Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday

The US Department of War has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, citing concerns that the third-party assessment requirement was pushing small and mid-sized defense contractors out of business. This move affects only the mandatory third-party assessment requirement, leaving other aspects of the program intact.

Industry insiders are warning that self-attestation without verification raises significant risks, including False Claims Act exposure. For those unfamiliar with the CMMC program, it’s worth noting that Phase 1 requires companies to conduct their own security assessments and report their scores through the Supplier Performance Risk System (SPRS). However, this is not enough to ensure compliance with Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which mandates protection of controlled unclassified information.

Industry professionals like Abdie Mohamed, GRC Engineering Lead at NR Labs, are cautioning that self-attestation without verification can lead to costly consequences. Mohamed points out that while Phase 1 remains in effect, the suspension of third-party assessments leaves companies vulnerable to False Claims Act exposure if they inaccurately report their compliance status.

The CMMC program’s problems run deeper than just its assessment requirements. With over 100 authorized assessors for more than 100,000 companies, it was always a challenge for these businesses to scale and meet demand. This led the Department of War to form a CMMC Reform Task Force, which will spend the next 60 days gathering industry feedback and reporting recommendations by mid-September.

Industry leaders are divided on how to address the program’s issues. Some argue that assessments should be automated or scaled back, while others believe they should remain largely intact. Chris Nyhuis, CEO of Vigilant, believes that suspending Phase 2 was a necessary step, citing concerns about the slow pace and high costs associated with third-party audits.

Nyhuis emphasizes that self-attestation without verification is not a foolproof solution. In his experience, many companies skirt the rules, and third-party validation exists to ensure accountability. Without it, Nyhuis warns that self-attestation could become “a fast lie,” leading to costly breaches down the line.

While the CMMC program’s future remains uncertain, one thing is clear: its problems are not going away anytime soon. As the industry waits for the CMMC Reform Task Force’s recommendations, companies must remain vigilant about their security posture and compliance obligations. In the meantime, it’s essential for defense contractors to prioritize transparency and accountability in their self-attestation processes.

Ultimately, this development highlights the importance of finding a balance between speed and security in the defense industry. As Nyhuis puts it, “Speed done securely is a security requirement now, not a nice-to-have.” Companies must focus on protecting controlled unclassified information while also navigating the complexities of the CMMC program.


Source: SecurityWeek — 2026-07-17