Pentagon HALTS Costly Cyber Crackdown

The Pentagon aerial view with surrounding highways and parking lots
Photo: Austin Nooe / Shutterstock

The Pentagon’s decision to suspend CMMC Phase II is not a retreat from cybersecurity, but a deliberate rebalancing of how much compliance burden the defense supply chain can absorb before security rules themselves start hollowing out the industrial base.

Key Points

  • The Defense Department has suspended CMMC Phase II, halting mandatory third‑party cyber audits that were set to start this November, after small‑business cost estimates topped $7 billion per year.
  • Phase I self‑assessment requirements and the underlying NIST SP 800‑171 / DFARS cybersecurity obligations remain fully in force; contractors’ legal duties have not been rolled back.
  • Senior officials explicitly tied the pause to “prohibitive compliance costs and bureaucratic burdens” on small and non‑traditional suppliers and launched a 60‑day CMMC Reform Task Force to redesign the regime.
  • The core policy challenge is long‑standing: how to demand credible cyber hygiene in the defense industrial base without creating a pay‑to‑play audit system that drives innovative smaller vendors out of military work.

What Was Suspended: CMMC Phase II, Not Cybersecurity Itself

The decision centers on Phase II of the Cybersecurity Maturity Model Certification program, the point at which defense contractors would have to move from self‑attested compliance to formal third‑party audits before winning new work. Under the rule set to take effect November 10, 2026, most Level 2 contracts involving controlled unclassified information (CUI) would have required certification by a C3PAO—an accredited third‑party assessment organization—with Level 3 contracts subject to government‑run DIBCAC assessments. Program offices were already starting to put these audit requirements into solicitations as part of a phased rollout.

The Pentagon has now suspended that Phase II transition “effective immediately,” directing contracting officers to remove upcoming third‑party audit clauses from pending and future solicitations. It has also paused other scheduled CMMC milestones tied to audit requirements, pending recommendations from a new CMMC Reform Task Force. In plain terms, the government has taken its foot off the certification accelerator; it has not removed the engine of cybersecurity obligations that pre‑dated CMMC and remain embedded in DFARS and NIST standards.

Why Phase II Collided With the Economics of the Defense Supply Chain

To understand why Phase II was paused, it helps to look at the numbers. CMMC was built atop existing requirements that defense contractors protecting CUI implement 110 security controls from NIST SP 800‑171. Those controls were already mandatory under DFARS 252.204‑7012 and related clauses; what Phase II added was the requirement to prove adherence through recurring external audits.

The Department’s own cost projections estimated that a Level 2 third‑party certification would cost on the order of $105,000–$118,000 for small entities, including the triennial assessment itself and associated preparation. Independent analyses and consulting‑firm data suggested total first‑year spending for a typical small‑to‑mid‑size contractor pursuing Level 2 compliance could range from roughly $70,000 up to $250,000 or more, once remediation, tooling, and ongoing maintenance were included. Some small suppliers reported actual outlays in the hundreds of thousands of dollars when overhauling legacy systems to meet the standard.

Those figures scale quickly when multiplied across the lower tiers of the industrial base. A Small Business Administration survey cited by reporting estimated that CMMC implementation, as then designed, would impose more than $7 billion per year in compliance costs on small and medium‑sized businesses. For prime contractors with deep pockets, these are manageable investments; for machine shops, niche software firms, and specialized manufacturers operating on thin margins, they become existential. The Pentagon, in its own statement, acknowledged that “CMMC compliance is forcing innovative companies out of the Defense Industrial Base,” framing the pause as an effort to keep competition and innovation alive in the supply chain.

This is not a new pattern. Federal cybersecurity initiatives routinely start with ambitious visions of audited compliance, then encounter friction at the point where thousands of small entities must translate guidance into capital expenditures. CMMC Phase II simply reached that collision point more visibly, because it married a dense technical control set to an expensive certification apparatus in a short time frame.

Bureaucratic Bottlenecks: Too Few Auditors, Too Much Process

Cost alone did not drive the pause; capacity and bureaucracy were equally central. CMMC Phase II depended on a market of accredited C3PAOs and certified assessors to perform audits for an estimated 80,000–100,000 defense contractors handling CUI. While the ecosystem has grown, it remained limited—on the order of a hundred authorized C3PAOs and a larger but still finite pool of certified assessors—creating a simple arithmetic problem: far more entities needing audits than professionals available to conduct them in the required time frame.

The Pentagon’s Chief Information Officer, Kirsten Davies, was blunt in public remarks: the current CMMC construct imposed “significant and often prohibitive burdens on the defense industrial base, particularly small and non‑traditional businesses,” and clashed with Secretary of War Pete Hegseth’s acquisition transformation initiative focused on “speed to capability” and “lowering barriers” for new entrants. In practice, the program risked tying up contracting offices, vendors, and auditors alike in a thicket of scheduling, evidence gathering, and artifact management before a single widget or line of code reached a warfighter.

Industry feedback mirrored these concerns. Smaller suppliers complained not only of audit fees, but of consultant retainers, secure cloud migrations, staff training, and the administrative time required to assemble documentation and live through multi‑day assessments. International firms juggling divergent data‑protection regimes raised the specter of conflicting standards and duplicated effort. Lawyers warned that a rigid audit gate could unintentionally narrow the pool of eligible bidders, with downstream effects on cost and innovation.

When a compliance regime becomes a bottleneck in the acquisition pipeline, it starts to work against its parent strategy. That is the tension the Pentagon finally acted on.

What Remains in Force: Self‑Assessments, NIST 800‑171, and DFARS

Suspending Phase II does not mean contractors can relax their cyber posture. The Pentagon has emphasized in multiple channels that Phase I remains in place: Level 1 and Level 2 self‑assessments, scored against NIST SP 800‑171 controls, must continue, and the department will enforce compliance “through self‑assessments and select government‑led assessments” during the review period. Suppliers handling CUI are still expected to implement all 110 NIST 800‑171 requirements, maintain accurate System Security Plans, and report scores to the Supplier Performance Risk System as their contracts require.

DFARS clauses on incident reporting, data handling, and cyber requirements have not been rescinded. Nor has the broader enforcement environment softened; the Department of Justice’s civil cyber fraud initiative continues to use the False Claims Act to pursue companies that attest to compliance they do not in fact maintain. The pivot is away from universal pre‑award audits, not away from accountability.

For many contractors, this reshapes the risk profile rather than erasing it. In an audit‑centric world, failure to achieve certification could block access to new work. In the current pause, the greater risk lies in misrepresenting self‑assessment results or failing to implement required controls, then facing scrutiny after a breach or whistleblower complaint. The logical response is to keep building substantive security programs while welcoming relief from near‑term audit queues.

The 60‑Day Reform Window: What Might Replace Phase II

The Pentagon has given itself 60 days to rethink CMMC’s verification model, tasking a CMMC Reform Task Force to produce recommendations that align with warfighting priorities and industrial‑base realities. Officials have already sketched the direction of travel: away from “prohibitive third‑party compliance models” and toward “scalable, realistic security measures” that emphasize tangible risk reduction rather than paperwork.

Several ideas are circulating in expert and industry commentary. One is a heavier reliance on self‑attestation supplemented by targeted, risk‑based audits—focusing government assessment resources on higher‑risk programs or vendors rather than mandating certification for all. Another is increased use of commercial secure‑by‑design platforms and managed security services, with clear shared‑responsibility matrices so that contractors can inherit robust controls from cloud and MSP providers while still being held to account for their portion of the stack.

A third avenue is harmonization: aligning CMMC’s underlying control set with evolving NIST standards and proposed government‑wide rules for CUI protection, to avoid forcing dual‑use contractors into divergent regimes depending on whether the customer is a defense or civilian agency. Whatever the exact mix, the department’s own rhetoric suggests the next iteration will privilege outcomes—how well CUI is protected and how resilient systems are to attack—over ritualized certification cycles.

Implications for Small and Mid‑Sized Contractors

For smaller companies, the immediate implication is relief from an imminent financial shock. A regime projected to cost them collectively more than $7 billion a year is on hold. Many had already begun budgeting six‑figure sums for audits and remediation; some had reportedly exited defense work altogether rather than incur those costs. The pause removes, at least temporarily, the requirement to pay for third‑party certification just to stay eligible for bids.

At the same time, it removes a degree of clarity. Businesses that spent the past two years preparing for Phase II now face uncertainty about what verification mechanism will ultimately apply. Investments in NIST 800‑171‑aligned controls and documentation will not be wasted—those obligations persist—but the specific audit pathways and timelines may change. That is frustrating for well‑prepared firms that saw certification as a competitive differentiator.

The more enduring lesson for small and mid‑sized contractors is that cybersecurity in the defense ecosystem is a moving target, but the baseline keeps rising. Federal policy swings can alter how compliance is checked; they do not reset the expectation that any entity handling sensitive government data will meet a recognized standard of care. Companies that treat the Phase II pause as breathing room to improve their security posture will be better positioned regardless of how the task force redraws the lines.

Where This Fits in the Longer Arc of Defense Cyber Policy

The CMMC Phase II suspension sits squarely within a broader trend of recalibrating cyber mandates across the federal landscape. Executive Order 14306, issued by President Trump in 2025, had already scaled back certain Biden‑era requirements for contractor attestations and digital identity measures, while leaving the DFARS mandate for 110 NIST controls intact. That order reflected similar concerns: that aggressively layered compliance rules could entangle contractors in bureaucracy without materially advancing security.

Seen in that light, the Pentagon’s move is less a sudden reversal than a continuation of efforts to distinguish necessary technical controls from optional process overhead. The enduring policy objective is straightforward: sensitive government data must be protected to a high, demonstrable standard. The live debate is over mechanisms, cadence, and who bears which slice of the cost—government, primes, or the smallest suppliers with the least room to maneuver.

For defense leaders, acquisition officials, and contractors alike, the CMMC Phase II pause is an opportunity to rebuild that mechanism with clearer eyes. If the reform effort succeeds, the next iteration of CMMC will retain the discipline of structured requirements and credible verification, but in a form that does not treat every vendor alike nor assume that an audit is the only way to tell who is secure. The stakes are not just accounting lines; they are whether the United States can maintain a diverse, innovative industrial base while still taking the cybersecurity of its supply chain as seriously as the weapons that supply chain produces.

Sources:

military.com, business.defense.gov, crowell.com, dentons.com, youtube.com, linkedin.com, secureworld.io, dowcio.war.gov, petronellatech.com, cmmc.com, thedefensecompliancereport.com, strikegraph.com, getroz.com, dodcio.defense.gov, kiteworks.com