CMMC stakeholders are concerned about the progress or fate of the certification model due to changes in leadership at DoD Acquisition & Sustainment, several missed deadlines, and lack of reassurance by CMMC leadership. There are several incidences that took place in the last few months.
Admittedly, these are big delays and it is natural that stakeholders might get frustrated. However, these delays point to bureaucracy and loss aversion more than anything else.
Now, let’s think logically and straight to the point. If CMMC was out of the equation we would probably see the following signs:
The answer is a resounding ‘NO’ as we haven’t seen any of the above-taken places. The US really needs a comprehensive strategy for cybersecurity as the supply chain risk is a top priority for the administration as per the release of Executive Order 14028. The basic concept of CMMC is a good one. Right now, the model is just suffering from a lack of official guidance.
The “CMMC Third-Party Assessor Organizations” or C3PAOs are almost at the heart of the CMMC model. They are the only authorized entities that can enter into contracts with defense contractors to perform an assessment. Hence, the DoD has set very tough requirements to meet for C3PAOs before they actually start work. Seemingly, these requirements are causing all the delays because of some dependency bottlenecks.
Yes, the long wait is painful but there is a good side to it. As a contractor, if you are not ready (almost 90% are not) these delays give you more time. The slow rollout will provide you a window to build knowledge about the exact requirements to pass the CMMC assessment.