Reading the Tea Leaves: Where CMMC Assessments May Be Headed and What It Means for Assessors and OSCs

Jillian WrightLead CMMC Certified Assessor · 17 MIN READ
Hands holding a crystal ball against a red background

The CMMC ecosystem is full of speculation at the moment. This post is my contribution to the pile: some of my own thoughts after the completely speculative, creative thinking exercise by Matt Travis and Mike Snyder at the most recent Cyber AB town hall. To be clear up front, none of this is official, and none of it is on anyone's calendar. These are possibilities, not policy. But several of the ideas line up suspiciously well with what DoD is already doing on its own systems, which makes them worth thinking through.

CMMC Level 2 assessments today are a once-every-three-years snapshot against a fixed list of 110 requirements. Whether that model survives the next few years is anyone's guess, and right now, a lot of people are guessing.

So let's walk through some of the possibilities, where those ideas come from, and what it could mean for the people on both sides of the assessment table.

Where these ideas are coming from

Most of the predictions trace back to two documents that already exist. If you want to know where CMMC might go, these are the places to look.

DoD's Cybersecurity Risk Management Construct (CSRMC)

In September 2025, DoD announced the Cybersecurity Risk Management Construct, which replaces the Risk Management Framework it used to approve its own systems. The old process was slow, paperwork-heavy, and built around periodic sign-offs. If that sounds familiar, it should. It is CMMC's cousin.

CSRMC swaps the periodic snapshot for continuous, automated monitoring. Its guiding principles include focusing on the controls that matter most, automating evidence collection, building security into development, keeping systems running under attack, accepting assessments across organizations instead of redoing them, and validating security with realistic, threat-informed testing.

CSRMC applies to DoD's own systems, not to contractor networks. But nearly every prediction below maps to one of its principles.

NIST Cybersecurity Framework (CSF) 2.0

The CSF is NIST's general-purpose framework, and it describes what good security looks like rather than prescribing a list of specific requirements. Updated in 2024, it is organized around six outcomes: Govern, Identify, Protect, Detect, Respond, and Recover. Notice that most of those are about what happens before and after an attack, not just keeping data secret. It is also openly risk-based, meaning each organization decides how far to go based on its own situation. That is a very different philosophy from a fixed checklist.

From the Crystal Ball: Five big shifts that could be coming

1. From protecting CUI to keeping the defense industrial base secure and running

CMMC today is almost entirely about keeping Controlled Unclassified Information out of the wrong hands. One possibility is that the focus widens to industrial resiliency: can a supplier keep producing parts for the military even when someone is actively trying to stop it?

That brings OT (operational technology) into the spotlight. OT is the equipment that makes physical things happen: CNC machines, robotic arms, and the small industrial computers that control them. It often runs old software that cannot be patched, and taking it offline means stopping production. Today much of it is documented as a Specialized Asset and largely left alone in an assessment. That gap is unlikely to last.

2. From point-in-time to continuous validation

Today a company proves compliance once, gets a certificate, and comes back in three years. In between, things drift. Continuous validation means regularly and automatically checking that security controls are still working, so the evidence is always current instead of three years stale.

A prerequisite is asset awareness, which simply means knowing everything connected to your network. You cannot continuously validate what you do not know exists, and plenty of manufacturers genuinely do not know every device on the shop floor.

3. From checklists to risk-based assessments and "living control sets"

A checklist asks "Is this box checked?" A risk-based assessment asks "Does what this company is doing actually reduce its real risk?" Two companies can both technically meet a requirement while only one would stop a real attacker. A checklist cannot tell them apart.

A living control set is a set of controls that evolves as threats and the company change, rather than waiting years for the next revision of the standard. NIST SP 800-171 Rev 3 already nudges in this direction with organization-defined parameters, where the company fills in its own values for things like how often to review access.

4. From documents to compliance-as-code

Today, compliance lives in Word documents and spreadsheets that humans read and interpret. Compliance-as-code means expressing requirements and evidence in a form computers can read and check automatically.

Two pieces make that possible:

  • OSCAL (Open Security Controls Assessment Language) is a NIST standard format for writing control catalogs, System Security Plans, assessment results, and POA&Ms as structured data. Software can then compare what the SSP claims against what the systems actually show.
  • STIGs (Security Technical Implementation Guides) are very specific configuration instructions published by DISA, the Defense Information Systems Agency. NIST 800-171 says what to achieve. A STIG says exactly which setting to change on a specific product.

One idea floating around is DISA acting as a central hub for standardized, machine-readable configuration guidance and OSCAL repositories for the defense industrial base.

5. From confidentiality to the whole CIA triad

Security is often described with three goals:

  • Confidentiality: only authorized people can see the information.
  • Integrity: the information has not been altered or tampered with.
  • Availability: systems and data are there when you need them.

CMMC covers the first one. Future requirements could reach into the other two. In manufacturing, a quietly altered tolerance on a part drawing or a production line knocked out by ransomware can be a bigger national security problem than a leaked spreadsheet.

The nuts and bolts that might change

Big ideas are nice. Here is how they might actually show up in the program.

Hybrid assessments

Instead of a C3PAO assessing all 110 requirements, it would verify a critical subset, somewhere around 20 to 40, and the company would self-assess the rest. The goal is lower cost, which speaks directly to the reason given for the pause: small businesses saying they cannot afford CMMC.

Two catches. First, CMMC exists because contractor self-assessments were often optimistic, so handing most controls back to self-assessment reopens that door. Second, someone has to decide which controls are "critical." A fixed list becomes a new checklist. A list that varies by company needs assessor judgment, and judgment is hard to keep consistent.

Penetration testing as validation

Correctly scoped penetration testing and red teaming keep coming up as a strong way to confirm controls are actually implemented. A penetration test is hiring ethical hackers to find weak spots within agreed boundaries. A red team acts like a real adversary with a specific goal and tests whether you would even notice.

The scope of a test matters as much as the test itself. A test that covers the main business network but skips the cloud environment, the shop floor, or the engineering systems leaves gaps, and an attacker will go wherever the door is open, not just where the testers were allowed to look. Development environments, the places where engineers build software, firmware, and designs, are often left out of scope, and they should not be. They tend to be less locked down because people need flexibility, and a compromise there can ship straight to the customer.

Scoring

Today's SPRS score starts at 110 and subtracts 1, 3, or 5 points for each unmet requirement, regardless of how much that gap matters for a given company. Scoring could shift toward a risk-based, control-level approach, possibly modeled on the continuous risk scoring DoD already uses on its own networks.

FedRAMP

FedRAMP is the government's security approval program for cloud services. Contractors storing CUI in the cloud already need a FedRAMP Moderate or equivalent provider. How the two programs fit together, including what counts as equivalent and how inherited controls get credited, is still a major open question.

Reciprocity

Reciprocity is a fancy word for "if someone already checked this, do we really need to check it again?" It is one of the biggest unanswered questions in the program.

Plenty of OSCs have already been through demanding assessments: ISO 27001 certifications, SOC 2 audits, FedRAMP authorizations for their own cloud products, DoD-led reviews, or assessments for other federal agencies. Today, very little of that work counts toward CMMC, so an OSC can end up paying to prove the same thing two or three times to different auditors.

The hard part is deciding what should count. Frameworks overlap but do not match one for one, assessments are done to different levels of rigor, and the scope of one review may not cover the systems that handle CUI. Answering that well means deciding which outside assessments earn credit, for which requirements, and how an assessor confirms the earlier work is still current and actually covers the right environment.

This is not just an industry gripe. Members of Congress have directly asked for a look at how to harmonize the patchwork of cybersecurity requirements placed on government contractors. Today there are multiple baselines, and they change as you move from one department or agency to the next. Contractors end up sitting through multiple audits that cover much of the same ground. Even the incident reporting rules vary, with different deadlines and thresholds depending on which part of the government contracting landscape you are working in. All that duplication costs time and money on both sides of the table, and nobody ends up any more secure for having proved the same thing three times.

DoD has already made reciprocity one of the core principles for its own systems under CSRMC, which is one reason many in the ecosystem hope it shows up in CMMC too. Done well, it is one of the few ideas that could genuinely lower cost without lowering the bar.

NIST SP 800-171 Revision 3

CMMC is still built on Revision 2. Revision 3 was published in 2024 with consolidated requirements, new areas like supply chain risk management, and organization-defined parameters. If the move to Rev 3 gets fast-tracked, a grandfathering period seems likely so companies that already spent real money on Rev 2 certification are not stranded.

The elephant in the room: the pause

All of this speculation is happening against a very real backdrop. On July 13, 2026, DoD suspended the Phase II requirement for C3PAO assessments that was set to begin November 10, 2026. Self-assessments still apply, and DFARS 7012 never went anywhere. In September, the suspension became binding through a class deviation telling contracting officers to pull third-party assessment requirements out of contracts.

A CMMC Reform Task Force was given 60 days to review the program. Its recommendations went to the DoD CIO in mid-September but, as of this writing, have not been made public. So we are all reading tea leaves together.

What happens to the numbers?

Before the pause, the ecosystem was planning for tens of thousands of Level 2 certifications a year. A common claim was that there simply were not enough C3PAOs and assessors to handle that volume. That claim does not hold up. The rollout was designed to phase in gradually, and the ecosystem was healthy and growing right alongside it, with new C3PAOs and certified assessors coming online to meet demand. The numbers shared at the most recent Cyber AB town hall back that up, even in the middle of the pause. There are now 117 authorized C3PAOs, up 3 percent since the last update, with several newly authorized in just the past month. Four of them have also earned full accreditation to ISO/IEC 17020, the international standard for organizations that perform inspections, and that number is expected to keep climbing. The people doing the work are growing too: CCAs are up 4 percent, and CCPs and LCCAs are each up 3 percent. How that volume changes depends on which levers DoD pulls:

  • Fewer companies need a C3PAO. If third-party assessments are reserved for higher-risk work and everyone else self-assesses, the annual number could shrink dramatically.
  • Same companies, smaller assessments. A hybrid model keeps the number of certified companies roughly intact but cuts the hours per assessment. Team size is another lever: today every assessment requires three CCAs, and the Cyber AB has asked DoD to reconsider that.
  • Fewer big events, more small ones. The Cyber AB has also pointed out that there is no continuous monitoring and no way to do a delta assessment today, and suggested borrowing that idea from FedRAMP. Full recertifications every three years could give way to lighter, more frequent check-ins.
  • Same model, slower clock. The phase-in resumes later with roughly the same structure, and the volume simply spreads over more years.
  • Scoping does the heavy lifting. If more OSCs move CUI into enclaves or cloud environments and inherit controls, many assessments get much smaller even if the count stays high.

There is a people problem hiding behind those numbers, too. They count credentials, not paychecks. Assessors cannot go without income forever, and with Level 2 assessments on hold, I fear many of them will take jobs outside CMMC and not come back. Becoming a certified assessor takes a lot of time and real money. If a large share walk away during the pause, the capacity the ecosystem built will not be there when assessments restart, and the old "not enough assessors" claim could finally come true.

Most of these roads lead to the same place for C3PAOs: less work per engagement, with the possible upside of more recurring work. For OSCs, the risk is treating "paused" as "cancelled." The underlying obligations never stopped, and when assessments return in whatever form, the companies that kept working will be the ones ready for them.

About those cost "savings"

Here is the awkward part. The pause happened because CMMC was seen as too expensive, yet several of the ideas floating around would expand what OSCs have to protect and prove. Can both be true? Mostly, it depends on which bill you are looking at.

The assessment bill could go down

  • Assessing a critical subset instead of all 110 requirements means fewer assessor hours.
  • Smaller assessment teams cost less.
  • Delta or continuous assessments could replace a full recertification every three years.
  • Automated evidence could cut the hours OSCs spend producing screenshots and documents.
  • Inheriting controls from FedRAMP or enclave providers leaves less to assess.

The security bill would likely go up

  • OT: Segmenting shop floor equipment, monitoring it, and sometimes replacing equipment that cannot be secured is real money, often requiring expertise small manufacturers do not have on staff.
  • Penetration testing: A properly scoped test is not cheap, and a cheap test is usually not properly scoped. If it becomes a recurring requirement, it is a recurring cost. Red teaming costs more.
  • Integrity and availability: Tested backups, recovery planning, redundancy, and tamper detection all cost money. Adding two-thirds of the CIA triad is not a minor scope change.
  • Compliance-as-code: Automation pays off over time, but someone has to buy or build the tools and know how to run them. A large prime can absorb that. A 30-person machine shop probably cannot, unless affordable tools or government-provided resources actually show up.

So it is a shift, not a savings

Spending moves away from paperwork and assessment and toward actually securing things. For many OSCs, especially smaller ones, the total bill could easily be higher. A few things could square the circle:

  • Tiering: The expanded requirements apply only to suppliers whose disruption would matter most, while lower-risk suppliers get a lighter path.
  • Trading, not adding: Some documentation-heavy requirements get dropped in exchange for validated outcomes, so OSCs are not paying for both.
  • Shared services: Government-provided configurations, tools, or subsidized testing lower the cost of doing it right.
  • Avoided losses: A ransomware attack that stops production for weeks costs far more than backups and segmentation. True, but a hard sell to a small business owner staring at this quarter's budget.

These ideas could make CMMC cheaper to assess. They are much less likely to make it cheaper to comply with. Anyone pitching them as pure savings is skipping a step.

A different take: Katie Arrington on funding and fixes

Not everyone thinks cost is the real problem. Katie Arrington, former DoD CIO (performing the duties) and often called the mother of CMMC, laid out a very different view in a recent CMMC Uncovered podcast episode. She is openly critical of the pause and firmly against relying on self-assessments. Her summary, after noticing she had drawn her two eyebrows differently that morning: self-assessments don't work. The ideas and opinions below are hers.

Her ideas for funding small businesses

  • A cybersecurity loan program, with forgiveness. Her main proposal. The SBA and the DoD CIO would offer loans for cybersecurity, and after a set number of years in good standing as a government supplier, the debt would be forgiven. Her reasoning is that taxpayers are already paying for poor cyber hygiene through stolen R&D and breaches, so funding the fix up front is the better deal.
  • Targeted loans for manufacturers. Aimed specifically at shop floor protection, as an alternative to removing requirements because they are "too hard."
  • Treat compliance as a business investment. She pushes back hard on "CMMC is too expensive." Contractors already pay for DCAA-approved accounting systems, FedRAMP, and ISO audits, so in her view cyber should be budgeted the same way, with a business plan behind it.

Her ideas for improving CMMC

  • Use AI to mark and label CUI. She sees CUI identification as the real weak spot. Government program managers decide what is CUI, but they are often not trained to do it, and nobody is entirely sure where the line is.
  • Think about aggregation, not just labels. A pile of individually harmless information can add up to something an adversary wants. Her example: a construction firm's drawings showing where the security rooms and control systems are.
  • Sampling-based assurance. Instead of an OSC putting a POA&M out to 2099 for something that is never "done" (like bringing in new software), the OSC documents its process. The assessor picks a few examples, pulls the documentation and logs, and confirms the process was actually followed. As she puts it, assessors cannot be gate guards to everything.
  • Prepare for quantum. Today's encryption will not hold up forever, which makes getting the basics right even more urgent.

Her loan idea speaks directly to the cost problem above: if the security bill is going up regardless, someone has to help small businesses pay it. And her sampling approach is a preview of the assessor role described next.

So what happens to C3PAOs and assessors?

The short answer: the role gets more important, but it changes shape. Less checker of boxes, more auditor of the machinery that checks the boxes.

Judging whether the evidence can be trusted

If compliance-as-code takes off, a lot of today's work (reading the SSP, reviewing screenshots, asking someone to pull up a setting) gets automated. But automated results are only as good as what they are pointed at. An independent assessor still has to confirm the tooling covers the whole environment and that the data has not been massaged. A dashboard that is all green is reassuring right up until you learn it was only watching half the network.

Scoping becomes the main event

Automation cannot tell you what it is not looking at. Confirming the asset inventory is complete, the CUI data flows are accurately mapped, and the shop floor has not been quietly left out is human work. Scoping is already where assessments most often go sideways, so this may become the most valuable thing an assessor does.

Professional judgment replaces pass/fail

A risk-based model means the assessor decides whether a company's approach actually reduces its risk. That is exactly what experienced humans are for. It also means two assessors could reach different conclusions on the same company, so calibration and documented reasoning would matter a lot more.

Checking the testing, not doing it

C3PAOs likely would not run the penetration tests themselves, since that creates independence problems. Instead they would evaluate whether testing was scoped correctly, done by qualified people, and whether the findings were actually fixed. Some have floated RPOs taking on part of this role, which deserves a careful look. RPOs help companies prepare, and asking the helper to also grade the work blurs a line the program has worked hard to draw.

From events to relationships

If security is validated continuously, a once-every-three-years snapshot looks odd. A likely model resembles ISO surveillance audits: a full assessment followed by lighter, periodic check-ins that review monitoring data and spot-check reality. That shifts C3PAOs from big episodic engagements to recurring ones, and it puts even more pressure on keeping assessing and advising separate.

New skills required

OT security, reading machine-readable SSPs, interpreting automated tooling output, and evaluating integrity and availability (backup and recovery testing, tamper detection, resilience planning) are not things most assessors are trained on today. Training would need a serious update, and specialists, such as OT-focused assessors, may emerge.

Who wins and who gets squeezed

Assessors whose value is mostly document review and interview scripts would see that work shrink. Assessors who understand technical evidence, can spot gaps in automation, and can defend a risk judgment become more valuable. Financial auditing is a useful comparison. Accounting software automated the arithmetic decades ago, and auditors did not disappear. They moved to testing the controls around the systems and deciding which numbers deserved a closer look.

What OSCs should do now

None of this changes your next assessment. CMMC is still built on 110 requirements, and any of these changes would require rulemaking, which moves at roughly the speed of continental drift. But a few steps are smart no matter which predictions come true:

  1. Know what is on your network. Every laptop, server, cloud service, and machine on the shop floor. This pays off under today's rules and tomorrow's.
  2. Stop treating your SSP as a once-a-year document. Keep it current as your environment changes. If continuous validation arrives, you will already be in the habit.
  3. Take a hard look at your OT. Document it, separate it from the rest of your network where you can, and know what you would do if it went down.
  4. Think about recovery, not just prevention. Test your backups. Know how long it would take to get production running again after an incident.
  5. Scope your testing honestly. If you pay for a penetration test, make sure it covers the places an attacker would actually go, including development environments.

The bottom line

The direction of travel is clear even if the timeline is not: from proving once that you followed the list to continuously proving that your security actually works, across your whole operation, shop floor included. For contractors, that means building habits now. For C3PAOs and assessors, it means the job shifts from verifying documents to judging evidence, scope, and risk. That is harder work, and frankly, more interesting work.

Sources

CMMCC3PAOCSRMCNIST CSF 2.0reciprocityOT security
WRITTEN BY Jillian Wright President of Wrightbrained Security and a Lead CMMC Certified Assessor. More about Jil →
KEEP READING

Related posts

All posts →
// READY WHEN YOU ARE

Is your security posture keeping you up at night?

Thirty minutes, no slide deck. Tell us what you're up against and we'll tell you honestly whether we can help.