The Evidence Pack: Why the Pentagon Halted CMMC Phase 2 Cybersecurity Requirements
The Pentagon has abruptly suspended its mandatory third-party cybersecurity audits for defense contractors, launching a 60-day task force to address a capacity crisis and billions in compliance costs.
By Factlen Editorial Team
- Small & Mid-Sized Contractors
- Relief from crushing compliance costs that threatened their ability to bid on contracts.
- Defense Leadership
- Prioritizing speed and reducing red tape to keep small businesses in the defense industrial base.
- Legal & Compliance Counsel
- Warning that self-attestation increases False Claims Act liability for executives.
- Cybersecurity Assessors
- Emphasizing that the underlying security requirements remain, even if the audit mechanism is paused.
What's not represented
- · Prime Contractors
- · Adversarial Nation-State Hackers
Why this matters
For tens of thousands of small and mid-sized defense contractors, this suspension removes an immediate $500,000-plus compliance hurdle. It keeps innovative companies in the military supply chain while the government recalibrates how it secures sensitive data without crushing small businesses.
Key points
- The Pentagon suspended the November 2026 deadline for CMMC Phase 2 third-party cybersecurity audits.
- Officials cited a severe lack of authorized assessors and an estimated $7 billion annual cost to small businesses.
- A newly formed CMMC Reform Task Force will conduct a 60-day review of the program.
- Defense contractors must still comply with core NIST cybersecurity standards through self-assessments.
On July 13, 2026, the Pentagon abruptly suspended the looming Phase 2 rollout of its flagship Cybersecurity Maturity Model Certification (CMMC) program.[1][7]
The suspension halts a November 10, 2026, deadline that would have forced tens of thousands of defense contractors to pass costly, independent cybersecurity audits to bid on military contracts.[2][6]
The primary claim driving the suspension is a severe bottleneck in assessment capacity that made the deadline mathematically impossible.[3][7]
Department of War Chief Information Officer Kirsten A. Davies summarized the logistical reality, noting that "the math just simply doesn't math" for the industrial base to reach compliance in time.[7]
Currently, there are only about 100 authorized Certified Third-Party Assessment Organizations (C3PAOs) available to audit an estimated 100,000 companies in the defense supply chain.[3][7]

Beyond logistics, the sheer financial toll on small and non-traditional defense contractors threatened to hollow out the military's supply chain.[1][2]
Data from the Small Business Administration (SBA) estimates that achieving CMMC third-party certification could cost a single small firm up to $593,800.
Data from the Small Business Administration (SBA) estimates that achieving CMMC third-party certification could cost a single small firm up to $593,800.
Across the industrial base, internal Pentagon estimates suggested the mandate would drain over $7 billion annually from small and mid-sized businesses.[3][7]

Under Secretary of Defense for Acquisition and Sustainment Michael Duffey framed the pause as a necessary intervention to keep innovative companies in the defense ecosystem, aligning with Secretary Pete Hegseth's directive to prioritize speed to capability over bureaucratic hurdles.[1][7]
While the third-party audit mechanism is paused, the underlying cybersecurity obligations are not, creating a complex landscape for compliance officers.[4][5]
Contractors must still comply with the National Institute of Standards and Technology (NIST) SP 800-171 Revision 2 standards and existing Defense Federal Acquisition Regulation Supplement (DFARS) clauses.[4][6]
Phase 1 of the CMMC program, which requires companies to conduct and submit self-assessments, remains firmly in place across the defense industrial base.[1][4]

Legal analysts warn that this dynamic actually elevates the immediate risk for contractors. Without a third-party assessor signing off, company executives bear the sole legal responsibility for their self-attestations.[3][6]
Misrepresenting cybersecurity compliance on these self-assessments leaves companies highly exposed to severe penalties under the False Claims Act, making accurate internal audits more critical than ever.[6]
To chart a new path, the Pentagon has established a CMMC Reform Task Force, which will conduct a top-to-bottom review of the program's structure and costs.[2][7]

How we got here
October 2024
The Department of Defense issues the final CMMC Program Rule.
November 2025
Phase 1 begins, requiring self-assessments for Level 1 and Level 2 contracts.
July 13, 2026
The Pentagon abruptly suspends the Phase 2 rollout and launches a 60-day review.
August 14, 2026
Deadline for defense contractors to submit RFI responses to the CMMC Reform Task Force.
November 10, 2026
Original deadline for Phase 2 third-party assessment requirements (now suspended).
Viewpoints in depth
Defense Leadership
Prioritizing speed and reducing red tape to keep small businesses in the defense industrial base.
Pentagon officials argue that the current iteration of CMMC was structurally incompatible with the need to rapidly expand the defense industrial base. By pausing the costly third-party audit requirements, leadership aims to lower the barrier to entry for non-traditional and small businesses, ensuring that cutting-edge commercial technology can reach the warfighter without being bogged down by bureaucratic compliance.
Small & Mid-Sized Contractors
Relief from crushing compliance costs that threatened their ability to bid on contracts.
For smaller defense suppliers, the suspension is a massive financial reprieve. Industry advocates point to SBA data showing that compliance costs approaching $600,000 per firm would have forced many specialized manufacturers and tech startups to abandon government contracting entirely. They view the pause as a necessary correction to a policy that favored massive prime contractors with deep pockets.
Cybersecurity Assessors
Emphasizing that the underlying security requirements remain, even if the audit mechanism is paused.
C3PAOs and IT compliance firms caution against viewing the suspension as a free pass. They stress that the core NIST SP 800-171 standards are still actively enforced through self-assessments. These organizations warn that companies pausing their cybersecurity investments now will find themselves highly vulnerable to both actual cyber threats and future regulatory shifts once the 60-day review concludes.
Legal & Compliance Counsel
Warning that self-attestation increases False Claims Act liability for executives.
Government contract lawyers highlight a hidden danger in the suspension: the shift back to self-attestation. Without the shield of a third-party certification, executives who sign off on their company's cybersecurity posture bear full legal responsibility. Legal experts warn that the Department of Justice is increasingly using the False Claims Act to prosecute defense contractors who misrepresent their cyber readiness, making accurate self-reporting a high-stakes obligation.
What we don't know
- Whether the CMMC program will be permanently canceled or simply modified.
- How the Pentagon plans to verify cybersecurity compliance without third-party assessors.
- If the November 2026 deadline will be pushed back to a specific new date or abandoned entirely.
Key terms
- CMMC (Cybersecurity Maturity Model Certification)
- A tiered framework requiring defense contractors to prove they meet specific cybersecurity controls to protect sensitive government data.
- C3PAO
- Certified Third-Party Assessment Organizations authorized to conduct independent cybersecurity audits for defense contractors.
- NIST SP 800-171
- A set of cybersecurity standards developed by the National Institute of Standards and Technology that defense contractors are legally required to follow.
- False Claims Act
- A federal law that imposes severe liability on persons and companies who defraud governmental programs, applicable if a contractor misrepresents their cybersecurity compliance.
Frequently asked
Does this suspension mean defense contractors can stop worrying about cybersecurity?
No. The suspension only pauses the third-party audit requirement. Contractors are still legally obligated to maintain cybersecurity standards and conduct self-assessments.
What happens to the November 2026 deadline?
The November 10, 2026, deadline for Phase 2 has been completely halted. All active solicitations and contracts are being amended to remove the third-party assessment requirement.
Will the CMMC program be canceled entirely?
It is currently under a 60-day review. While officials have not ruled out cancellation, it is more likely the program will be modified to reduce costs and administrative burdens.
Sources
[1]Department of WarDefense Leadership
Department of War Suspends CMMC Phase II Requirements
Read on Department of War →[2]CBIASmall & Mid-Sized Contractors
Pentagon Suspends CMMC Phase 2 Rollout
Read on CBIA →[3]Government Contracts LawLegal & Compliance Counsel
DoD Suspends CMMC Phase 2: What You Need to Know
Read on Government Contracts Law →[4]IBSSCybersecurity Assessors
What the CMMC Phase II Suspension Does and Does Not Change
Read on IBSS →[5]NtivaCybersecurity Assessors
CMMC Phase 2 Suspended: What It Means for Defense Contractors
Read on Ntiva →[6]Morgan LewisLegal & Compliance Counsel
DoW Suspends CMMC Phase II Requirements
Read on Morgan Lewis →[7]Clark HillLegal & Compliance Counsel
DoW Suspends the Nov 10, 2026 CMMC Phase 2 Deadline
Read on Clark Hill →
Every angle. Every day.
Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.







