CMMC Compliance Third-Party Assessment Is Paused. The Risk Isn't.
On July 13, 2026, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification program, pausing the third-party assessment requirement that was set to appear in contracts on November 10, 2026. The announcement cited “prohibitive compliance costs and bureaucratic burdens” and referenced Small Business Administration data confirming “that CMMC compliance is forcing innovative companies out of the Defense Industrial Base, which will delay the delivery of critical capabilities to the warfighters.”
A CMMC Reform Task Force now has 60 days to review the program and report back to the department's CIO, with recommendations expected around September 13.
Eight months earlier, my column on the CMMC assessor shortage drew immediate pushback from assessors and consultants who argued the real constraint was contractor readiness, not assessor capacity. This follow-up revisits that argument with what's actually changed.
The CMMC Compliance Capacity Debate
When I first reported on the shortage, Thomas Graham of Redspin cited roughly 550 to 560 Certified CMMC Assessors worldwide, divided by three – the minimum staffing for an assessment team – to estimate parallel throughput. Secureframe’s April coverage of the CMMC ecosystem estimated that at least 80,000 organizations in the DIB are expected to require a certified third-party assessment against a pool of roughly 100 Certified Third Party Assessment Organizations registered by CyberAB. CyberAB is the nonprofit accreditation body authorized by the Department of War for the CMMC process.
David Koran, a CyberAB Registered Practitioner Advanced who published a capacity analysis of the ecosystem in May, argues the two numbers were never measuring the same thing, since a single C3PAO can field multiple assessment teams. His paper, The Inverted Bottleneck , put the ecosystem at 766 Certified Assessors and 489 Lead Assessors as of April 2026. By Koran’s calculations, this is enough for 255 concurrent teams, and "approximately two and a half years ahead of the capacity" the Department of War's rollout projections require.
Jacob Horne of Summit 7 reached a similar conclusion on his podcast The Numbers Behind CMMC Assessment Capacity . "What the data actually shows is that the ecosystem is sitting on a huge amount of excess capacity," he said, not a shortfall.
Asked directly whether the suspension changes that picture, Koran said it sharpens the disagreement rather than resolving it. "The Department's memorandum asserted severe shortages in third-party assessment capacity, yet it published none of the capacity analysis needed to support that assertion or to reconcile it with the Department's own Table 8 projections," he said. The math in his paper, he added, "still stands against an assertion that remains undocumented."
CMMC Compliance Costs Are Impacting Assessors, Too
Even before the suspension, the raw counts had a complication the headline math didn’t capture. Jason Palmer, a Certified Public Accountant and Lead Certified CMMC Assessor, reached out after my November column with a different argument: credentialed assessors aren’t necessarily available at the market rate. Becoming a Lead CCA requires years of audit and cybersecurity or managerial experience, an advanced professional qualification, and a Tier 3 federal background check. Yet, Palmer said, “the real issue for me is the low billing rates for independent contractors." He described typical bill rates of $200 to $250 an hour for IT work related to readiness consulting, value-added reseller, or managed service provider – which require little to no specialized training – compared with $125 to $200 for the specialized CMMC assessment work the ecosystem is short on. “More people have been to outer space as astronauts (approximately 700 per Wikipedia) versus Lead Assessors (approximately 659 as of the August 2026 CyberAB Town Hall) and yet the bill rates do not reflect scarcity,” Palmer said. "The rarest of commodity is the lowest compensated."
By his own estimate based on his professional network and not published data, of roughly 659 active Lead CCAs, fewer than half were realistically available for independent work once instructors, primes' captive staff and C3PAO employees were excluded.
Readiness, Not Capacity, Is the Real CMMC Compliance Problem
Contractor readiness, not assessor capacity, is the constraint most consultants, assessors and C3PAOs point to. A survey of 102 contractors conducted by ISI, a defense cybersecurity firm, found 91% had at least one foundational compliance gap, including nearly half who hadn't completed a required internal self-assessment against the Supplier Performance Risk System. "The most common issues we encounter aren't technical, they're organizational," said David Lawrence, ISI's CEO, citing incomplete self-assessments and unconfirmed vendor cloud authorizations. ISI's survey drew self-selected respondents through a public assessment tool, a caveat worth noting alongside the topline figures.
Koran draws a sharper distinction. The objections that drove the July suspension, he said, are "overwhelmingly about remediation costs rather than assessment costs." In his view, “remediation costs are simply the price of implementing NIST SP 800-171 [security controls] that have been a contractual obligation under the Defense Federal Acquisition Regulation Supplement since 2017.” Said another way, this is nine years of deferred security work coming due at once, not a new burden created by CMMC itself.
CMMC Compliance Capacity Is Shifting
The Phase 2 pause is shifting assessment capacity in ways that will remain once the suspension is lifted. “Many C3PAOs are very small, and I’m concerned about how they might have been impacted by the loss of revenue,” Lawrence said. Koran expects some assessor capacity to migrate toward the Defense Industrial Base Cybersecurity Assessment Center, the Pentagon's internal assessment arm, which he says has been "hiring actively since the suspension was announced." Lawrence described a more immediate concern: "We're already hearing of assessors being laid off and people who were considering becoming assessors may have pulled back on this career path," meaning the pause intended to relieve pressure on contractors may complicate third party assessment once it is reinstated.
CMMC Still Requires SPRS And False Claims Act Compliance
Koran asserts that the detail most likely to be lost in coverage of the suspension is what it left in place: contractual requirements to safeguard information, report incidents, and submit self-assessment scores to the Supplier Performance Risk System. DIBCAC retains full authority to conduct government-led assessments at any time. None of that depended on the C3PAO mandate that was paused.
"Every SPRS score is still a representation to the government, and False Claims Act exposure never depended on the assessment mandate in the first place," Koran said. "It arises from the gap between what a contractor represented in SPRS and what its environment actually looked like when the score was submitted." He called that exposure "arguably more dangerous now because the pause has persuaded a portion of the industrial base that oversight itself has stopped."
Governance Stakes of CMMC Compliance
For board directors and compliance leaders evaluating CMMC, the practical takeaway isn't which side of the capacity argument was right. It's that the pause changed who signs off on a company's cybersecurity posture, not what that posture is required to be. At best, CMMC compliance is expected to be a competitive differentiator once Level 2 compliance is reinstated. At worst, False Claims Act exposure and debarment are at risk.
Another takeaway: compliance requires leadership. Readiness gets “handed off to IT because it’s labeled a ‘CMMC project,’ but this is a cross-functional management challenge,” Lawrence said. “Buy-in has to start at the top.”
Did you enjoy this story on CMMC compliance? Don’t miss my next one: use the blue “follow” button at the top of the article near my byline to follow my work, and check out my other columns here .
Loading article...