Multiple sources have confirmed that the Cyber AB was entirely unaware of the Dept. of War’s intent to temporarily suspend all third-party assessments of the CMMC program, and that Board members only learned about the plan after reading it on social media alongside the rest of the world.
In a call with C3PAO assessment companies, representatives of the AB were reportedly “aghast” at the news, and additional meetings with C3PAOs were immediately cancelled.
The AB issued a press release in which CEO Matt Travis said the AB was “both surprised and disappointed” in the decision. Travis goes on to bemoan “the immense investment that companies throughout the DIB and within the CMMC Ecosystem have already made in its future.” Travis has received massive annual salary bonuses for his role at the AB, despite that body having never accredited a single CMMC C3PAO since its formation years ago.
It is thought that the bloated cost of Cyber AB fees, alongside gold rush style profiteering by C3PAOs and blatant disregard for ethics and oversight led the current Dept. of War CIO, Kirsten Davies, to consider the pause. Increasingly, reports are emerging that C3PAO assessments under the CMMC scheme are rubber-stamp affairs and that when reported, the Cyber AB has refused to take action.
The DoW is reportedly frustrated by the “grift” nature of the program and Cyber AB’s inability to obtain ISO 17011 status as required by its sole-source contract. That the Department did not warn the Cyber AB ahead of the announcement rubs salt in that wound.
Some C3PAOs, who entered the program with the intent of actually helping improve US cybersecurity defense, have been confronted with the fraud. One C3PAO representative suggested that, at this point, the program should be cancelled outright due to bad acts by ecosystem actors, like the Cyber AB:
The amount of waste and fraud that has been shown on LinkedIn, from people whining about the [suspension], should be enough to cancel the program. It is pathetic at how many people are involved in this Ponzi scheme, making money off of the DIB, when there are many other means of securing the industry.
The Cyber AB has raked in millions of dollars since its formation, and yet has never accredited a single CMMC C3PAO. Instead, the AB worked to have its DoW contract revised to allow them to “authorize” C3PAOs in lieu of accreditation, making the scheme appear even more like a rubber-stamp affair. In response to a FOIA request for the revised contract, Stacy Bostjanick personally refused to honor the FOIA, declaring she alone had the authority to decide what the American people get to see regarding CMMC, setting the stage for a formal FOIA lawsuit. She has since retired and now works for a firm selling the CMMC services she helped create.
All signs point to the DoW cancelling CMMC outright, as the optics of a massive, multi-billion-dollar unfunded mandate placed upon American defense contractors is seen as antithetical to President Trump’s pro-business posture. Ironically, the program was launched under Trump’s first administration by his political appointee and supporter, Katie Arrington.
The majority of cybersecurity attacks are made by nation-state actors who are likely to penetrate defense of small companies regardless of what they do. In addition, these attacks are made against defense prime contractors, such as Lockheed Martin and Raytheon, and not leveled against small companies at all. The DoW and CMMC supporters remain silent when asked if Lockheed would be debarred from all Federal contracting, or face False Claims Act criminal liability, should they be hacked as they were previously, when the F-35 jet plans were allegedly stolen by China. It seems unlikely the DoW would begin debarring its main contractors, making CMMC appear theatrical.




