From compliance to resilience — the latest signals from DoW CIO Kirsten Davies, as of Monday, 7 September 2026.

What Davies is signaling
At DIBX 2026 on 26 August, DoW CIO Kirsten Davies indicated the Reform Task Force received ~1,100 RFI responses comprising more than 11,000 pages.
The Department wants to move away from cybersecurity that primarily produces compliance artifacts and toward cybersecurity that demonstrates actual risk reduction and operational resilience.
Her message
“Protecting federal information remains the baseline. The next question is whether the DIB can continue operating through a cyberattack.”
Davies emphasized operational technology (OT) and production resilience — the systems, controllers, workstations and manufacturing infrastructure required for a defense supplier to actually produce and deliver capability.
The DoW CIO website notes continued evaluation of industry input and cites inconsistent government CUI designation and portion marking as a source of friction across the DIB.
What the Reform Task Force is examining
The RFI provides the clearest indication of what could emerge. DoW specifically asked industry how it could:
- Reduce the largest CMMC cost and administrative burdens.
- Identify controls producing measurable cyber-risk reduction.
- Eliminate requirements producing administrative burden without corresponding security improvement.
- Recognize commercial cybersecurity capabilities, platforms and managed services.
- Improve and potentially streamline self-assessment.
- Reduce barriers for small and nontraditional contractors.
- Improve operational resilience against cyberattacks.
DoW is explicitly investigating whether existing commercial cybersecurity capabilities, platforms and managed services can be recognized within the compliance and risk framework, rather than requiring every DIB company to construct an expensive bespoke compliance environment.
Where I believe CMMC is heading
There is not yet an official replacement architecture, so this is an assessment rather than announced DoW policy. The evidence increasingly points toward something resembling a shift from CMMC compliance certification to continuous DIB cyber-risk and resilience assurance, with several layers.
| Layer | Likely emphasis |
|---|---|
| CUI protection | NIST 800-171 remains baseline |
| Architecture | Clearly bounded CUI environments and enclaves |
| Verification | Self-assessment plus targeted government validation |
| Risk | Greater emphasis on actual exploitable risk |
| Technology | Increased recognition of commercial and cloud security services |
| Resilience | Ability to continue mission and production following attack |
| OT | Manufacturing and operational systems become more important |
| Government oversight | Risk-based targeting rather than universal expensive assessments |
This would preserve the security objectives of CMMC while potentially changing how compliance is demonstrated.
People · Strategy · Technology · Resilience — a stronger, more resilient tomorrow.
Notice: this update is compiled from third-party and open information available as of 7 August 2026.