CMMC After the Pause: Charting the Path Forward
While the DoW resolves what’s next for CMMC following the Phase 2 pause, contractors face two urgent questions: Will I still need a third-party (C3PAO) assessment, and what should I do today to avoid wasting money or losing contract eligibility?
The Department has yet to announce its final conclusions. However, announcing the suspension, Under Secretary Michael Duffey stated: “We’re not relaxing the standards by any means… What we’re removing is the bureaucracy of the third-party assessment.” That statement, combined with their RFI questions, signals exactly where the DoW is looking to drive change.
Join PreVeil on September 16 1PM ET as we speak with:
- Travis Goldbach, VP of Strategic Business Development & GTM at Coalfire Federal
- Dr. Thomas Graham, VP, CISO & CMMC Provisional Assessor/Instructor at Redspin
- Michael Barker, Cybersecurity Lead at Georgia MEP, CCP & CCA
We’ll cover:
- What the DoW has signaled through their statements and questions about what’s changing and what’s not
- Where SMBs should focus their compliance efforts
- How the DoW can cut compliance red tape without lowering the bar on CUI security
- Where our RFI responses converge and what that suggests for the future

Travis Goldbach
VP of Strategic Business Development & GTM at Coalfire Federal
Travis Goldbach leads go-to-market strategy at Coalfire Federal, a Certified Third-Party Assessment Organization (C3PAO) for CMMC Level 2. He joined after running CMMC go-to-market globally at AWS, and brings 20 years in cybersecurity and compliance leadership across the DIB.

Dr. Thomas Graham
P, CISO & CMMC Provisional Assessor/Instructor at Redspin
Dr. Thomas Graham is VP and CISO at Redspin, where he helped establish one of the industry’s first authorized C3PAOs and has led more than 150 CMMC assessments across the US, Canada, and Europe. He chairs the Cyber AB’s C3PAO Accreditation Committee and trains new assessors as a CMMC Provisional Instructor.

Michael Barker
Cybersecurity Lead at Georgia MEP, CCP & CCA
Michael Barker leads cybersecurity services at the Georgia Manufacturing Extension Partnership, helping small and mid-sized manufacturers build toward CMMC certification. He holds a Doctor of Science in Information Technology and brings more than 20 years of experience in information security, GRC, and digital forensics.
PROUDLY MADE IN THE USA
PreVeil is 100% Designed & Developed in the USA