The U.S. Department of Defense announced on the 13th that it is suspending the advancement of the third-party assessment requirements for Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program and initiating a 60-day "top-to-bottom" comprehensive review of the certification initiative. This move signifies a major potential adjustment to the long-standing cybersecurity compliance mechanism for contractors used by the U.S. military.
In a memorandum signed on the 13th, Department of Defense Chief Information Officer Kirsten Davies stated that the DoD has decided to pause the CMMC Phase 2 requirements originally scheduled to take effect on November 10, 2026. According to the original plan, this phase would have mandated that all defense contractors handling sensitive but unclassified information undergo third-party cybersecurity assessments. Davies noted that the Phase 1 self-assessment requirements, which took effect last November, remain in force, but all pending and future CMMC milestone deadlines are now "paused pending further notice."
Defense officials revealed that the core rationale behind this suspension and review is a significant conflict between the cumbersome procedures of the current CMMC mechanism and the "Weapons Systems Acquisition Reform" initiative championed by Secretary of Defense Pete Hegseth. Hegseth's procurement reform aims to eliminate administrative bureaucracy and foster technological innovation.
In the memorandum, Davies emphasized that while the current version of the CMMC certification mechanism is designed to enhance security, it has imposed substantial and often exclusionary administrative and financial burdens on the U.S. Defense Industrial Base (DIB), particularly on small and non-traditional businesses that serve as engines of innovation. Data from the Department of Defense and feedback from the Small Business Administration (SBA) indicate that high compliance costs, a severe shortage of capacity among third-party assessment organizations, and a complex regulatory timeline are driving key new technology providers and small businesses away from bidding on military contracts, leading to a substantive loss of critical supply chain participants.
To address this, Davies has authorized the establishment of a 60-day "CMMC Reform Task Force" responsible for providing recommendations for a new alternative framework. This framework will prioritize the speed of delivering technical capabilities, lower the barrier to entry for small businesses and non-traditional suppliers, and replace high-cost, pro forma third-party certifications with scalable, practical, day-to-day cyber protection measures.
SBA Administrator Kelly Loeffler issued a statement the same day expressing support for the Defense Department's decision to pause. Loeffler pointed out that small businesses are the cornerstone of the national security supply chain, and CMMC compliance is becoming an insurmountable barrier, supporting the military's efforts to cut such high-cost administrative red tape.
The Cybersecurity Maturity Model Certification (CMMC) program was initially launched during former President Trump's first term, aiming to introduce independent third-party auditors to conduct mandatory assessments of cybersecurity levels across the vast defense contractor base, addressing long-standing issues with inaccurate contractor self-assessments. However, due to excessively high compliance costs, the program also faced suspension and simplification during the Biden administration. The U.S. military previously estimated that approximately 80,000 companies would be subject to its rules. This return to a review track reflects the deep-seated, difficult-to-reconcile conflict within the U.S. military between strengthening supply chain cybersecurity and maintaining the scale and vitality of its industrial base.