The Cyber AB Identified Potential CMMC Program Changes
The accreditation body for Pentagon cybersecurity standards signaled upcoming adjustments to the certification initiative.
Updated on Oct. 6, 2026 in Cybersecurity

Live Poll
Should the federal government require mandatory third-party cybersecurity certifications for all defense contractors?
The Cyber AB, which serves as the official accreditation body for the Pentagon's Cybersecurity Maturity Model Certification (CMMC) program, has identified potential changes to the framework. Leadership noted these adjustments during a recent town hall meeting.
Why it matters
The CMMC program is a critical initiative for safeguarding defense-related information, making any potential modifications highly significant for industry stakeholders. Defense contractors are currently awaiting the results of a formal Defense Department review of the initiative.
The Cyber AB acts as the accrediting body for the Pentagon's Cybersecurity Maturity Model Certification (CMMC) framework. The specifics of the proposed technical or administrative adjustments to the certification program have not yet been released.
The players
The Cyber AB
This organization serves as the authorized accreditation body for the Pentagon's Cybersecurity Maturity Model Certification program.
Matthew Travis
He serves as the CEO of the Cyber AB and provides leadership regarding the organization's accreditation standards.
Defense Department
This executive department of the United States federal government is responsible for conducting the current review of the CMMC program.
The details
Leadership at the Cyber AB highlighted the potential for shifts in the CMMC program during a recent public town hall. The industry remains in a waiting pattern for the findings of a Department of Defense review that will dictate the future direction of the certification process.
Timeline
October 6, 2026: Announcement of potential program changes.
The Tech Race
These identified shifts align with the ongoing evolution of the Cybersecurity Maturity Model Certification program. This development marks a transition in federal cybersecurity standards as the Defense Department refines its approach to supply chain security.
Defense contractors and their partners should monitor these potential changes, as they may impact future compliance workflows. Adjustments to the certification process could dictate new requirements for how organizations maintain access to sensitive federal data.
The takeaway
Stakeholders should prepare for potential adjustments by maintaining ongoing alignment with current federal guidelines. Staying informed on the results of the Defense Department review will be essential for maintaining certification status.
Further reading
For more information on the current regulatory environment, visit the United States Cybersecurity section.
Source note: This article includes information reported by Inside Cybersecurity.
Live Poll
Should the federal government require mandatory third-party cybersecurity certifications for all defense contractors?










