Wire flash
PoliticsPentagon suspends Phase 2 of CMMC cybersecurity certification, launches 60-day reform review
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
The U.S. Defense Department has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, which was set to require third-party certifications starting November 10, 2026. Phase 1 self-assessments will remain in place. The Pentagon is launching a 60-day review to align the program with Defense Secretary Pete Hegseth's acquisition reform priorities, which emphasize speed and reducing barriers for small and medium businesses. The decision follows complaints about rising compliance costs and bureaucratic burdens, with the Small Business Administration reporting that CMMC requirements had driven some companies out of the defense industrial base, delaying critical deliveries. DOD Chief Information Officer Kirsten Davies announced the suspension and the formation of a CMMC Reform Task Force. The department has also issued a request for information seeking industry feedback on cost drivers, administrative burdens, and how commercial cybersecurity tools could be recognized in a revised framework. Responses are due by August 14, 2026. All future phases of CMMC, including Phase 3 and Phase 4, are also suspended pending the review.
Source report
The Defense Department has effectively ended the Cybersecurity Maturity Model Certification (CMMC) program by suspending its Phase 2 requirements.
Current Status
- Phase 1 remains in effect, requiring self-assessments for how companies protect controlled unclassified information in their systems.
- Phase 2 is suspended, which was set to begin on Nov. 10 and required third-party certifications.
- Phase 3 (scheduled for November 2027) and Phase 4 (full implementation) are also suspended.
Reason for Suspension
According to DOD's Monday statement, the department is responding to complaints that CMMC was increasing compliance costs and adding bureaucratic burdens. The Small Business Administration also reported that CMMC compliance had caused some companies to leave the defense industrial base, which DOD said is delaying deliveries of critical capabilities to operators.
Reform Review
DOD is launching a 60-day review of CMMC to ensure alignment with Defense Secretary Pete Hegseth’s acquisition initiatives, which prioritize speed and lowering barriers for new entrants. The Acquisition Transformation System directives aim to replace bureaucratic compliance with what DOD calls "scalable, resilient cybersecurity measures."
DOD has formed a CMMC Reform Task Force to conduct the review. Their responsibilities include reviewing comments in response to a request for information (RFI), which DOD posted Monday.
Official Statements
Kirsten Davies, DOD Chief Information Officer:
"In support of Secretary Pete Hegseth's directive to reduce compliance barriers for small and medium sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program."
Davies added that cybersecurity and operational resilience are critical priorities:
"We believe the DIB can achieve both, while we reduce unnecessary government red tape."
Michael Duffey, Defense Undersecretary for Acquisition and Sustainment:
"The CIO's decision ensures we maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain."
Interim Measures
In the meantime, DOD said it would rely on "self-assessments and select government-led assessments."
Background
The CMMC program began during the first Trump administration and was revised and streamlined during the Biden administration. It was envisioned as a cyber and supply chain security standard for the defense industrial base.
Request for Information (RFI)
DOD is seeking feedback from companies on:
- Cost drivers and administrative burdens tied to CMMC compliance
- Which NIST 800-171 security controls deliver meaningful risk reduction
- How companies are already using commercial cybersecurity tools and managed services
- How DOD might recognize those tools in a compliance framework instead of requiring separate assessments
Responses to the RFI are due Aug. 14.
Source
Defense One - All ContentWestern
Part of this Story
Pentagon Suspends CMMC Phase 2, Launches 60-Day Reform Review