CMMC Update: From Compliance to Resilience

From compliance to resilience — the latest signals from DoW CIO Kirsten Davies, as of Monday, 7 September 2026.

What Davies is signaling

At DIBX 2026 on 26 August, DoW CIO Kirsten Davies indicated the Reform Task Force received ~1,100 RFI responses comprising more than 11,000 pages.

The Department wants to move away from cybersecurity that primarily produces compliance artifacts and toward cybersecurity that demonstrates actual risk reduction and operational resilience.

Her message

“Protecting federal information remains the baseline. The next question is whether the DIB can continue operating through a cyberattack.”

Davies emphasized operational technology (OT) and production resilience — the systems, controllers, workstations and manufacturing infrastructure required for a defense supplier to actually produce and deliver capability.

The DoW CIO website notes continued evaluation of industry input and cites inconsistent government CUI designation and portion marking as a source of friction across the DIB.

What the Reform Task Force is examining

The RFI provides the clearest indication of what could emerge. DoW specifically asked industry how it could:

  1. Reduce the largest CMMC cost and administrative burdens.
  2. Identify controls producing measurable cyber-risk reduction.
  3. Eliminate requirements producing administrative burden without corresponding security improvement.
  4. Recognize commercial cybersecurity capabilities, platforms and managed services.
  5. Improve and potentially streamline self-assessment.
  6. Reduce barriers for small and nontraditional contractors.
  7. Improve operational resilience against cyberattacks.

DoW is explicitly investigating whether existing commercial cybersecurity capabilities, platforms and managed services can be recognized within the compliance and risk framework, rather than requiring every DIB company to construct an expensive bespoke compliance environment.

Where I believe CMMC is heading

There is not yet an official replacement architecture, so this is an assessment rather than announced DoW policy. The evidence increasingly points toward something resembling a shift from CMMC compliance certification to continuous DIB cyber-risk and resilience assurance, with several layers.

LayerLikely emphasis
CUI protectionNIST 800-171 remains baseline
ArchitectureClearly bounded CUI environments and enclaves
VerificationSelf-assessment plus targeted government validation
RiskGreater emphasis on actual exploitable risk
TechnologyIncreased recognition of commercial and cloud security services
ResilienceAbility to continue mission and production following attack
OTManufacturing and operational systems become more important
Government oversightRisk-based targeting rather than universal expensive assessments

This would preserve the security objectives of CMMC while potentially changing how compliance is demonstrated.


People · Strategy · Technology · Resilience — a stronger, more resilient tomorrow.

Notice: this update is compiled from third-party and open information available as of 7 August 2026.

Keep reading

From the Desk of David Shaw

All posts in this section  ·  CMMC readiness for defense contractors

Start the conversation

Talk to a cybersecurity engineer — not a sales rep.

Tell us your industry and where you are today. We’ll route you to the right specialist and a practical next step — no pressure, no jargon.