Blog

November 10, 2026, marks a significant turning point: Certified Third-Party Assessment Organization (C3PAO) certification will become essential for CMMC Level 2 Controlled Unclassified Information (CUI) environments. Small and mid-sized contractors who act decisively by narrowing their scope and partnering with independent experts like JANUS Associates will protect revenue, outpace competitors, and demonstrate resilience in an intensifying defense supply chain. 

Today, cybersecurity is more than just having the right technology. As threats and rules change, organizations need to be proactive, not just reactive. A structured cybersecurity maturity assessment framework empowers leaders to evaluate their risk posture, prioritize improvements, and align operations with global standards such as CMMC Cyber Security, NIST, and ISO 27001.

The Department of Defense (DoD) has suspended the original cybersecurity certification program pending major changes. On November 4, 2021, the DoD announced the completion of an internal review of its Cybersecurity Maturity Model Certification (CMMC) program and the release of Model 2.0.

Patricia Fisher, President and CEO of JANUS Associates, Inc. is one of the Founding Partners of the Connecticut Technology Council (CTC) and continues on the board in addition to leading the Cyber Security Task Force. Ms. Fisher is also involved in other technology-oriented associations.