Federal News
GAO Urges DoD to Strengthen CMMC Implementation
March 18, 2026
The Government Accountability Office (GAO) has issued multiple reports highlighting critical risks and gaps in the Department of Defense's (DoD) implementation of the Cybersecurity Maturity Model Certification (CMMC) program. Key concerns include insufficient assessment and documentation of external factors such as the availability of qualified third-party assessors, ecosystem capacity, evolving cybersecurity requirements, and contractor compliance oversight. The DoD has acknowledged these findings and agreed to develop mitigation strategies, improve acquisition workforce training, and align CMMC requirements with national defense priorities to ensure the program's long-term effectiveness in safeguarding sensitive defense information across its extensive contractor base.
- Why this matters: Procurement professionals and contractors must recognize that CMMC compliance is increasingly critical for contract eligibility, impacting contract awards, option exercises, and pipeline planning.
- The shortage of certified assessors and evolving standards may affect certification timelines and contractor readiness, requiring proactive engagement with accredited bodies and training organizations.
- Organizations should evaluate cost-effective approaches to meet CMMC Level 1 and Level 2 requirements without overengineering compliance to maintain competitiveness.
- The DoD's focus on assessment integrity and trust underscores the importance of rigorous, transparent cybersecurity practices for defense contractors handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
The Department will also assess the fulsomeness of CMMC requirements to address the National Defense Strategy and Secretary priorities.
— Kirsten Davies, DoD Chief Information Officer
Trust remains the cornerstone of CMMC. However, trust must be earned through rigor, transparency and assessment integrity. Strengthening this foundation is not just a governance issue; it is mission critical.
— Kevin Spease, President at ISSE Services
how CMMC Level requirements will affect contract awards, option exercises, and pipeline planning
— Cy Alba
Agencies
Department of Defense, Government Accountability Office, National Institute of Standards and Technology, General Services Administration, Department of Defense Office of Inspector General
Vendors
Cyber AB, Cyber Accreditation Body, ISACA, Cybersecurity Assessor and Instructor Certification Organization
Locations
Sources
- GAO report highlights risks to CMMC rollout as nation-state attacks target defense contractors - Industrial Cyber · Industrial Cyber · Mar 16
- DoD to evaluate βexternalβ CMMC risks | Federal News Network · Federal News Network · Mar 12
- GAO: DOD Needs to Improve Implementation of CMMC · meritalk · Mar 13
- Watchdog urges DOD to address external factors affecting CMMC implementation | DefenseScoop · DefenseScoop · Mar 12
- GAO Says DOD Should Better Assess Contractors' Cyber Risk - Law360 · Law360 · Mar 12