Artificial Intelligence Fuels Global Cyber Crisis As Breaches Skyrocket
The Rise of AI-Enabled Cyberattacks: A Growing Concern for Organizations Worldwide In a recent …
16. July 2026

The pause on third-party audits in the Defense Department’s Cybersecurity Maturity Model Certification (CMMC) program has sparked concerns among industry officials and experts, who argue that a review regime is necessary to ensure the integrity of cybersecurity standards.
CMMC was designed to address the issue of contractors grading their own homework. The program requires companies working with the DoD to undergo assessments to ensure compliance with cybersecurity standards. Industry experts agree that even if the pause does not lower the cybersecurity expectations, it leaves a gap in how the department can hold contractors to those standards.
Jacob Horne, Chief Cybersecurity Evangelist at Summit 7, noted that the fundamental problem identified by the DoD Inspector General seven years ago is that the department’s policy of letting contractors grade their own homework is a failure. “The question that’s never been answered is ‘how does the government know what you claimed in your self-assessment is true?’” Horne said.
Without third-party validation, the Pentagon relies more heavily on contractors’ word, which can increase uncertainty and False Claims Act risk. Michael Brooks, a lead CMMC Certified Assessor at A-LIGN, highlighted the challenges of relying solely on self-assessments. “That can increase uncertainty for program offices, prime contractors, and supply chain partners, while also increasing False Claims Act risk when cybersecurity assertions cannot be substantiated,” he said.
Georgianna Shea, chief technologist at the Foundation for Defense of Democracies Center on Cyber and Technology Innovation, suggested that the DoD didn’t necessarily need a third-party assessment to assess cybersecurity standards but needed some kind of proof. “The central policy question should not be whether third-party assessments are universally good or bad. It should be whether the Department can obtain reliable evidence of cybersecurity in a manner proportionate to the actual risk,” she said.
Cybersheath CEO Emil Sayegh emphasized that most organizations genuinely believe they are compliant but struggle with interpreting and objectively evaluating cybersecurity controls without independent validation. “Third-party assessments were never just about identifying bad actors. They were designed to provide an objective measure of cybersecurity maturity and create accountability in a system that otherwise relies heavily on contractor self-representations,” Sayegh said.
Industry experts agree that the pause on Phase II has raised questions about the adequacy of self-assessments and the need for third-party validation. As the Pentagon develops a new framework for CMMC, industry experts hope it will preserve the security objectives of the program while reducing unnecessary cost and complexity.
Shea suggested that the department may slim down Phase II-style third-party assessments to be more fit for purpose, with stronger certification standards for higher-risk work. “I do not think the Phase 2 suspension necessarily kills CMMC, but it may end CMMC as a broadly applied, certification-centered program,” Shea said. “The direction signaled by the Department appears to be a more risk-based model: lighter requirements and self-assessment for lower-risk contracts, with stronger evidence and independent or government-led assessment reserved for information, systems, and suppliers that present greater mission consequences.”
This approach could reduce unnecessary barriers for small and nontraditional businesses without treating every contractor as though it presents the same level of risk. The challenge will be determining risk consistently. Shea noted that ensuring consistency in assessing risk while maintaining the security objectives of CMMC is crucial.
The pause on third-party audits has sparked concerns about the adequacy of cybersecurity standards and the need for a review regime to ensure compliance. Industry experts emphasize the importance of reliable evidence and objective validation to enforce cybersecurity standards.
CMMC was designed to address the issue of contractors grading their own homework and ensure that defense contractors are compliant with cybersecurity standards. The pause on Phase II has raised questions about the adequacy of self-assessments and the need for third-party validation.
Industry experts agree that a more risk-based model could be more effective in reducing unnecessary barriers for small and nontraditional businesses. The development of a new framework for CMMC is crucial in addressing these concerns.
The framework should strike a balance between security objectives, cost, and complexity, ensuring that the program remains effective in enforcing cybersecurity standards without placing an undue burden on contractors.