Wire flash
PoliticsPentagon suspends Phase 2 of CMMC cybersecurity certification, launches 60-day reform review
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
The U.S. Defense Department has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, which would have required third-party certifications starting November 10, 2026. Phase 1 self-assessments will remain in place. The Pentagon is launching a 60-day reform review to align CMMC with Secretary Pete Hegseth's acquisition priorities emphasizing speed and reduced barriers for small and medium businesses. The decision follows complaints that CMMC increased compliance costs and bureaucratic burdens, with the Small Business Administration reporting that some companies left the defense industrial base, delaying critical capabilities. DOD Chief Information Officer Kirsten Davies announced the suspension and the formation of a CMMC Reform Task Force. The department has posted a Request for Information seeking industry input on cost drivers, administrative burdens, and how commercial cybersecurity tools could be recognized. Responses are due by August 14, 2026. Phases 3 and 4 are also suspended pending the review.
Source report
The Defense Department has effectively ended the Cybersecurity Maturity Model Certification (CMMC) program by suspending its second-phase requirements.
The Pentagon will maintain Phase 1, which requires self-assessments for how companies protect controlled unclassified information within their systems. However, the department announced Monday that it is suspending Phase 2, originally scheduled to begin on November 10, which would have required third-party certifications.
Review and Reform
DOD is launching a review of CMMC to ensure alignment with Defense Secretary Pete Hegseth’s acquisition initiatives, which prioritize speed and lowering barriers for new entrants. The Acquisition Transformation System directives also aim to replace bureaucratic compliance with what DOD describes as "scalable, resilient cybersecurity measures."
The CMMC program originated during the first Trump administration and was revised and streamlined under the Biden administration. It has been envisioned as a cyber and supply chain security standard for the defense industrial base.
Industry Concerns
According to DOD's Monday statement, the department is responding to complaints that CMMC was increasing compliance costs and adding bureaucratic burdens.
The Small Business Administration also reported that CMMC compliance had caused some companies to leave the defense industrial base, which DOD said is delaying the delivery of critical capabilities to operators.
Official Statements
"In support of Secretary Pete Hegseth's directive to reduce compliance barriers for small and medium sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program," said DOD Chief Information Officer Kirsten Davies.
Davies emphasized that cybersecurity and operational resilience remain critical priorities.
"We believe the DIB can achieve both, while we reduce unnecessary government red tape," she said.
Additional Suspensions
Phase 3 of CMMC, which was to begin in November 2027, and Phase 4 for full implementation are also suspended.
In the interim, the department stated it would rely on "self-assessments and select government-led assessments."
DOD's announcement confirmed that Davies made the decision.
"The CIO's decision ensures we maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain," said Michael Duffey, defense undersecretary for acquisition and sustainment.
Reform Task Force and Public Input
DOD has formed a CMMC Reform Task Force to conduct a review of the certification program. Part of their role will be to review comments submitted in response to a request for information (RFI), which DOD posted Monday.
The department is seeking feedback from companies on:
- Cost drivers
- Administrative burdens tied to CMMC compliance
- Which NIST 800-171 security controls deliver meaningful risk reduction
DOD also wants to understand how companies are already using commercial cybersecurity tools and managed services, and how the department might recognize those in a compliance framework instead of requiring separate assessments.
Responses to the RFI are due by August 14.
Source
Defense One - All ContentWestern
Part of this Story
Pentagon Suspends CMMC Phase 2, Launches 60-Day Reform Review