Defense ProcurementPolicy ExplainerJul 18, 2026, 5:39 PM· 3 min read

The Evidence Pack: Why the Pentagon Halted CMMC Phase 2 Cybersecurity Requirements

The Pentagon has abruptly suspended its mandatory third-party cybersecurity audits for defense contractors, launching a 60-day task force to address a capacity crisis and billions in compliance costs.

By Factlen Editorial Team

Small & Mid-Sized Contractors 30%Defense Leadership 25%Legal & Compliance Counsel 25%Cybersecurity Assessors 20%
Small & Mid-Sized Contractors
Relief from crushing compliance costs that threatened their ability to bid on contracts.
Defense Leadership
Prioritizing speed and reducing red tape to keep small businesses in the defense industrial base.
Legal & Compliance Counsel
Warning that self-attestation increases False Claims Act liability for executives.
Cybersecurity Assessors
Emphasizing that the underlying security requirements remain, even if the audit mechanism is paused.

What's not represented

  • · Prime Contractors
  • · Adversarial Nation-State Hackers

Why this matters

For tens of thousands of small and mid-sized defense contractors, this suspension removes an immediate $500,000-plus compliance hurdle. It keeps innovative companies in the military supply chain while the government recalibrates how it secures sensitive data without crushing small businesses.

Key points

  • The Pentagon suspended the November 2026 deadline for CMMC Phase 2 third-party cybersecurity audits.
  • Officials cited a severe lack of authorized assessors and an estimated $7 billion annual cost to small businesses.
  • A newly formed CMMC Reform Task Force will conduct a 60-day review of the program.
  • Defense contractors must still comply with core NIST cybersecurity standards through self-assessments.
$593,800
Estimated CMMC certification cost per small firm
$7 billion
Projected annual cost to small and mid-sized businesses
100,000+
Defense contractors requiring assessments
~100
Authorized C3PAO assessors available

On July 13, 2026, the Pentagon abruptly suspended the looming Phase 2 rollout of its flagship Cybersecurity Maturity Model Certification (CMMC) program.[1][7]

The suspension halts a November 10, 2026, deadline that would have forced tens of thousands of defense contractors to pass costly, independent cybersecurity audits to bid on military contracts.[2][6]

The primary claim driving the suspension is a severe bottleneck in assessment capacity that made the deadline mathematically impossible.[3][7]

Department of War Chief Information Officer Kirsten A. Davies summarized the logistical reality, noting that "the math just simply doesn't math" for the industrial base to reach compliance in time.[7]

Currently, there are only about 100 authorized Certified Third-Party Assessment Organizations (C3PAOs) available to audit an estimated 100,000 companies in the defense supply chain.[3][7]

A severe shortage of authorized third-party assessors made the November 2026 deadline mathematically impossible.
A severe shortage of authorized third-party assessors made the November 2026 deadline mathematically impossible.

Beyond logistics, the sheer financial toll on small and non-traditional defense contractors threatened to hollow out the military's supply chain.[1][2]

Data from the Small Business Administration (SBA) estimates that achieving CMMC third-party certification could cost a single small firm up to $593,800.

Data from the Small Business Administration (SBA) estimates that achieving CMMC third-party certification could cost a single small firm up to $593,800.

Across the industrial base, internal Pentagon estimates suggested the mandate would drain over $7 billion annually from small and mid-sized businesses.[3][7]

SBA data highlighted the crushing financial toll the third-party audits would take on small and mid-sized businesses.
SBA data highlighted the crushing financial toll the third-party audits would take on small and mid-sized businesses.

Under Secretary of Defense for Acquisition and Sustainment Michael Duffey framed the pause as a necessary intervention to keep innovative companies in the defense ecosystem, aligning with Secretary Pete Hegseth's directive to prioritize speed to capability over bureaucratic hurdles.[1][7]

While the third-party audit mechanism is paused, the underlying cybersecurity obligations are not, creating a complex landscape for compliance officers.[4][5]

Contractors must still comply with the National Institute of Standards and Technology (NIST) SP 800-171 Revision 2 standards and existing Defense Federal Acquisition Regulation Supplement (DFARS) clauses.[4][6]

Phase 1 of the CMMC program, which requires companies to conduct and submit self-assessments, remains firmly in place across the defense industrial base.[1][4]

While third-party audits are paused, core cybersecurity self-assessments remain legally required.
While third-party audits are paused, core cybersecurity self-assessments remain legally required.

Legal analysts warn that this dynamic actually elevates the immediate risk for contractors. Without a third-party assessor signing off, company executives bear the sole legal responsibility for their self-attestations.[3][6]

Misrepresenting cybersecurity compliance on these self-assessments leaves companies highly exposed to severe penalties under the False Claims Act, making accurate internal audits more critical than ever.[6]

To chart a new path, the Pentagon has established a CMMC Reform Task Force, which will conduct a top-to-bottom review of the program's structure and costs.[2][7]

Defense contractors must still secure their networks against cyber threats, even as the audit mechanism undergoes review.
Defense contractors must still secure their networks against cyber threats, even as the audit mechanism undergoes review.

The task force is soliciting industry feedback through a public Request for Information (RFI) open until August 14, 2026, with a final report expected by mid-September.[3][5]

The ultimate fate of CMMC remains highly uncertain. The task force could recommend modifying the audit timelines, shifting the scope of who requires certification, or replacing the framework entirely with a more scalable model.[3][7]

How we got here

  1. October 2024

    The Department of Defense issues the final CMMC Program Rule.

  2. November 2025

    Phase 1 begins, requiring self-assessments for Level 1 and Level 2 contracts.

  3. July 13, 2026

    The Pentagon abruptly suspends the Phase 2 rollout and launches a 60-day review.

  4. August 14, 2026

    Deadline for defense contractors to submit RFI responses to the CMMC Reform Task Force.

  5. November 10, 2026

    Original deadline for Phase 2 third-party assessment requirements (now suspended).

Viewpoints in depth

Defense Leadership

Prioritizing speed and reducing red tape to keep small businesses in the defense industrial base.

Pentagon officials argue that the current iteration of CMMC was structurally incompatible with the need to rapidly expand the defense industrial base. By pausing the costly third-party audit requirements, leadership aims to lower the barrier to entry for non-traditional and small businesses, ensuring that cutting-edge commercial technology can reach the warfighter without being bogged down by bureaucratic compliance.

Small & Mid-Sized Contractors

Relief from crushing compliance costs that threatened their ability to bid on contracts.

For smaller defense suppliers, the suspension is a massive financial reprieve. Industry advocates point to SBA data showing that compliance costs approaching $600,000 per firm would have forced many specialized manufacturers and tech startups to abandon government contracting entirely. They view the pause as a necessary correction to a policy that favored massive prime contractors with deep pockets.

Cybersecurity Assessors

Emphasizing that the underlying security requirements remain, even if the audit mechanism is paused.

C3PAOs and IT compliance firms caution against viewing the suspension as a free pass. They stress that the core NIST SP 800-171 standards are still actively enforced through self-assessments. These organizations warn that companies pausing their cybersecurity investments now will find themselves highly vulnerable to both actual cyber threats and future regulatory shifts once the 60-day review concludes.

Legal & Compliance Counsel

Warning that self-attestation increases False Claims Act liability for executives.

Government contract lawyers highlight a hidden danger in the suspension: the shift back to self-attestation. Without the shield of a third-party certification, executives who sign off on their company's cybersecurity posture bear full legal responsibility. Legal experts warn that the Department of Justice is increasingly using the False Claims Act to prosecute defense contractors who misrepresent their cyber readiness, making accurate self-reporting a high-stakes obligation.

What we don't know

  • Whether the CMMC program will be permanently canceled or simply modified.
  • How the Pentagon plans to verify cybersecurity compliance without third-party assessors.
  • If the November 2026 deadline will be pushed back to a specific new date or abandoned entirely.

Key terms

CMMC (Cybersecurity Maturity Model Certification)
A tiered framework requiring defense contractors to prove they meet specific cybersecurity controls to protect sensitive government data.
C3PAO
Certified Third-Party Assessment Organizations authorized to conduct independent cybersecurity audits for defense contractors.
NIST SP 800-171
A set of cybersecurity standards developed by the National Institute of Standards and Technology that defense contractors are legally required to follow.
False Claims Act
A federal law that imposes severe liability on persons and companies who defraud governmental programs, applicable if a contractor misrepresents their cybersecurity compliance.

Frequently asked

Does this suspension mean defense contractors can stop worrying about cybersecurity?

No. The suspension only pauses the third-party audit requirement. Contractors are still legally obligated to maintain cybersecurity standards and conduct self-assessments.

What happens to the November 2026 deadline?

The November 10, 2026, deadline for Phase 2 has been completely halted. All active solicitations and contracts are being amended to remove the third-party assessment requirement.

Will the CMMC program be canceled entirely?

It is currently under a 60-day review. While officials have not ruled out cancellation, it is more likely the program will be modified to reduce costs and administrative burdens.

Sources

Source coverage

7 outlets

4 viewpoints surfaced

Small & Mid-Sized Contractors 30%Defense Leadership 25%Legal & Compliance Counsel 25%Cybersecurity Assessors 20%
  1. [1]Department of WarDefense Leadership

    Department of War Suspends CMMC Phase II Requirements

    Read on Department of War
  2. [2]CBIASmall & Mid-Sized Contractors

    Pentagon Suspends CMMC Phase 2 Rollout

    Read on CBIA
  3. [3]Government Contracts LawLegal & Compliance Counsel

    DoD Suspends CMMC Phase 2: What You Need to Know

    Read on Government Contracts Law
  4. [4]IBSSCybersecurity Assessors

    What the CMMC Phase II Suspension Does and Does Not Change

    Read on IBSS
  5. [5]NtivaCybersecurity Assessors

    CMMC Phase 2 Suspended: What It Means for Defense Contractors

    Read on Ntiva
  6. [6]Morgan LewisLegal & Compliance Counsel

    DoW Suspends CMMC Phase II Requirements

    Read on Morgan Lewis
  7. [7]Clark HillLegal & Compliance Counsel

    DoW Suspends the Nov 10, 2026 CMMC Phase 2 Deadline

    Read on Clark Hill
Stay informed

Every angle. Every day.

Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.