Terry Gerton Last week, the window for the comments on the CMMC rules from DoD closed, and also DoD issued a class deviation regarding CMMC compliance. Help us sort out the signals there. What should people be reading?
Stephanie Kostro So a lot has been happening, Terry, on the CMMC front this year. And it started really in earnest a few months ago with, I’ll cite the chief information officer from the Department of War’s memo in July, regarding pausing and suspending CMMC’s requirements. That said, there’s been a lot of chatter about what that meant. So we welcomed the class deviation that came out just a few days ago regarding instructions to contracting officers about what they should be including in contracts. And so it offered us a really good insight into how the building — the Department of War — is approaching CMMC. I’ve been fielding lots of questions from contractors about what should they be doing, what should be looking for. So let me just level set, if I may, what this class deviation is and what it is not. The first question that we get is, “is this the death knell of CMMC,” the Cybersecurity Maturity Model Certification Program that has been around for a few years and gone through many permutations, right? This is not the death knell of CMMC. In no way, shape, or form does this class deviation say, CMMC is dead. I can insert all sorts of pop culture references to “bring out your dead” or, you know, “I’m not dead yet,” that kind of thing. I would say that this is not an obituary for CMMC. What it does do is reference that July memo from the chief information officer suspending the program, but not suspending cybersecurity requirements. And let me just unpack that for you, Terry, just really quickly. The core cybersecurity requirements remain, and that is — I’m going to dork out with you here — DFARS 252.204-7012, that is the safeguarding requirements. It remains pertinent that contractors have to live up to NIST Special Publication 800-171, Revision 2; that is still the control. It does look at the Supplier Performance Risk System, which is what we call SPRS, and those scoring requirements, those are still the same. And there is still an annual affirmation of compliance with all of these requirements. Those things are still in existence. So I just want to dispel any rumors, myths, etc., out there among contractors that this class deviation guts cybersecurity. It does not.
Terry Gerton Stephanie, with those provisions though, what’s the difference between this and the CMMC rules then?
Stephanie Kostro CMMC really laid out different levels. So, level 1 was the basic level. If you were a CMMC level 1, you did a self-assessment and you could affirm that you are cybersecure to a certain level. Level 2 is still retained that you can do this self-assessment. What it does right now is it gets rid of the outside assessment piece — we call them C3PAOs, so it’s a cybersecurity entity outside of your company that would come in and certify your system or your approach to cybersecurity. And so it does suspend that. It suspends the Phase 2 transition, where you would start going towards this level 2 by an outside assessor. Level 3 also exists; it’s the toughest CMMC level. That is also still suspended. So it retains the self-assessments, it retains baseline compliance with NIST 800-171-Rev. 2, which I mentioned earlier. And it does require contracting officers to update active solicitations to reflect all these changes. So this is — I think it was more than 80 pages of a class deviation, they showed the line-in, line-out. It should be very, very clear what is still required and what is no longer required right now. Meanwhile, Terry, we are still waiting for the department to share the results of its review that the CIO asked for two months ago. Right about now is when the review should be ending, and hopefully the department and the officials will come and tell industry what the results of that review are and what industry will be required to do going forward.
Terry Gerton Stephanie Kostro is president of the Professional Services Council. Stephanie, on that last point, during this 60-day window, I’ve had the opportunity to talk to lots of contractors and I would say they fall into two buckets. One is, “I’m so proud I was an early adopter of CMMC Level 2 and got my certification. That’s my competitive advantage.” And the other group of contractors says, “I’m not ever doing that unless I absolutely, positively have to.” So when you think about all of the uncertainty around this, what should contractors be thinking about which bucket is best?
Stephanie Kostro I have had the same experience, Terry, where we’ve got these two schools of thought. And I would say that if you have undertaken an outside review, an outside assessment of your approach to cybersecurity, that was money well spent because there are still going to be cybersecurity requirements going forward. And let’s be honest, sunk costs are sunk. You’ve already paid the outside assessment. You’ve got the piece of paper, virtual or not, that you can wave in front of people. And I think that was a good investment. That said, if requirements do change going forward, I don’t blame companies for going, hey, you know, I haven’t started my assessment, I’m way back in the queue waiting for my assessment, I’m going to hit pause until I find out what the actual requirements are. So I think that’s a good way forward as well. What we’re watching for, Terry, are a few things. I mentioned earlier that I would love to talk to department officials, have them talk to industry about this review that’s been going on for the last two months and where they’re going. I would love a little bit of insight into that Magic 8 Ball there. I would also say we’re looking for another memo from the Department of War CIO, right? Everything in this class deviation that just came out was predicated, or cited as its authority, the July memo from the CIO. I would hope that the CIO would come out with a new memo once all of this officially says, you know, here’s where we’re going with this. So that’s what we’re watching for as well. I would love to have conversations with department officials on where they’re heading once they figure it out themselves.
Terry Gerton Well, Stephanie, let’s shift from cybersecurity to border security. That’s been a topic for PSC over the last year, and coming back onto the top of your agenda, what’s happening now that’s bringing it back to the forefront for you?
Stephanie Kostro Border security has been a hot topic, not just for Professional Services Council member companies, which represent, as you know, Terry, some 400 companies that do government services and technology solutions for every single agency within the federal government. A huge federal customer over the last few years, to be honest, has been the Department of Homeland Security and specifically Customs and Border Protection. Our vice president for civilian agencies, Krista Sweet, has worked tirelessly with DHS and CBP in particular to organize a border tour out to the southwest border. We are bringing a dozen or so companies with PSC staff to San Diego and Los Angeles, Long Beach. Now, you may be wondering, what kind of boondoggle is this? You’re going in September? The answer is simple. We had scheduled this border tour to go to the ports of Los Angeles and Long Beach, to also go to some land border crossings near San Diego — so the Office of Field Operations in San Ysidro and Otay Mesa, the ports of entry and the border patrol along the U.S.-Mexico land border near San Diego. We organized this trip a year ago, but then there was a shutdown, the longest ever in U.S. federal government history. And then DHS remained shut down earlier this year. So even though CBP had money because of the One Big Beautiful Bill Act and Reconciliation 2.0, we were still facing a shutdown. So we are finally having this trip. It’s going to be Sept. 30 and Oct. 1. They’re going to hit all of these great ports of entry to see what’s going on. They’re going to get operational briefings, facility tours, tech demonstrations, and they’re going to have direct conversations with frontline officers and agents. I’m so excited for this trip, and I’m thrilled that it’s finally happening.
Terry Gerton What does an on-the-ground experience change for these contractors beyond the normal business-to-government conversations?
Stephanie Kostro You know, I think we live so often in our D.C. bubble, Terry … we’re here talking to headquarters staff who operate in these big, beautiful buildings here in Arlington or at St. Elizabeth’s or in downtown D.C. And we don’t actually talk to folks who, from a domestic border perspective, have boots on the ground. You know, I come from a Department of Defense-slash-War background, so I’m used to talking about boots on the ground in overseas environments, right? But literally at these ports of entry, they are the first line of defense when it comes to making sure that the borders are protected. And this is a nonpartisan issue, or a bipartisan issue. Democrats and Republicans alike all have often talked about the border. Contractors talking to folks who have skin in the game, who are actually walking the border, who are checking in all of the cargo that comes on ships from overseas, or even just that come into our territorial waters — it’s important for contractors to understand that these are the customers they’re serving. It’s not the folks sitting here in the National Capital Region. It’s those folks out on the operational field. So I think as we get companies out there talking to folks, it’s going to bring home why it is that they do what they do and how can they do it better.
Terry Gerton And do you see a change in understanding from the government frontline folks when they actually talk to the contractors as well?
Stephanie Kostro One hundred percent. Because, you know, they look at it and go, oh, you guys are in D.C. and you always talk to the head shed or you talk to headquarters folks; you never come and talk to us about what we need. And this changes their perspective as well. What’s fortunate is when you get an industry association like PSC organizing this trip, the lawyers are also happy because we’re not just bringing one company to talk to a field office. We’re bringing a dozen companies. So you don’t get that conflict of interest either. I think at the end of the day, we would love to do this more often. You know, PSC has long had a series on the Hill, called PSC on the Hill, where we do demonstrations for congressional staff and members. This is a PSC in the Field, and I love this series of events, and I hope to have more of them going forward.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
