← BACK TO FEED
CMMCPentagoncybersecurity compliancedefence contractingNIST 800-171

Pentagon Hits Pause on CMMC Phase 2, Launches 60-Day Review of Contractor Cybersecurity Rules

The Pentagon has suspended phase two of its Cybersecurity Maturity Model Certification (CMMC) program, which was due to take effect in November 2026, initiating a 60-day review of the entire framework. Officials cited a shortage of approved third-party assessors and concerns that compliance costs could push smaller manufacturers out of defense contracting as key reasons for the pause. A newly formed task force will gather industry feedback and propose streamlined security measures, while contractors must still meet existing phase one requirements and baseline cybersecurity standards.

The Pentagon has suspended the next phase of its Cybersecurity Maturity Model Certification programme, shelving requirements that were due to kick in this November while it spends 60 days rethinking the whole thing.

Kirsten Davies, CIO at what the current administration has taken to calling the Department of War, insists the pause isn't a retreat on security standards. Contractors still have to comply with phase one requirements and existing rules around handling government data. The suspension is, in theory, about cutting red tape rather than cutting corners.

A newly stood-up CMMC review and reform task force will gather industry input and figure out where the compliance burden can be trimmed, particularly for smaller and non-traditional defence suppliers who've been struggling to absorb the costs.

Undersecretary for Acquisition and Sustainment Michael Duffey was blunt about one of the practical problems: there simply aren't enough approved third-party assessors to meet the November 2026 deadline. That alone would have created a certification bottleneck severe enough to lock smaller manufacturers out of defence contracting entirely, which rather defeats the point.

For context, CMMC 2.0 simplified the original five-tier structure down to three levels. Level 1 covers basic protection of federal contract information. Level 2 maps to NIST 800-171 and applies to controlled unclassified information. Level 3 is reserved for critical systems facing advanced persistent threats. The framework applies to any contractor or subcontractor touching government data, regardless of company size.

The programme formally began on 10 November 2025, with phase one requiring self-assessments at Levels 1 and 2. Phase two was supposed to raise the stakes by mandating independent third-party certification for new contracts. Phase three, pencilled in for November 2027, would have introduced Level 3 requirements, with full implementation across all applicable contracts targeted for 2028.

That roadmap is now under review. The task force will report back with recommendations, presumably before anything gets rescheduled.

Whether this produces a leaner, more workable programme or simply delays the inevitable compliance crunch remains to be seen. The assessor shortage problem doesn't disappear just because a deadline moves.

READ NEXT
This Cybersecurity Index Tracks Real Breaches and Refuses to Invent a Grand TotalCapital One Releases AI Vulnerability Hunter to the Public23 Million Paidwork Users' Data Dumped Online After Alleged March Breach