{"id":46712,"date":"2026-07-16T20:24:53","date_gmt":"2026-07-16T12:24:53","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/pentagon-suspends-cmmc-phase-ii-plans-cites-concerns-with-compliance-burdens\/"},"modified":"2026-07-16T20:24:53","modified_gmt":"2026-07-16T12:24:53","slug":"pentagon-suspends-cmmc-phase-ii-plans-cites-concerns-with-compliance-burdens","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/pentagon-suspends-cmmc-phase-ii-plans-cites-concerns-with-compliance-burdens\/","title":{"rendered":"Pentagon Suspends CMMC Phase II Plans, Cites Concerns With Compliance \u2018Burdens\u2019"},"content":{"rendered":"<p>The Pentagon announced Monday it is suspending planned implementation of the next Cybersecurity Maturity Model Certification (CMMC) phase, which included third-party audits, as it reviews the future of the program.<\/p>\n<p>While current Phase I requirements for industry to self-assess for cyber security compliance will remain in place, Pentagon officials said the costs and bureaucratic burdens associated with current CMMC plans were deterring some small businesses and newer defense entrants from pursuing contracts with the department.<\/p>\n<p>\u201cWhile the original intent of CMMC was to strengthen the cyber security of the DIB, the research is illuminating that it is instead creating costly bureaucratic burdens, which are resulting in innovative small, medium and non-traditional businesses having to choose between completing paperwork and paying for assessments or exiting the defense base altogether. This is simply not acceptable,\u201d Kirsten Davies, the Pentagon\u2019s chief information officer, told reporters.<\/p>\n<p>\u201cThis is not achieving what it was intended to achieve, and so we need to think differently about it,\u201d Davies added.<\/p>\n<p>CMMC is the Pentagon\u2019s program for setting cyber security contracting standards, with the department first rolling out the initiative in 2019 before it&nbsp;moved to a \u201c2.0\u201d model&nbsp;in 2021 aimed at addressing cost and complexity concerns by reducing the number of tiers of compliance from five to three and allowing for more self-assessment opportunities on certain types of programs (<i>Defense Daily<\/i>, Nov. 4, 2021).<\/p>\n<p>However, a memo signed on Monday by Davies and Michael Duffey, the department\u2019s acquisition chief, states that the current iteration of CMMC \u201cimposes significant and often prohibitive burdens,\u201d especially for small and non-traditional businesses, and that it\u2019s \u201cstructurally incompatible\u201d with the efforts to expand the defense industrial base.<\/p>\n<p>\u201cThe combination of prohibitive compliance costs, severe shortages in third-party assessment capacity and complex regulatory timelines is actively forcing innovative new entrants and small businesses to opt out of [Pentagon] contracts and freezing critical suppliers out of the market,\u201d the memo states.<\/p>\n<p>Duffey said he has \u201cno doubt\u201d that CMMC and the planned Phase II requirements had kept some companies from competing for contracts.<\/p>\n<p>A recent Small Business Administration survey with small to medium-sized businesses provided data that backed up concerns with CMMC\u2019s potential impact, according to Davies, to include highlighting \u201csignificant duplicative overlap\u201d with existing regulatory requirements for the handling of federal data.<\/p>\n<p>\u201cThe data we are seeing, including recent reports from the Small Business Administration, the SBA, makes one thing clear: the current CMMC requirements, including the future planned requirements, are creating prohibitive compliance costs and unacceptable bureaucratic burdens, especially to small businesses,\u201d Davies said. \u201cWe will not allow duplicative and ineffective administrative hurdles to delay the delivery of critical capabilities to our warfighters.\u201d<\/p>\n<p>\u201cIt is anticipated that moving on into the future phases of the CMMC implementation was going to cost over $7 billion per annum for small to medium-sized businesses to get compliant with those,\u201d she added.<\/p>\n<p>Davies noted that over 100,000 defense firms still needed to complete a third-party cyber security assessment to comply with Phase II requirements, while just over 100 assessors were available to conduct those audits.<\/p>\n<p>\u201cSo the math just simply doesn\u2019t math for small to medium-sized businesses to even get compliance by the [former] transition date, which [was] November,\u201d Davies said. \u201cThe research is showing us that there are not enough assessors to meet the demand of the industry.\u201d<\/p>\n<p>The memo states that, effective immediately, the Pentagon is suspending the planned transition into Phase II of CMMC on November 10 and has paused \u201cpending and future CMMC implementation milestones across solicitations and contracts.\u201d<\/p>\n<p>\u201cWe are halting complex audits. We are stopping the requirement for third-party assessors and audits. Instead, we are establishing a pragmatic, secure baseline, enforcing proven NIST cyber security standards through simplified Level One and Level Two self-assessments,\u201d Duffey said.<\/p>\n<p>Duffey said the Pentagon will on \u201ccleaning up active solicitations immediately\u201d for those contracts that had CMMC Phase II compliance built into requirements.<\/p>\n<p>\u201cIf a current defense solicitation or contract contains those suspended Phase II requirements, I have directed our program managers and contracting officers to amend or modify them as soon as possible to remove the burden,\u201d Duffey added.<\/p>\n<p><strong>60 Day Review<\/strong><\/p>\n<p>The Pentagon is establishing a CMMC Reform Task Force to conduct a 60-day review of the program, noting a goal for \u201creplacing bureaucratic compliance with scalable, resilient cyber security measures.\u201d<\/p>\n<p>A Request for Information will be published to gather industry\u2019s feedback on cyber security compliance measures for contracting, which the task force will use to inform a final report with recommendations to Davies.<\/p>\n<p>During the interim period as the review gets underway, the Pentagon confirmed it will continue to enforce cyber security compliance with the NIST SP 800-171 Rev 2 standard \u201cthrough self-assessments and select government-led assessments, focusing on tangible cyber hygiene rather than administrative overhead.\u201d<\/p>\n<p>\u201cI want to be clear, across the Department of War and our defense industrial base, investing in and dynamically maintaining robust cyber security remains a critical,&nbsp; non-negotiable priority. This action does not eliminate the legal requirement for our industry partners to protect federal data. First of all, Phase I self-assessment requirements remain firmly in place. Second, we will continue to enforce compliance with the NIST SP 800-171 Rev 2 standard, focusing on tangible cyber hygiene rather than administrative overhead. And third, all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information under existing DFARS requirements,\u201d Davies told reporters.<\/p>\n<p>\u201cWhat we\u2019re doing is reducing this red tape burden of simply having a check-the-box exercise of compliance. But the self-assessment is actually still quite valid for companies to be seeing where they stand in basic cyber hygiene because that keeps them in business,\u201d she added.<\/p>\n<p>Davies noted that the non-profit CMMC Accreditation Body, which certifies third-party auditors, had not been informed of the memo as of its public release on Monday afternoon.<\/p>\n<p>\u201cSo my phone will be very busy for the rest of the day,\u201d Davies said.<\/p>\n<p>Davies also addressed potential for pushback by those firms that have invested resources to get after meeting the now-suspended CMMC Phase II compliance requirements.<\/p>\n<p>\u201cEvery dollar spent on security is a wise dollar spent. And so, those who have been forward-leaning in uplifting their cyber posture, in assessing what their posture is and doing something about it, they have contributed to national security. They\u2019ve contributed to the operational resiliency of their own company. That is not money that is spent in vain,\u201d she said.<\/p>\n<p><em>This story was first published by Defense Daily<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Pentagon announced Monday it is suspending planned implementation of the next Cybersecurity Maturity Model Certification (CMMC) phase, which included third-party audits, as it reviews the future of the program. While current Phase I requirements for industry to self-assess for cyber security compliance will remain in place, Pentagon officials said the costs and bureaucratic burdens [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":46713,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-46712","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/46712"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=46712"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/46712\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/46713"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=46712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=46712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=46712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}