The Pentagon is suspending Cybersecurity Maturity Model Certification (CMMC) phase two requirements that were set to take effect in November, pending a 60-day review of the entire program.
CMMC Review and Reform
Kirsten Davies, CIO at the Department of War (formerly the Department of Defense), said the move clears bureaucratic obstacles without lowering the bar on cybersecurity, noting that contractors must still meet phase one requirements and existing regulations for handling government information.
A newly formed CMMC review and reform task force will collect industry feedback and then recommend scaled-back security measures to speed up contracting for small and nontraditional businesses.
Industry Feedback and Recommendations
Undersecretary of War for Acquisition and Sustainment Michael Duffey framed the pause as necessary to keep smaller manufacturers from being squeezed out of defense work by compliance costs.
The CMMC is a framework for verifying that companies handling government information meet baseline cybersecurity standards before they can win defense contracts.
CMMC Framework and Requirements
Contractors and subcontractors that process federal contract information (FCI) or controlled unclassified information (CUI) are subject to the framework, regardless of their size.
CMMC 2.0 streamlined the program from five levels to three: Level 1 covers protection of FCI, Level 2 covers CUI based on NIST 800-171, and Level 3 focuses on critical CUI against advanced persistent threats.
Phased Rollout and Certification Requirements
The rule took effect on November 10, 2025, kicking off a multi-year phased rollout, with phase one requiring Level 1 and Level 2 self-assessments.
However, when announcing the changes, officials cited a shortage of approved third-party assessors as one reason the November deadline was no longer feasible.
Phase three, scheduled for November 2027, would introduce Level 3 certification requirements, while the fourth and final phase would bring full implementation across applicable contracts by 2028.
“The Department of War is taking decisive action to clear bureaucratic roadblocks and revitalize our defense industrial base in support of Secretary of War Pete Hegseth’s directive to aggressively scale warfighter readiness,” said Davies, adding, “[But] I want to be clear, across the Department of War and our defense industrial base, investing in and dynamically maintaining robust cybersecurity remains a critical, nonnegotiable priority.”
The suspension of CMMC phase 2 requirements is expected to have a significant impact on the defense industry, particularly for small and nontraditional businesses.
Impact on the Defense Industry
The move is seen as a necessary step to ensure that the CMMC program is effective and efficient in its goal of protecting government information and ensuring the security of the defense industrial base.
The CMMC review and reform task force will play a crucial role in shaping the future of the program and ensuring that it meets the needs of the defense industry and the government.
- CMMC phase 2 requirements suspended pending 60-day review
- CMMC review and reform task force to collect industry feedback and recommend scaled-back security measures
- Phase one requirements and existing regulations still apply to contractors
- CMMC framework and requirements to be re-evaluated and potentially revised
The outcome of the review and the future of the CMMC program remain uncertain, but one thing is clear: the importance of robust cybersecurity in the defense industry will only continue to grow.
Source: SecurityWeek