Next-Gen Air Defense: A Guide to the Latest Army Contract Opportunities

A Government Accountability Office report published Thursday reveals that the Pentagon has failed to systematically account for external factors that could stall implementation. Chief among these concerns is whether the private sector has enough certified assessors to handle the approximately 80,000 defense contractors now requiring Level 2 certification. 

GAO Raises Concerns Over CMMC Assessor Capacity Amid Phased Rollout

The Potomac Officers Club's 2026 Cyber Summit on May 21 will bring together government and industry leaders to discuss evolving cyberthreats, federal cybersecurity policy and initiatives affecting the defense and civilian sectors. Register now.

What Is the CMMC Program?

CMMC is DOW’s framework for verifying that contractors follow required cybersecurity practices when handling government data. The model was introduced in 2020 and later revised as CMMC 2.0 to simplify compliance and reduce the number of certification tiers.

Under the updated structure, the program includes three levels of cybersecurity maturity aligned with the sensitivity of data handled by contractors:

  • Level 1: Basic safeguards for federal contract information
  • Level 2: Implementation of all 110 controls from the National Institute of Standards and Technology Special Publication 800-171 to protect controlled unclassified information
  • Level 3: Additional protections from NIST SP 800-172 to defend against advanced threats

The Pentagon began the phased rollout of CMMC in November 2025, marking the end of the program’s voluntary phase and requiring contractors seeking certain defense contracts to begin meeting certification requirements.

What Risks Could Affect the CMMC Assessment Ecosystem?

DOW currently relies on third-party assessor organizations to verify that companies are protecting sensitive government data. The Cyber AB, an external nonprofit organization, administers the certification program and accredits organizations that conduct contractor assessments. As of December 2025, The Cyber AB had authorized 92 CMMC third-party assessment organizations to conduct Level 2 certification assessments. However, GAO investigators found that the DOW has not documented how it will mitigate the risk if these private sector assessors cannot meet the demand. 

“By assessing and documenting key external factors and developing approaches to address them, DOD would better understand program implementation risks,” the GAO noted, warning that relying on waivers to bypass requirements could undermine the entire program's intent to verify security.

GAO: DOW Still Evaluating Training Needs

The government watchdog also noted that DOW is still determining how extensively the acquisition workforce must be trained to administer and enforce the CMMC program.

Officials within the Office of the Under Secretary of Defense for Acquisition and Sustainment must evaluate existing training materials and determine whether new courses or expanded training requirements are needed, the report said.

The Defense Acquisition University has already developed several training offerings to support implementation, including:

  • Cybersecurity 1010, an introductory course covering CMMC program requirements and regulatory clauses tied to defense contracts
  • Cybersecurity 1020, which explains how cybersecurity requirements flow through the acquisition process and apply to subcontractors
  • Cybersecurity 1030, a course for senior acquisition personnel focused on selecting appropriate certification requirements for procurements

DAU also provides webinars and online resources describing CMMC regulatory requirements and implementation guidance.

However, GAO said officials have not yet determined the full scope of workforce training required to ensure acquisition personnel can effectively implement the program.

How Prepared Is the Defense Industrial Base for CMMC Compliance?

The urgency of the GAO’s warning is underscored by industry data showing a massive readiness gap. An October 2025 CyberSheath report indicated that only 1 percent of the defense industrial base was fully prepared for the CMMC final rule. The State of the DIB Report 2025 also noted that while 69 percent of contractors claim compliance through self-assessments, only 30 percent have undergone validated third-party checks.

As the Pentagon continues its phased rollout of CMMC requirements, GAO is calling on the DOW secretary to have the department's chief information officer assess and document key external factors that may impede CMMC implementation, ensuring the Pentagon has a clear road map for addressing those challenges. DOW concurred with the recommendation.

Share5Tweet19

Recommended For You

Trump Releases National Security Systems Cybersecurity Policy

by Jane Edwards
June 15, 2026
Cybersecurity. Trump has issued a policy to strengthen the cybersecurity of U.S. national security systems.

Trump has issued a policy to bolster the cybersecurity of national security systemsThe memo calls for the reestablishment of the Committee on National Security SystemsThe 2026 Intel Summit...

Read moreDetails

Space Systems Command’s Angela Lindenmuth on International Agreements

by Jane Edwards
June 15, 2026
Angela Lindenmuth. The SSC International Affairs Office deputy chief said SSC executes nearly 40 international agreements.

A Space Systems Command division has executed nearly 40 international cooperative agreementsSSC expects to record nearly $700 million in additional partner investments by the end of 2026The 2026...

Read moreDetails

From Agentic AI to Next-Gen Air Defense: A Guide to the Latest Army Contract Opportunities

by Elodie Collins
June 15, 2026
Army seal. The Army is seeking commercial technologies across AI, autonomy, cloud infrastructure, training and air defense

The Army has issued contract opportunities for advanced technologies, such as AI, command-and-control systems, air defense, autonomous and robotic systems, synthetic training, and dronesThe Army is also seeking...

Read moreDetails

Navy Launches Recruitment Drive for Commercial Technology Experts

by Miles Jamison
June 15, 2026
U.S. Navy logo. The Navy is launching a recruitment drive for top commercial technology experts.

The Department of the Navy has announced a national talent search to recruit top commercial technology professionals into the Navy Reserve's Navy Innovation Unit.The Navy's push to recruit commercial...

Read moreDetails

DOW Issues Guidance to Mitigate Vendor Threats in Overseas Operations

by Kristen Smith
June 15, 2026
DOW logo. DOW has released guidance for identifying foreign vendors that pose security risks to U.S. operations abroad.

The Department of War has set department-wide procedures for identifying foreign vendors that pose security risks to U.S. operations abroad and removing them from federal contracts, grants and...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved.

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved.

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!