Skip to main content
Defense Supply ChainPolicy ExplainerAug 20, 2026, 1:20 AM· 5 min read· in defense security

Pentagon Suspends Major Cybersecurity Rule for Defense Contractors Over $7 Billion Cost Concerns

The Department of Defense has abruptly halted Phase II of its Cybersecurity Maturity Model Certification (CMMC) program, citing prohibitive costs for small businesses. A 60-day review will seek to balance supply chain security with the need to keep innovative firms in the defense industrial base.

By Aarav Khanna

Small & Medium Defense Contractors 40%Cybersecurity Assessors & Early Adopters 30%Pentagon Leadership 30%
Small & Medium Defense Contractors
View the suspension as a necessary intervention to prevent mass bankruptcies and supply chain consolidation.
Cybersecurity Assessors & Early Adopters
Express frustration over sunk costs and warn that self-assessments leave the supply chain vulnerable.
Pentagon Leadership
Focus on balancing baseline data security with the need to rapidly acquire commercial technology.

At a glance

  1. The Department of Defense suspended Phase II of the CMMC program, which would have mandated third-party cybersecurity audits for contractors.
  2. The decision was driven by Small Business Administration data projecting a $7 billion annual compliance cost for small and mid-sized firms.
  3. Phase I self-assessment requirements and underlying NIST SP 800-171 obligations remain fully enforceable.
  4. A newly formed CMMC Reform Task Force is conducting a 60-day review to propose scalable security alternatives.

The Department of Defense has abruptly halted the rollout of its flagship cybersecurity certification program for defense contractors, suspending Phase II of the Cybersecurity Maturity Model Certification just months before it was scheduled to take effect. The decision pauses a mandate that would have required tens of thousands of companies to undergo costly third-party cybersecurity audits beginning in November 2026. By freezing the timeline, the Pentagon has temporarily relieved the defense industrial base of a massive compliance hurdle, while simultaneously injecting deep uncertainty into the regulatory ecosystem.[1][5]

Announced jointly by Department of Defense Chief Information Officer Kirsten Davies and Under Secretary for Acquisition and Sustainment Michael Duffey, the suspension represents the most significant recalibration of defense cybersecurity policy in years. The move is explicitly designed to prevent a mass exodus of small and mid-sized manufacturers from the defense supply chain. Officials concluded that the stringent audit requirements, if enforced on schedule, would create a bottleneck that prioritized compliance over the rapid acquisition of commercial technology.[4][5]

To understand the systemic impact of the reversal, it is necessary to examine the architecture of the CMMC program. Originally established in 2019, the framework was engineered to ensure that any company handling Controlled Unclassified Information meets specific, verifiable cybersecurity controls before being awarded a defense contract. The entire structure is built upon the National Institute of Standards and Technology SP 800-171 guidelines, which detail 110 specific security controls required to protect sensitive government data residing on non-federal systems.[3][5]

The rollout was deliberately structured in escalating phases to allow the industrial base time to adapt. Phase I, which took effect in late 2025, required contractors to complete internal self-assessments of their cybersecurity posture and submit their scores to a central government database. Phase II, slated for November 10, 2026, would have fundamentally altered the enforcement mechanism by mandating that contractors pass an independent audit conducted by a Certified Third-Party Assessor Organization as a strict condition of contract award.[3][5]

Phase II of the CMMC rollout, which mandated third-party audits, has been indefinitely suspended.

The primary catalyst for the suspension is the staggering financial projection associated with those independent audits. According to data circulated by the Small Business Administration, the transition to mandatory third-party assessments was projected to cost small and mid-sized defense contractors more than $7 billion annually. For many lower-tier suppliers—machine shops, specialized component manufacturers, and software developers—the cost of hiring consultants, upgrading IT infrastructure, and paying the assessors was viewed as an untenable barrier to entry.[1][2]

The primary catalyst for the suspension is the staggering financial projection associated with those independent audits.

Small business advocates lobbied aggressively against the Phase II deadline, arguing that the administrative burden was fundamentally incompatible with the economics of small-scale defense contracting. Organizations representing these firms warned that the costs were pushing innovative commercial technology providers out of the defense sector entirely. By suspending the requirement, the Pentagon aims to prioritize speed to capability and lower barriers for non-traditional businesses, aligning with broader administration directives to streamline procurement and reduce bureaucratic friction.[4]

Small Business Administration data suggests Phase II compliance could cost small and mid-sized contractors upwards of $7 billion annually.

However, the abrupt suspension has disrupted a compliance ecosystem that spent years and millions of dollars preparing for the November deadline. Defense contractors that proactively invested capital to upgrade their networks and secure early third-party audits now find themselves at a competitive parity with firms that delayed compliance. This creates a moral hazard within the supply chain, potentially disincentivizing future proactive investments in cybersecurity infrastructure if contractors believe deadlines will ultimately be waived.[2][5]

The pause also severely impacts the nascent industry of cybersecurity assessors built specifically to service the CMMC mandate. The Cyber AB, the nonprofit accreditation body sanctioned by the government to manage the ecosystem of third-party assessment organizations, was reportedly not notified in advance of the policy shift. With Phase II on hold, the immediate commercial demand for these specialized audits has evaporated, leaving trained assessors and consulting firms in a state of operational limbo.[2][5]

Despite the suspension of third-party audits, Pentagon officials have stressed that the underlying cybersecurity obligations remain firmly in place. Defense contractors are still legally bound by existing contract clauses to protect Controlled Unclassified Information and implement the required security controls. Phase I self-assessment requirements, including the continuous monitoring and submission of compliance scores to the Supplier Performance Risk System, continue to be actively enforced across all active defense contracts.[3][6]

This continued reliance on self-assessments carries significant legal risks for contractors who view the suspension as a license to abandon their cybersecurity programs. The Department of Justice has increasingly utilized the Civil Cyber-Fraud Initiative to prosecute companies that misrepresent their cybersecurity compliance or fail to adequately protect sensitive government data. Contractors that falsely attest to meeting the NIST standards face severe legal exposure and financial penalties under the False Claims Act.[3][6]

To chart a sustainable path forward, the Department of Defense has established a CMMC Reform Task Force. The group is tasked with conducting a 60-day top-to-bottom review of the program, gathering industry feedback, and proposing recommendations that reflect realistic, scalable security measures. The task force must solve the core tension of the CMMC initiative: how to rigorously secure a sprawling defense supply chain against sophisticated state-sponsored cyber threats without bankrupting the small businesses that manufacture critical components.[3][4]

Despite the suspension of third-party audits, defense contractors remain contractually obligated to protect Controlled Unclassified Information.

Until the task force delivers its findings, the future of defense cybersecurity regulation remains ambiguous. Procurement agencies have been instructed to amend current solicitations that demand third-party certification, reverting them to self-attested status. Whether CMMC Phase II is eventually restructured, scaled back, or permanently canceled will depend entirely on whether the Pentagon can engineer a framework that balances absolute data security with the economic realities of the industrial base.[4][5]

Terms to know

CMMC
Cybersecurity Maturity Model Certification, a tiered framework designed to ensure defense contractors meet specific cybersecurity controls.
CUI
Controlled Unclassified Information, sensitive government data that requires safeguarding but is not classified.
C3PAO
Certified Third-Party Assessor Organization, an independent entity authorized to conduct CMMC audits.
NIST SP 800-171
A set of 110 security controls established by the National Institute of Standards and Technology to protect CUI on non-federal systems.
DIB
Defense Industrial Base, the network of private-sector companies that provide products and services to the Department of Defense.

Questions readers ask

Does this mean defense contractors no longer need cybersecurity?

No. Phase I self-assessments and underlying NIST SP 800-171 requirements remain in full effect.

Why was Phase II suspended?

The Pentagon cited concerns over a projected $7 billion annual cost burden that threatened to push small and mid-sized businesses out of the defense supply chain.

What happens to companies that already paid for an audit?

They are currently at a competitive parity with those who did not, though their improved security posture remains a defense against cyber threats and False Claims Act liability.

When will a final decision be made?

A newly formed CMMC Reform Task Force is conducting a 60-day review to propose scalable alternatives.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Small & Medium Defense Contractors 40%Cybersecurity Assessors & Early Adopters 30%Pentagon Leadership 30%
  1. [1]Military.comPentagon Leadership

    Defense Department Suspends New Cybersecurity Rules After $7 Billion Cost Concerns

    Read on Military.com
  2. [2]Washington TechnologyCybersecurity Assessors & Early Adopters

    CMMC suspension caught industry off guard, but the reasons did not

    Read on Washington Technology
  3. [3]Latham & WatkinsCybersecurity Assessors & Early Adopters

    What Defense Contractors Should Know About DOD's Suspension of CMMC Phase 2

    Read on Latham & Watkins
  4. [4]Department of DefensePentagon Leadership

    Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements

    Read on Department of Defense
  5. [5]CBIASmall & Medium Defense Contractors

    Department of Defense Suspends Rollout of CMMC Phase 2

    Read on CBIA
  6. [6]BakerHostetlerCybersecurity Assessors & Early Adopters

    DoD Suspends CMMC Phase II and Launches 60-Day Review

    Read on BakerHostetler

Comments

Stay informed

Every angle. Every day.

Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.