Wire flash
PoliticsPentagon suspends Phase 2 of CMMC, launches 60-day reform review
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
The U.S. Defense Department has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, which was set to require third-party certifications starting November 10, 2026. Phase 1 self-assessments will remain in place. The Pentagon is launching a 60-day review to align CMMC with Secretary Pete Hegseth's acquisition reform priorities, which emphasize speed and reducing barriers for small and medium businesses. The decision follows complaints about rising compliance costs and bureaucratic burdens, with the Small Business Administration reporting that some companies left the defense industrial base due to CMMC requirements. All future phases (3 and 4) are also suspended. A CMMC Reform Task Force will conduct the review and seek industry feedback via a request for information due August 14, 2026. The department will rely on self-assessments and select government-led assessments in the interim.
Source report
The Defense Department has effectively ended the Cybersecurity Maturity Model Certification (CMMC) program by suspending its second phase requirements.
Current Status
- Phase 1 remains in effect, requiring self-assessments for how companies protect controlled unclassified information in their systems.
- Phase 2 is suspended, which was set to begin on November 10 and required third-party certifications.
- Phase 3 (scheduled for November 2027) and Phase 4 (full implementation) are also suspended.
Reform Review
DOD is launching a 60-day review of CMMC to ensure alignment with Defense Secretary Pete Hegseth’s acquisition initiatives, which prioritize speed and lowering barriers for new entrants. The Acquisition Transformation System directives aim to replace bureaucratic compliance with what DOD calls "scalable, resilient cybersecurity measures."
Background
The CMMC program originated during the first Trump administration and was revised and streamlined during the Biden administration. It was envisioned as a cyber and supply chain security standard for the defense industrial base.
Reasons for Suspension
According to DOD's Monday statement, the department is responding to complaints that CMMC was:
- Increasing compliance costs
- Adding bureaucratic burdens
The Small Business Administration also reported that CMMC compliance had caused some companies to leave the defense industrial base, which DOD said is delaying deliveries of critical capabilities to operators.
Official Statements
Kirsten Davies, DOD Chief Information Officer:
"In support of Secretary Pete Hegseth's directive to reduce compliance barriers for small and medium sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program."
Davies added that cybersecurity and operational resilience are critical priorities:
"We believe the DIB can achieve both, while we reduce unnecessary government red tape."
Michael Duffey, Defense Undersecretary for Acquisition and Sustainment:
"The CIO's decision ensures we maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain."
Interim Measures
In the meantime, the department said it would rely on "self-assessments and select government-led assessments."
CMMC Reform Task Force
DOD has formed a CMMC Reform Task Force to conduct a review of the certification program. Part of their role will be to review comments in response to a request for information, which DOD posted Monday.
Request for Information (RFI)
DOD is seeking feedback from companies on:
- Cost drivers and administrative burdens tied to CMMC compliance
- Which NIST 800-171 security controls deliver meaningful risk reduction
- How companies are already using commercial cybersecurity tools and managed services
- How the department might recognize those tools in a compliance framework instead of requiring separate assessments
Responses to the RFI are due August 14.
Source
Defense One - All ContentWestern
Part of this Story
Pentagon Suspends CMMC Phase 2, Launches 60-Day Reform Review