Full Breakdown
Pentagon Halts CMMC Phase II, Launches 60-Day Program Review
7/14/2026, 12:30:57 PM
Immediate Suspension of Phase II Requirements
On July 13 2026 the Department of Defense announced an immediate freeze on the Cybersecurity Maturity Model Certification (CMMC) Phase II mandate that had been slated to take effect on November 10 2026. The pause eliminates the requirement for third-party assessments on contracts involving controlled unclassified information. Contracts will continue to require Level 1 or Level 2 self-assessments and selected government-led reviews while a newly created CMMC Reform Task Force conducts a top-to-bottom review over the next 60 days.
Background and Evolution of CMMC
CMMC was first introduced in 2019 under the Trump administration to protect defense-contractor data from foreign adversaries. A 2021 revision—CMMC 2.0—reduced certification levels from five to three and emphasized self-assessment options. The program entered a phased rollout in November 2025 (Phase I) and was to progress to Phase II in November 2026, eventually adding Level 3 assessments in 2027. The rollout aligns with Secretary of War Pete Hegseth’s Acquisition Transformation System, which seeks to cut bureaucracy and accelerate capability delivery.
Quantitative Pressures on the Defense Industrial Base
- The Department estimated roughly 80,000 firms would eventually need third-party assessments; later statements referenced over 100,000 DIB businesses.
- The Cyber Accreditation Body reported ?104 authorized C3PAOs and ?988 certified assessors as of May 2026, far fewer than the volume of contractors.
- Small-business compliance cost analyses projected $593,800–$600,000 per certification for firms requiring third-party audits and $388,600 for self-assessment routes.
- The Small Business Administration warned the aggregate cost could approach $7 billion annually.
Official Statements and Responses
DoD Chief Information Officer Kirsten Davies framed the suspension as a corrective step to “prioritize speed to capability, lower barriers for small, medium, and non-traditional businesses, and replace prohibitive, third-party compliance models with scalable, realistic security measures.” Undersecretary for Acquisition and Sustainment Michael Duffey linked the decision to the department’s push to “speed weapons production” and to remove “paralyzing costs” while preserving innovation. The Pentagon’s public statement asserted that “CMMC compliance is forcing innovative companies out of the Defense Industrial Base.” SBA Administrator Kelly Loeffler praised the move, noting that the compliance burden was “an untenable barrier pushing [small firms] out of the Defense Industrial Base.”
Criticism and Opposition
Small-business advocates, including the SBA’s Office of Advocacy, warned since 2024 that the original rules would force many firms to exit the DIB. Industry lawyers warned that the third-party audit mandate could “squeeze out lower-tier suppliers” and complicate participation for international companies facing divergent data-privacy regimes. A March 2026 Government Accountability Office report highlighted the mismatch between the number of required assessments and the limited pool of qualified assessors, describing the situation as a “catastrophic scalability challenge.”
Conflicting Reports and Gaps
Sources differ on the exact number of firms affected: some cite 80,000, while others reference over 100,000. Cost estimates also vary, ranging from “hundreds of thousands of dollars” per firm to the more precise $593,800–$600,000 figure. No source provides a definitive timeline for when the task force’s recommendations will be implemented beyond the 60-day review period.
Verbatim Quotes
- “The current iteration of the Cybersecurity Maturity Model Certification (CMMC) program, while intended to enhance security, imposes significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses that are the engine of American innovation,” — Kirsten Davies, DoD CIO
- “CMMC compliance is forcing innovative companies out of the Defense Industrial Base,” — Pentagon statement
- “We’re not relaxing any standards by any means,” — Michael Duffey, Undersecretary of Defense for Acquisition and Sustainment
- “So the math just simply doesn’t math for small to medium-sized businesses to even get compliant by the transition date,” — Kirsten Davies, DoD CIO
What’s Next
The CMMC Reform Task Force will collect industry feedback through a public request for information and deliver a set of recommendations within 60 days. During the review, the Department will continue enforcing baseline cybersecurity through NIST SP 800-171 Rev 2 self-assessments and applicable DFARS clauses, ensuring that protection of federal data remains in force while the certification framework is re-engineered.
