Skip to main content
Defense ProcurementPolicy Explainer· 3 min read· in Defense & Security

The Evidence Pack: Why the Pentagon Halted CMMC Phase 2 Cybersecurity Requirements

The Pentagon has abruptly suspended its mandatory third-party cybersecurity audits for defense contractors, launching a 60-day task force to address a capacity crisis and billions in compliance costs.

By Marina Lopez

Small & Mid-Sized Contractors 30%Defense Leadership 25%Legal & Compliance Counsel 25%Cybersecurity Assessors 20%
Small & Mid-Sized Contractors
Relief from crushing compliance costs that threatened their ability to bid on contracts.
Defense Leadership
Prioritizing speed and reducing red tape to keep small businesses in the defense industrial base.
Legal & Compliance Counsel
Warning that self-attestation increases False Claims Act liability for executives.
Cybersecurity Assessors
Emphasizing that the underlying security requirements remain, even if the audit mechanism is paused.

Perspectives this story doesn't cover

  • Prime Contractors
  • Adversarial Nation-State Hackers

On July 13, 2026, the Pentagon abruptly suspended the looming Phase 2 rollout of its flagship Cybersecurity Maturity Model Certification (CMMC) program.[1][7]

The suspension halts a November 10, 2026, deadline that would have forced tens of thousands of defense contractors to pass costly, independent cybersecurity audits to bid on military contracts.[2][6]

The primary claim driving the suspension is a severe bottleneck in assessment capacity that made the deadline mathematically impossible.[3][7]

Department of War Chief Information Officer Kirsten A. Davies summarized the logistical reality, noting that "the math just simply doesn't math" for the industrial base to reach compliance in time.[7]

Currently, there are only about 100 authorized Certified Third-Party Assessment Organizations (C3PAOs) available to audit an estimated 100,000 companies in the defense supply chain.[3][7]

A severe shortage of authorized third-party assessors made the November 2026 deadline mathematically impossible.

Beyond logistics, the sheer financial toll on small and non-traditional defense contractors threatened to hollow out the military's supply chain.[1][2]

Data from the Small Business Administration (SBA) estimates that achieving CMMC third-party certification could cost a single small firm up to $593,800.

Data from the Small Business Administration (SBA) estimates that achieving CMMC third-party certification could cost a single small firm up to $593,800.

Across the industrial base, internal Pentagon estimates suggested the mandate would drain over $7 billion annually from small and mid-sized businesses.[3][7]

SBA data highlighted the crushing financial toll the third-party audits would take on small and mid-sized businesses.

Under Secretary of Defense for Acquisition and Sustainment Michael Duffey framed the pause as a necessary intervention to keep innovative companies in the defense ecosystem, aligning with Secretary Pete Hegseth's directive to prioritize speed to capability over bureaucratic hurdles.[1][7]

While the third-party audit mechanism is paused, the underlying cybersecurity obligations are not, creating a complex landscape for compliance officers.[4][5]

Contractors must still comply with the National Institute of Standards and Technology (NIST) SP 800-171 Revision 2 standards and existing Defense Federal Acquisition Regulation Supplement (DFARS) clauses.[4][6]

Phase 1 of the CMMC program, which requires companies to conduct and submit self-assessments, remains firmly in place across the defense industrial base.[1][4]

While third-party audits are paused, core cybersecurity self-assessments remain legally required.

Legal analysts warn that this dynamic actually elevates the immediate risk for contractors. Without a third-party assessor signing off, company executives bear the sole legal responsibility for their self-attestations.[3][6]

Misrepresenting cybersecurity compliance on these self-assessments leaves companies highly exposed to severe penalties under the False Claims Act, making accurate internal audits more critical than ever.[6]

To chart a new path, the Pentagon has established a CMMC Reform Task Force, which will conduct a top-to-bottom review of the program's structure and costs.[2][7]

Defense contractors must still secure their networks against cyber threats, even as the audit mechanism undergoes review.

The task force is soliciting industry feedback through a public Request for Information (RFI) open until August 14, 2026, with a final report expected by mid-September.[3][5]

The ultimate fate of CMMC remains highly uncertain. The task force could recommend modifying the audit timelines, shifting the scope of who requires certification, or replacing the framework entirely with a more scalable model.[3][7]

Why this matters

For tens of thousands of small and mid-sized defense contractors, this suspension removes an immediate $500,000-plus compliance hurdle. It keeps innovative companies in the military supply chain while the government recalibrates how it secures sensitive data without crushing small businesses.

How we got here

  1. October 2024

    The Department of Defense issues the final CMMC Program Rule.

  2. November 2025

    Phase 1 begins, requiring self-assessments for Level 1 and Level 2 contracts.

  3. July 13, 2026

    The Pentagon abruptly suspends the Phase 2 rollout and launches a 60-day review.

  4. August 14, 2026

    Deadline for defense contractors to submit RFI responses to the CMMC Reform Task Force.

  5. November 10, 2026

    Original deadline for Phase 2 third-party assessment requirements (now suspended).

Sources

Source coverage

7 outlets

4 viewpoints surfaced

Small & Mid-Sized Contractors 30%Defense Leadership 25%Legal & Compliance Counsel 25%Cybersecurity Assessors 20%
  1. [1]Department of WarDefense Leadership

    Department of War Suspends CMMC Phase II Requirements

    Read on Department of War
  2. [2]CBIASmall & Mid-Sized Contractors

    Pentagon Suspends CMMC Phase 2 Rollout

    Read on CBIA
  3. [3]Government Contracts LawLegal & Compliance Counsel

    DoD Suspends CMMC Phase 2: What You Need to Know

    Read on Government Contracts Law
  4. [4]IBSSCybersecurity Assessors

    What the CMMC Phase II Suspension Does and Does Not Change

    Read on IBSS
  5. [5]NtivaCybersecurity Assessors

    CMMC Phase 2 Suspended: What It Means for Defense Contractors

    Read on Ntiva
  6. [6]Morgan LewisLegal & Compliance Counsel

    DoW Suspends CMMC Phase II Requirements

    Read on Morgan Lewis
  7. [7]Clark HillLegal & Compliance Counsel

    DoW Suspends the Nov 10, 2026 CMMC Phase 2 Deadline

    Read on Clark Hill

Comments

Stay informed

Every angle. Every day.

Get Defense & Security stories with full source coverage and perspective breakdowns delivered to your inbox.