The Pentagon has suspended the second phase of its Cybersecurity Maturity Model Certification (CMMC) program, which was set to kick in next month. This move is a significant development in the ongoing effort to strengthen cybersecurity standards for companies working on government contracts.
The CMMC program aims to verify that contractors handling sensitive information meet minimum cybersecurity requirements before they can secure defense contracts. The suspension of phase two has been put in place while the Department of War conducts a 60-day review of the entire program, with the goal of streamlining security measures and making it easier for smaller businesses to participate.
One of the main drivers behind this decision is the recognition that compliance costs have become too high for some small manufacturers. According to officials, there are not enough approved third-party assessors to handle the expected demand, which would have made meeting the November deadline impossible. The review task force will collect feedback from industry stakeholders and recommend scaled-back security measures to speed up contracting processes.
Under the original plan, contractors handling federal contract information or controlled unclassified information would need to meet one of three levels of cybersecurity standards: Level 1 focuses on protecting sensitive but not classified information, Level 2 builds on this with additional requirements for advanced threats, and Level 3 introduces even more stringent measures. The second phase was scheduled to require third-party certification assessments for new contracts at the Level 2 standard.
While the suspension of phase two may seem like a setback, officials emphasize that contractors will still need to meet existing regulations for handling government information, including Phase One requirements. This means that while the timeline has been adjusted, cybersecurity remains a top priority across the Department of War and its defense industrial base.
The move is seen as a step towards revitalizing the defense industrial base by clearing bureaucratic obstacles and making it easier for smaller businesses to participate in government contracting. Secretary of War Pete Hegseth’s directive to aggressively scale warfighter readiness has driven this effort, with officials committed to investing in and maintaining robust cybersecurity across all departments.
In practical terms, contractors need to be aware that while the CMMC program is being revised, they must still comply with existing regulations for handling sensitive information. This means staying up-to-date on their security measures and ensuring they meet the necessary standards to avoid potential contract disruptions.
Source: SecurityWeek — 2026-07-14