The Evidence Pack: Why the Pentagon Halted CMMC Phase 2 Cybersecurity Requirements
The Pentagon has abruptly suspended its mandatory third-party cybersecurity audits for defense contractors, launching a 60-day task force to address a capacity crisis and billions in compliance costs.
By Marina Lopez
- Small & Mid-Sized Contractors
- Relief from crushing compliance costs that threatened their ability to bid on contracts.
- Defense Leadership
- Prioritizing speed and reducing red tape to keep small businesses in the defense industrial base.
- Legal & Compliance Counsel
- Warning that self-attestation increases False Claims Act liability for executives.
- Cybersecurity Assessors
- Emphasizing that the underlying security requirements remain, even if the audit mechanism is paused.
Perspectives this story doesn't cover
- Prime Contractors
- Adversarial Nation-State Hackers
On July 13, 2026, the Pentagon abruptly suspended the looming Phase 2 rollout of its flagship Cybersecurity Maturity Model Certification (CMMC) program.[1][7]
The suspension halts a November 10, 2026, deadline that would have forced tens of thousands of defense contractors to pass costly, independent cybersecurity audits to bid on military contracts.[2][6]
The primary claim driving the suspension is a severe bottleneck in assessment capacity that made the deadline mathematically impossible.[3][7]
Department of War Chief Information Officer Kirsten A. Davies summarized the logistical reality, noting that "the math just simply doesn't math" for the industrial base to reach compliance in time.[7]
Currently, there are only about 100 authorized Certified Third-Party Assessment Organizations (C3PAOs) available to audit an estimated 100,000 companies in the defense supply chain.[3][7]
Beyond logistics, the sheer financial toll on small and non-traditional defense contractors threatened to hollow out the military's supply chain.[1][2]
Data from the Small Business Administration (SBA) estimates that achieving CMMC third-party certification could cost a single small firm up to $593,800.
Data from the Small Business Administration (SBA) estimates that achieving CMMC third-party certification could cost a single small firm up to $593,800.
Across the industrial base, internal Pentagon estimates suggested the mandate would drain over $7 billion annually from small and mid-sized businesses.[3][7]
Under Secretary of Defense for Acquisition and Sustainment Michael Duffey framed the pause as a necessary intervention to keep innovative companies in the defense ecosystem, aligning with Secretary Pete Hegseth's directive to prioritize speed to capability over bureaucratic hurdles.[1][7]
While the third-party audit mechanism is paused, the underlying cybersecurity obligations are not, creating a complex landscape for compliance officers.[4][5]
Contractors must still comply with the National Institute of Standards and Technology (NIST) SP 800-171 Revision 2 standards and existing Defense Federal Acquisition Regulation Supplement (DFARS) clauses.[4][6]
Phase 1 of the CMMC program, which requires companies to conduct and submit self-assessments, remains firmly in place across the defense industrial base.[1][4]
Legal analysts warn that this dynamic actually elevates the immediate risk for contractors. Without a third-party assessor signing off, company executives bear the sole legal responsibility for their self-attestations.[3][6]
Misrepresenting cybersecurity compliance on these self-assessments leaves companies highly exposed to severe penalties under the False Claims Act, making accurate internal audits more critical than ever.[6]
To chart a new path, the Pentagon has established a CMMC Reform Task Force, which will conduct a top-to-bottom review of the program's structure and costs.[2][7]
Why this matters
For tens of thousands of small and mid-sized defense contractors, this suspension removes an immediate $500,000-plus compliance hurdle. It keeps innovative companies in the military supply chain while the government recalibrates how it secures sensitive data without crushing small businesses.
How we got here
October 2024
The Department of Defense issues the final CMMC Program Rule.
November 2025
Phase 1 begins, requiring self-assessments for Level 1 and Level 2 contracts.
July 13, 2026
The Pentagon abruptly suspends the Phase 2 rollout and launches a 60-day review.
August 14, 2026
Deadline for defense contractors to submit RFI responses to the CMMC Reform Task Force.
November 10, 2026
Original deadline for Phase 2 third-party assessment requirements (now suspended).
Sources
[1]Department of WarDefense LeadershipDepartment of War Suspends CMMC Phase II Requirements
Read on Department of War →
[2]CBIASmall & Mid-Sized ContractorsPentagon Suspends CMMC Phase 2 Rollout
Read on CBIA →
[3]Government Contracts LawLegal & Compliance CounselDoD Suspends CMMC Phase 2: What You Need to Know
Read on Government Contracts Law →
[4]IBSSCybersecurity AssessorsWhat the CMMC Phase II Suspension Does and Does Not Change
Read on IBSS →
[5]NtivaCybersecurity AssessorsCMMC Phase 2 Suspended: What It Means for Defense Contractors
Read on Ntiva →
[6]Morgan LewisLegal & Compliance CounselDoW Suspends CMMC Phase II Requirements
Read on Morgan Lewis →
[7]Clark HillLegal & Compliance CounselDoW Suspends the Nov 10, 2026 CMMC Phase 2 Deadline
Read on Clark Hill →
Comments
More in Defense & Security
See all →Information Security
U.S. Information Classification: The Statutory Boundaries Between Top Secret, Secret, and Confidential
8 sources
Defense Procurement
Title 10 U.S.C. § 2500: The Statutory Definition and Economic Measurement of the U.S. Defense Industrial Base
4 sources
Strait of Hormuz
Iran to Announce 'Restricted Zone' Near Strait of Hormuz Following U.S. Tanker Strikes
6 sources
Counterinsurgency Doctrine
Evaluating the Three Pillars of Counterinsurgency: How Security, Governance, and Economics Intersect
6 sources
Every angle. Every day.
Get Defense & Security stories with full source coverage and perspective breakdowns delivered to your inbox.




