Pentagon Suspends CMMC Phase 2, Launches 60-Day Reform Review
The U.S. Defense Department has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, originally set for November 2026, and launched a 60-day reform review. The suspension follows complaints that third-party certification costs—up to $593,800 for small firms—were driving contractors out of the defense industrial base. Phase 1 self-assessments remain in effect. A CMMC Reform Task Force will seek industry feedback to align the program with acquisition reform priorities emphasizing speed and reduced barriers for small businesses.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Source updates only; analysis pending
Analysis pending
Cross-source coverage
Wire timeline
US Department of War Suspends CMMC Phase II Over Small Contractor Concerns
The US Department of War (DoW) has suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC), originally scheduled for November 2026, due to concerns about prohibitive costs for small defense contractors. An assessment by the Small Business Administration (SBA) found that third-party verification could cost small firms up to $593,800, with self-assessment still costing around $388,600, unsustainable for over 120,000 small businesses. DoW CIO Kirsten Davies warned the original timeline could reduce competition and strain supply chains. A 60-day task force has been formed to review the program, incorporating industry feedback. Phase I requirements remain in effect, and Davies emphasized cybersecurity remains a non-negotiable priority.
US Department of War Suspends CMMC Phase II for Defense Contractors
The US Department of War (DoW) has suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC), originally set for November 2026, due to concerns over prohibitive costs for small defense contractors. An assessment by the Small Business Administration (SBA) found that third-party verification could cost small firms up to $593,800, with self-assessment still around $388,600, unsustainable for over 120,000 small businesses. DoW CIO Kirsten Davies warned that proceeding could exclude small suppliers, reduce competition, and strain supply chains critical to defense readiness. A task force will review the entire CMMC scheme over 60 days, incorporating industry feedback. Existing Phase I requirements remain in effect, and Davies emphasized that robust cybersecurity remains a non-negotiable priority.
US Department of War Suspends CMMC Phase II for Defense Contractors
The US Department of War (DoW) has suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC), originally set for November 2026, due to concerns over prohibitive costs for small defense contractors. An assessment by the Small Business Administration (SBA) found that third-party verification could cost small firms up to $593,800, with only about 100 authorized assessors available for over 120,000 small businesses. DoW CIO Kirsten Davies warned the original timeline could exclude many suppliers, reducing competition and harming defense readiness. A task force will review the entire CMMC scheme over 60 days, incorporating industry feedback. Phase I requirements remain in effect, and Davies emphasized that robust cybersecurity remains a non-negotiable priority.
Show 3 older updatesHide older updates
Pentagon Halts Phase 2 of Cybersecurity Certification Program, Launches 60-Day Reform Review
The U.S. Defense Department has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, which was set to require third-party certifications starting November 10, 2026. Phase 1 self-assessments will remain in place. The Pentagon is launching a 60-day review to align CMMC with Secretary Pete Hegseth's acquisition reform priorities, which emphasize speed and reducing barriers for small and medium businesses. The decision follows complaints about rising compliance costs and bureaucratic burdens, with the Small Business Administration reporting that some companies left the defense industrial base due to CMMC requirements. All future phases (3 and 4) are also suspended. A CMMC Reform Task Force will conduct the review and seek industry feedback via a request for information due August 14, 2026. The department will rely on self-assessments and select government-led assessments in the interim.
Pentagon Halts Phase 2 of Cybersecurity Certification Program, Launches 60-Day Reform Review
The U.S. Defense Department has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, which would have required third-party certifications starting November 10, 2026. Phase 1 self-assessments will remain in place. The Pentagon is launching a 60-day reform review to align CMMC with Secretary Pete Hegseth's acquisition priorities emphasizing speed and reduced barriers for small and medium businesses. The decision follows complaints that CMMC increased compliance costs and bureaucratic burdens, with the Small Business Administration reporting that some companies left the defense industrial base, delaying critical capabilities. DOD Chief Information Officer Kirsten Davies announced the suspension and the formation of a CMMC Reform Task Force. The department has posted a Request for Information seeking industry input on cost drivers, administrative burdens, and how commercial cybersecurity tools could be recognized. Responses are due by August 14, 2026. Phases 3 and 4 are also suspended pending the review.
Pentagon Halts Phase 2 of Cybersecurity Certification Program, Launches 60-Day Reform Review
The U.S. Defense Department has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, which was set to require third-party certifications starting November 10, 2026. Phase 1 self-assessments will remain in place. The Pentagon is launching a 60-day review to align the program with Defense Secretary Pete Hegseth's acquisition reform priorities, which emphasize speed and reducing barriers for small and medium businesses. The decision follows complaints about rising compliance costs and bureaucratic burdens, with the Small Business Administration reporting that CMMC requirements had driven some companies out of the defense industrial base, delaying critical deliveries. DOD Chief Information Officer Kirsten Davies announced the suspension and the formation of a CMMC Reform Task Force. The department has also issued a request for information seeking industry feedback on cost drivers, administrative burdens, and how commercial cybersecurity tools could be recognized in a revised framework. Responses are due by August 14, 2026. All future phases of CMMC, including Phase 3 and Phase 4, are also suspended pending the review.