Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules

The Pentagon has put the brakes on its ambitious Cybersecurity Maturity Model Certification (CMMC) program, at least for now. The move comes as a welcome relief to small and non-traditional businesses that have been struggling to comply with the rigorous cybersecurity standards required by the framework.

Under the CMMC, companies handling sensitive government information must meet certain baseline security requirements before they can win defense contracts. However, the program’s second phase was set to introduce even tougher standards, requiring third-party certification assessments for new contracts. But with a shortage of approved assessors and bureaucratic obstacles in the way, the Pentagon has decided to pause the rollout until it can reassess its approach.

A newly formed review and reform task force will collect industry feedback and recommend scaled-back security measures to speed up contracting for smaller businesses. The goal is to clear “bureaucratic roadblocks” without lowering the bar on cybersecurity. As CIO Kirsten Davies put it, investing in robust cybersecurity remains a nonnegotiable priority across the Department of War and its defense industrial base.

The CMMC framework has been a contentious issue since its inception, with many small businesses complaining that compliance costs are too high and the requirements are too complex. Undersecretary of War for Acquisition and Sustainment Michael Duffey framed the pause as necessary to prevent smaller manufacturers from being squeezed out of defense work by compliance costs.

The CMMC is designed to ensure that companies handling sensitive government information meet baseline cybersecurity standards before they can win defense contracts. Contractors and subcontractors that process federal contract information (FCI) or controlled unclassified information (CUI) are subject to the framework, regardless of their size.

In 2025, the program was streamlined from five levels to three: Level 1 covers protection of FCI, Level 2 covers CUI based on NIST 800-171, and Level 3 focuses on critical CUI against advanced persistent threats. However, with phase two now on hold, it’s unclear when or if the more stringent standards will be introduced.

The Pentagon’s decision to pause the rollout is a significant development in the world of cybersecurity. As the government continues to grapple with the complexities of protecting sensitive information, one thing is clear: the stakes are high and the pressure is on to get it right.

For businesses that handle sensitive government information, this news may come as a welcome relief. But it’s essential to remember that cybersecurity remains a critical priority for the Department of War and its defense industrial base. As Davies emphasized, investing in robust cybersecurity is nonnegotiable – even if it means clearing bureaucratic obstacles along the way.

For those responsible for implementing or complying with the CMMC program, this development serves as a reminder that flexibility and adaptability are crucial in the ever-evolving world of cybersecurity.


Source: SecurityWeek — 2026-07-14