Pentagon Initiates CMMC Listening Sessions Amidst Review to Address Small Business Concerns
The Department of Defense (DoD) is conducting a comprehensive review of the Cybersecurity Maturity Model Certification (CMMC) program, with a focus on addressing the compliance challenges faced by small businesses. The review, led by DoD Chief Information Officer Kirsten Davies, aims to balance the need for stringent cybersecurity requirements with the financial and operational burdens these requirements impose on smaller defense contractors. The CMMC program, initially developed in 2019 during the first Trump administration, was designed to ensure defense contractors comply with cybersecurity standards. However, the program has faced criticism for its costly and complex third-party assessment requirements. In response, the DoD has suspended these requirements and is holding listening sessions to gather feedback from stakeholders, particularly small businesses. The review team has a 60-day period to collect input and a subsequent 15 days to present recommendations.