G-Tech Studios | Shutterstock

The Defense Department is working to resolve issues with the Cybersecurity Maturity Model Certification, placing the whole initiative in limbo. A department spokesperson said on September 16 that a final rule to implement CMMC, which was expected this month, would only come after the department has fully reviewed and approved the program.

Katie Arrington, CISO for the DoD’s Office of Acquisition and Sustainment, is under suspension related to allegations about the unauthorized disclosure of classified information. There are also reports of a potential conflict of interest over her ties to the since-resigned chairman of the CMMC Accreditation Body. A reported 670 individuals have paid close to a thousand dollars each to take exams needed to be CMMC assessors, but the courses needed to take the test aren’t expected to start until October or November. Many have also paid $1,000 to apply for the CMMC-AB recognized training courses.

Source: