Federal News
GAO Flags DoD Cybersecurity Certification Gaps
March 18, 2026
The Government Accountability Office (GAO) has identified critical gaps in the Department of Defense's (DoD) implementation of the Cybersecurity Maturity Model Certification (CMMC) program, which is designed to enhance cybersecurity standards among defense contractors. Key issues include a shortage of qualified third-party assessors and challenges adapting to evolving cybersecurity requirements. The DoD has agreed to address these concerns by developing systematic risk assessments and mitigation strategies to ensure the program's effectiveness and sustainability.
- Why this matters: Defense contractors must be aware of potential delays or changes in CMMC certification processes that could impact contract eligibility and compliance timelines.
- The shortage of assessors may affect the pace at which contractors can achieve or renew certifications, influencing procurement schedules.
- Procurement professionals should factor in evolving cybersecurity standards and GAO recommendations when planning contract requirements and vendor evaluations.
- Organizations supporting defense cybersecurity compliance can anticipate increased demand for assessor training and risk management services as the DoD responds to GAO's findings.
Agencies
Department of Defense, Government Accountability Office, National Institute of Standards and Technology
Locations
Sources
- GAO Flags Gaps in Pentagon Cyber Certification Rollout for Defense Contractors · The Defense Post · Mar 18