Key Takeaways
- The CMMC framework was created to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) on defense contractor networks, shifting from self‑attestation to mandatory third‑party verification.
- Phase II, which would have required Certified Third‑Party Assessor Organization (C3PAO) audits for contracts handling CUI, was suspended in November 2024 to reduce audit costs and bureaucratic red tape.
- The newly formed CMMC Reform Task Force has a 60‑day window (the RFI comment period closed August 14, 2024) to collect industry feedback, with recommendations due by mid‑September 2026 on whether to restructure, scale back, or alter the program.
- Dr. Jim Purtilo emphasizes that while third‑party audits raise assurance, they impose heavy financial and operational burdens that can push small and mid‑sized businesses out of the defense industrial base.
- The task force must balance the need for high technical standards with low‑burden practices, weighing trade‑offs where objective metrics for cybersecurity effectiveness are still lacking.
- If Phase II remains suspended, the industry reverts to self‑assessment, which experts warn offers a low bar for security and may encourage “folklore”‑based practices rather than evidence‑based controls.
- Lowering the barrier to entry could increase competition but risks weakening supply‑chain security and increasing liability under the False Claims Act.
- The outcome of the reform effort will determine whether the DoD can retain robust cybersecurity safeguards without forcing critical suppliers out of the defense market.
Overview of CMMC and Its Purpose
The Cybersecurity Maturity Model Certification (CMMC) is a framework instituted by the U.S. Department of Defense (DoD) to ensure that defense contractors and subcontractors adequately protect sensitive unclassified government data, specifically Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). Prior to CMMC, contractors merely self‑attested to following cybersecurity guidelines, a process that offered limited verification. CMMC introduced a tiered certification model requiring formal assessments to validate that contractors have implemented appropriate security controls. By linking contract eligibility to demonstrated cybersecurity maturity, the DoD aims to close gaps in its supply chain, reduce the risk of data breaches, and safeguard military and defense secrets that reside on third‑party networks.
Original CMMC Structure and Phasing
CMMC originally defined five maturity levels, ranging from basic cyber hygiene (Level 1) to advanced, progressive security practices (Level 5). Contracts involving only FCI were to require at least Level 1, while those handling CUI demanded Level 3 or higher, depending on the sensitivity of the information. The framework envisioned a phased rollout: Phase I focused on raising awareness and enabling self‑assessments for lower‑level contracts; Phase II would have made third‑party assessments by Certified Third‑Party Assessor Organizations (C3PAOs) mandatory for all contracts involving CUI; and Phases III‑V were slated for later implementation, addressing more sophisticated threats and continuous monitoring capabilities. This staged approach was intended to give industry time to adapt while gradually increasing assurance across the defense industrial base.
Suspension of Phase II Requirements
In November 2024, the DoD announced an immediate suspension of the Phase II requirements, which were scheduled to take effect on November 10, 2024. The decision aimed to alleviate what officials described as “bureaucratic red tape” and high audit costs that threatened to push critical small and mid‑sized businesses out of the defense supply chain. By pausing the mandatory C3PAO audits, the department sought to retain a broader pool of contractors while the CMMC Reform Task Force evaluates whether the current structure is overly burdensome. The suspension does not abolish CMMC altogether; instead, it returns the assessment process for CUI‑related contracts to self‑attestation until a revised framework is finalized.
RFI Comment Period and Timeline
To inform its review, the CMMC Reform Task Force issued a Request for Information (RFI) seeking industry perspectives on how to reshape the cybersecurity framework. The public comment period closed on Friday, August 14, 2024, after a 60‑day window that allowed contractors, academia, and other stakeholders to submit feedback on potential restructuring, scaling back, or alternative approaches. The task force is now tasked with analyzing these submissions and delivering a set of recommendations by mid‑September 2026. Those recommendations will determine whether Phase II will be reinstated in its original form, modified to reduce costs, or replaced with a different verification mechanism that still meets DoD security objectives.
Expert Insight: Administrative Burden vs. Assurance
Dr. Jim Purtilo, associate professor of computer science at the University of Maryland, highlighted the tension between achieving high assurance and imposing administrative strain. He acknowledged that third‑party audits are expensive and that tight compliance timelines could exclude smaller firms from competing for DoD contracts. Purtilo noted that the task force faces the challenge of “having its cake and eating it too”—designing low‑burden practices that still yield strong technical guarantees. He warned that without reliable data to inform decisions, cybersecurity practices risk devolving into folklore and guesswork, leading to unnecessary expenses driven by an “abundance of caution” rather than evidence‑based controls.
Financial and Operational Strain on Small Contractors
The mandatory C3PAO audits envisioned under Phase II would have required contractors to hire certified assessors and potentially upgrade technical systems, costs that can range from tens to hundreds of thousands of dollars. For small and mid‑sized enterprises operating on thin margins, such expenditures represent a significant financial strain, potentially diverting resources from innovation or business growth. Operationally, preparing for an audit demands dedicated staff time, documentation efforts, and process changes that can disrupt normal workflows. Critics argue that these burdens risk forcing capable, innovative suppliers out of the defense industrial base, reducing competition and limiting the DoD’s access to cutting‑edge technologies.
Risk‑Reward Considerations and Evidence‑Based Decision Making
Purtilo drew a parallel to software engineering, where managers weigh risk and reward using measurable metrics to allocate effort efficiently. He suggested that cybersecurity should adopt a similar evidence‑based approach, using concrete data to identify where investments yield the highest security returns. However, he lamented that the necessary data often remains obscured by current practices, making it difficult to distinguish between effective controls and superfluous measures. Until the task force can establish clearer metrics, any reform will inevitably involve trade‑offs: lowering the barrier to entry may increase participation but could also weaken assurance, while maintaining strict audits preserves security at the cost of accessibility.
Return to Self‑Assessment and Future Implications
With Phase II on hold, the industry has reverted to self‑assessment for contracts involving CUI. Purtilo cautioned that self‑attestation offers a relatively low bar for security verification and may encourage practices based on habit rather than rigorous validation. This environment raises concerns about the reliability of compliance claims and the potential for false statements that could trigger liability under the False Claims Act. The sooner the reform task force delivers clear guidance, the sooner contractors can align their efforts with a predictable, trustworthy framework that balances security needs with the realities of a diverse supplier base.
Conclusion: Seeking a Balanced Path Forward
The CMMC reform effort sits at a critical juncture where the DoD must protect its information assets without undermining the vitality of the defense industrial base. The suspension of Phase II highlights the recognition that excessive costs and complexity can exclude essential contributors, especially small businesses that drive innovation. Yet, any relaxation of requirements must be weighed against the risk of eroding supply‑chain security and increasing exposure to data breaches. The task force’s forthcoming recommendations will need to articulate a version of CMMC that leverages achievable, measurable controls, reduces unnecessary financial burdens, and sustains a high level of assurance. Achieving this balance will determine whether the DoD can maintain a resilient, secure procurement ecosystem while fostering broad participation from contractors of all sizes.

