Top story
Speaking at the Billington CyberSecurity Summit on September 9, DoW CIO Kirsten Davies gave the fullest picture yet of what the Reform Task Force heard. She told DefenseScoop the department received "over 1,100 responses" and "Over 10,000 pages of documentation that the team is all reading." She added: "More than 50% of the respondents were in favor of us putting this on hold and seeking some level of reform." On the program's impact: "CMMC was hitting small to medium-sized businesses really, really hard and inappropriately hard. So we have some work to do."
Rules and policy
- Compliance versus security. Davies: "Compliance equals compliance. Compliance doesn't equal security. Compliance equals a point-in-time check… It needs to be contiguous and continuous, and it needs to be at … the pace of the threat in and of itself." Why it matters: expect proposals for continuous monitoring or evidence over time, not just a one-time assessment.
- Assurance is still an open question. Davies acknowledged assessors' concern about how DoW will "prove … that the defense industrial base is following federal policies," adding, "This is still something that we need to resolve for." Why it matters: some form of verification is likely to survive reform.
- Revision 3 analysis. Pivot Point Security's September 8 review of the new class deviation notes that it "does not repeal the CMMC program" and "does not remove DFARS 252.204-7012 from the revised DFARS text." Why it matters: as CyberZ put it on September 10, "Unlike the July 13 suspension memo, a class deviation is binding acquisition regulation." The underlying safeguarding clause is still there.
Industry and enforcement
- The review window closes. The task force's 60-day review, which began July 13, reached its deadline on September 11. No report was released this week.
- No new DOJ cyber-fraud settlements were announced this week.
Still on the radar
- Davies also said "nowhere in CMMC was there even mention around how to build cyber resilience for a manufacturing line," reinforcing her August remarks on OT security.
Watch list
- The task force report, expected about 15 days after the review closed.
- A new DoW CIO memo on the program's direction.
What to do this week
- Think about how you'd show your controls working over time: logs, scan history, reviews on a schedule. That's where Davies is pointing.
- Keep your system security plan current. It's the document any future assessment model will start from.
Sources
- Pentagon pores over heaps of industry feedback on CMMC reform (DefenseScoop, Sept. 9, 2026)
- Revision 3 of DARS Class Deviation 2026-O0025: What Defense Contractors Need to Know (Pivot Point Security, Sept. 8, 2026)
- The CMMC Suspension Is Now a Regulation (CyberZ, Sept. 10, 2026)
- CMMC News 2026 tracker (Secureframe)
This briefing summarizes public sources for general awareness. It is not legal advice. Check the linked primary sources before acting on any item.