Skip to main content

Cyber AB Wants Delta Assessments and a CMMC Transition Plan

Cyber AB CEO Matthew Travis told Federal News Network what the accreditation body asked for in its response to the CMMC reform RFI, concentrating on changes the department could make without new rulemaking. The central one is a way to reassess only what changed. A certified company that modernizes its network today has to go back to a C3PAO and pay for a full assessment, with no continuous monitoring option and no delta assessment, and Travis pointed to FedRAMP as a model worth borrowing. He also wants two-assessor teams permitted for smaller companies that are well organized, plus faster background investigations for assessors, since the current backlog limits how many enter the workforce and keeps costs high. He asked the task force to clarify how FedRAMP and CMMC fit together. Travis said nearly 2,000 companies now hold Level 2 certification, and any transition plan should preserve the value of that work through reciprocity or standards acceptance.

Read the article

Federal News Netwrok — September 14, 2026


Back to List