📊 Key Data
  • 60-day review: The Department of War has suspended CMMC Phase II requirements and formed a task force to reassess the program.
  • $594,000 cost estimate: Small firms face nearly $600,000 in compliance costs for CMMC Level 2 certification.
  • 100,000+ companies affected: Over 100,000 contractors may require third-party assessments under the original plan.
🎯 Expert Consensus

Experts agree that while the pause introduces uncertainty, it reflects longstanding concerns about cost and complexity in cybersecurity compliance for defense contractors.

5 days ago
CMMC in Limbo: War Department Pauses Cybersecurity Rule, Leaving Contractors Reeling

CMMC in Limbo: War Department Pauses Cybersecurity Rule, Leaving Contractors Reeling

NATIONAL HARBOR, MD – July 15, 2026 – In a move that sent shockwaves through the nation's defense industrial base, the Department of War announced the suspension of its landmark Cybersecurity Maturity Model Certification (CMMC) Phase II requirements. The decision, which halts the impending mandate for third-party cybersecurity assessments, is coupled with the formation of a CMMC Reform Task Force tasked with a 60-day, top-to-bottom review of the entire program. The announcement creates a familiar and frustrating state of limbo for the tens of thousands of companies that supply the U.S. military, many of whom have invested significant capital to meet a compliance deadline that has now vanished.

The Cyber AB, the non-profit organization responsible for accrediting CMMC assessors, was caught off guard. “While we are both surprised and disappointed in yet another momentary pause to this original and vital Trump Administration program, we are confident that the continued and measurable progress of CMMC... will prove itself indispensable under a rigorous review,” stated Chief Executive Officer Matthew Travis. The statement underscores the deep-seated tension now at play: a clash between a new departmental philosophy aimed at slashing bureaucracy and the established, multi-year effort to fortify the digital supply chain.

This decision is the first major regulatory overhaul under the recently renamed Department of War, a symbolic rebranding intended to signal a more aggressive, “warrior ethos.” The CMMC pause appears to be the first practical application of this new doctrine, directly targeting what leadership perceives as a barrier to agility and industrial base expansion.

A Familiar Refrain of Stop and Start

For veterans of the defense industry, this week's 'momentary pause' feels less like a brief intermission and more like a rerun of a show they’ve seen before. The CMMC program’s history is a case study in the difficulty of implementing sweeping security mandates across a diverse industrial base. Its journey began in 2015 with the rollout of NIST SP 800-171, a set of 110 security controls that contractors were expected to self-attest to. When data breaches continued unabated, the Pentagon concluded that self-attestation was failing.

This led to the birth of CMMC 1.0 in January 2020, a framework that introduced five maturity levels and mandated third-party verification. But the program immediately ran into fierce headwinds. Industry critics and small business advocates decried its complexity, the high costs of compliance, and the inclusion of CMMC-unique requirements that went beyond the established NIST standards. A critical shortage of approved assessors made the entire timeline seem unworkable. In response, the Biden administration hit pause, conducting its own internal review which culminated in the November 2021 announcement of CMMC 2.0.

CMMC 2.0 was intended to be the solution. It streamlined the model into three tiers, aligned more closely with NIST standards, and allowed for self-assessments for less critical contracts. After a lengthy rulemaking process, the program was codified just eight months ago, and the defense sector began moving with purpose toward the Phase II deadline of November 10, 2026. Now, that deadline has been erased, bringing the program full circle to another high-stakes review, driven by the very same concerns that scuttled its first iteration: cost, complexity, and the burden on small businesses.

The High Cost of Compliance

The Department of War’s rationale for the suspension centers on a core plank of Secretary Pete Hegseth’s Acquisition Transformation System (ATS): reducing barriers for small and non-traditional businesses. Officials became convinced that the CMMC program, as structured, was doing the opposite. The Small Business Administration had sounded the alarm, with estimates suggesting that achieving CMMC Level 2 compliance could cost a small firm nearly $594,000 for a third-party assessment and hundreds of thousands more in supporting costs.

“We were looking at spending over half a million dollars we don't have, for a certification that didn’t directly add a single new security feature we hadn’t already planned,” said one executive at a mid-sized aerospace supplier, speaking on condition of anonymity. This sentiment was widespread. The high costs were reportedly driving innovative companies away from the defense market, directly threatening the Pentagon’s goal of broadening its industrial base.

Furthermore, the program's logistics were buckling under their own weight. With over 100,000 companies estimated to require a third-party assessment, the existence of only around 110 authorized CMMC Third-Party Assessment Organizations (C3PAOs) created a mathematical impossibility. The resulting bottleneck would have made a smooth rollout chaotic at best. The new administration saw a program that was “structurally incompatible” with its goal of rapidly expanding the DIB and chose to act decisively.

Navigating the Uncharted Pause

While the pause offers a reprieve from immediate certification costs, it plunges the Defense Industrial Base into a state of profound strategic uncertainty. For the nearly 2,000 defense contractors that The Cyber AB reports have already achieved CMMC Level 2 certification, the move is particularly vexing. Their proactive investment, once a competitive advantage, is now a sunk cost with an unclear return.

However, it is critical for all contractors to understand what has not been suspended. The foundational requirements to protect Controlled Unclassified Information (CUI) under the DFARS 7012 clause and NIST SP 800-171 remain fully in effect. Phase I self-assessment and reporting obligations are also unchanged. The suspension only removes the mandatory third-party verification layer, shifting the enforcement burden.

This creates a new and potent risk. With the government stepping back from pre-award verification, the focus will inevitably shift to post-award enforcement through the False Claims Act. Any company that self-attests to compliance without having done the work is now more exposed than ever to the Department of Justice's Civil Cyber-Fraud Initiative. “A Level 2 certification by a C3PAO remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk,” Travis noted, highlighting that the underlying need for robust, verifiable security has not disappeared.

A Mandate for Reform

The 60-day CMMC Reform Task Force, led by DoW CIO Kirsten Davies, is now the focal point for the program's future. Its mandate is to align CMMC with the ATS directives, emphasizing “scalable, realistic security measures” over “prohibitive, third-party compliance models.” The task force will synthesize industry feedback and is expected to explore a range of alternatives, from greater reliance on self-attestation and targeted government audits to the use of secure enclaves and commercial cybersecurity platforms.

For its part, The Cyber AB is standing by to assist, emphasizing the significant ecosystem built over the last several years, which includes over 1,000 certified assessors and thousands of certified professionals. Travis framed the moment as an opportunity for improvement. “The Arsenal of Freedom demands the right balance of security and efficiency in order to protect and enable our warfighters,” he said. “We know there is more innovation and improvement to be found and CMMC stakeholders want to contribute to this reform.”

As the task force begins its work, the entire defense ecosystem holds its breath. The challenge remains the same as it was in 2015: how to ensure the security of the nation’s most sensitive defense information without crippling the very industrial base responsible for creating it. This pause is not an end to that challenge, but merely the start of its next, uncertain chapter.

Topics & Related

Sector:
Aerospace & Defense
Government Services & GovTech
Theme:
Compliance Frameworks (SOC2/ISO27001)
Event:
Policy Change

📝 This article is still being updated

Are you a relevant expert who could contribute your opinion or insights to this article? We'd love to hear from you. We will give you full credit for your contribution.

Contribute Your Expertise →
UAID: 43173