The Cyber AB Identified Potential CMMC Program Changes

The accreditation body for Pentagon cybersecurity standards signaled upcoming adjustments to the certification initiative.

Updated on Oct. 6, 2026 in Cybersecurity

Isometric editorial illustration of a heavy, industrial steel data encryption cabinet with a reinforced lock, representing secure defense infrastructure.
The Cyber AB, the Pentagon’s official cybersecurity accreditation body, has signaled potential changes to the Cybersecurity Maturity Model Certification framework following recent review discussions. AI Illustration. Upload story photo >

Live Poll

Should the federal government require mandatory third-party cybersecurity certifications for all defense contractors?

The Cyber AB, which serves as the official accreditation body for the Pentagon's Cybersecurity Maturity Model Certification (CMMC) program, has identified potential changes to the framework. Leadership noted these adjustments during a recent town hall meeting.

Why it matters

The CMMC program is a critical initiative for safeguarding defense-related information, making any potential modifications highly significant for industry stakeholders. Defense contractors are currently awaiting the results of a formal Defense Department review of the initiative.

The Cyber AB acts as the accrediting body for the Pentagon's Cybersecurity Maturity Model Certification (CMMC) framework. The specifics of the proposed technical or administrative adjustments to the certification program have not yet been released.

The players

The Cyber AB

This organization serves as the authorized accreditation body for the Pentagon's Cybersecurity Maturity Model Certification program.

Matthew Travis

He serves as the CEO of the Cyber AB and provides leadership regarding the organization's accreditation standards.

Defense Department

This executive department of the United States federal government is responsible for conducting the current review of the CMMC program.

The details

Leadership at the Cyber AB highlighted the potential for shifts in the CMMC program during a recent public town hall. The industry remains in a waiting pattern for the findings of a Department of Defense review that will dictate the future direction of the certification process.

Timeline

  1. October 6, 2026: Announcement of potential program changes.

The Tech Race

These identified shifts align with the ongoing evolution of the Cybersecurity Maturity Model Certification program. This development marks a transition in federal cybersecurity standards as the Defense Department refines its approach to supply chain security.

Defense contractors and their partners should monitor these potential changes, as they may impact future compliance workflows. Adjustments to the certification process could dictate new requirements for how organizations maintain access to sensitive federal data.

The takeaway

Stakeholders should prepare for potential adjustments by maintaining ongoing alignment with current federal guidelines. Staying informed on the results of the Defense Department review will be essential for maintaining certification status.

Further reading

For more information on the current regulatory environment, visit the United States Cybersecurity section.

Source note: This article includes information reported by Inside Cybersecurity.

Live Poll

Should the federal government require mandatory third-party cybersecurity certifications for all defense contractors?