Key Takeaways
- The Department of Defense (DOD) has suspended Phase Two of the Cybersecurity Maturity Model Certification (CMMC) program, citing prohibitive compliance costs and bureaucratic burdens, especially for small‑to‑medium‑sized businesses.
- Phase One, which began in November 2025 and requires contractors to self‑certify adequate cyber defenses, remains in effect; a potential Phase Three slated for November 2027 is now on hold pending review.
- Over 100,000 defense firms still need third‑party assessments, but only about 100 accredited assessors are available, creating a significant bottleneck.
- A Small Business Administration (SBA) survey estimated that implementing Phase Two would cost small businesses more than $7 billion annually.
- DOD leadership emphasizes that robust cybersecurity remains a priority, but the department aims to reduce unnecessary red tape while maintaining a strict security baseline.
- In the interim, compliance will be enforced through self‑assessments and government‑led evaluations, and the DOD will review its certification programs and recommend new measures within 60 days.
- Other government entities, such as the Office of the Director of National Intelligence (ODNI), have also trimmed cybersecurity staff, reflecting a broader trend of streamlining security functions amid budget and efficiency pressures.
Overview of the Suspension
The Department of Defense announced that it is pausing the rollout of Phase Two of the Cybersecurity Maturity Model Certification (CMMC) program. Originally slated to take effect in November 2025, the phase would have required defense contractors to obtain a passing score from an independent, certified third‑party assessor before being eligible for contract awards. The decision comes after extensive feedback from industry stakeholders who argued that the forthcoming requirements would impose unsustainable financial and administrative pressures, particularly on small businesses that form a vital part of the defense industrial base.
Background and Purpose of CMMC
CMMC was first introduced in 2019 under the Trump administration as a unified framework to ensure that third‑party contractors adequately protect controlled unclassified information (CUI) and other sensitive Pentagon data. The model consists of five maturity levels, each building on the previous one with increasingly rigorous cybersecurity practices. Phase One, which launched in November 2025, mandates that contractors self‑attest that their cyber defenses meet basic hygiene standards. Phase Two was designed to add an external validation step, while a prospective Phase Three would have introduced continuous monitoring and advanced threat‑hunting capabilities.
Industry Concerns About Cost and Complexity
Since its inception, CMMC has drawn criticism from contractors who describe the certification process as cumbersome, costly, and difficult to navigate. Small‑ and medium‑sized enterprises (SMEs) have been especially vocal, noting that the expense of hiring accredited assessors, upgrading security controls, and maintaining documentation could outweigh the benefits of winning defense contracts. These concerns were echoed in numerous public comments, industry surveys, and testimonies before congressional committees, prompting the DOD to reassess the implementation timeline.
Leadership Statements on Security Versus Bureaucracy
Defense Department Chief Information Officer Kirsten Davies defended the suspension by emphasizing that every dollar spent on cybersecurity is a worthwhile investment, but that the current approach risked “paralyzing costs” that could stifle innovation. She highlighted that firms already improving their cyber posture contribute directly to national security and should not be penalized for excessive red tape. Under Secretary of Defense for Acquisition and Sustainment William A. Duffey echoed this sentiment, stating that the decision preserves a strict security baseline while removing barriers that could impede competition and the growth of the defense supply chain.
Assessment Capacity Constraints
A practical obstacle contributing to the pause is the severe shortage of qualified assessors. DOD estimates that more than 100,000 defense firms still require a third‑party cybersecurity evaluation to meet CMMC requirements, yet the pool of accredited assessors numbers just over 100. This mismatch would have created months‑long waiting periods, increased costs, and potentially delayed contract awards across the department. The bottleneck underscored the need to reconsider how compliance verification is conducted, at least in the near term.
SBA Survey Findings on Financial Impact
The Small Business Administration conducted a survey that quantified the anticipated financial strain of Phase Two on SMEs. According to the SBA’s analysis, implementing the mandatory third‑party assessments would have cost small‑to‑medium‑sized businesses upwards of $7 billion per year. The agency warned that such expenses could force many firms out of the defense market, reducing the diversity and resilience of the industrial base. In response, SBA Administrator Kelly Loeffler praised the DOD’s decision, asserting that cybersecurity must not become a prohibitive gatekeeper that excludes the very companies warfighters rely on for critical supplies and services.
Continuation of Phase One and Future Phases
While Phase Two is on hold, the DOD confirmed that Phase One of CMMC remains active. Contractors must continue to self‑certify that their cybersecurity hygiene meets the foundational standards outlined in the first maturity level. The department also noted that, had Phase Two proceeded as planned, a Phase Three would have been scheduled for November 2027, introducing more advanced, continuous monitoring requirements. The future of both Phase Two and Phase Three will be determined after the DOD completes its internal review of the certification framework.
Interim Measures and Broader Cybersecurity Adjustments
In the meantime, the DOD will enforce cybersecurity compliance through a combination of self‑assessments and government‑led evaluations. This hybrid approach aims to maintain oversight while alleviating the immediate pressure on the limited pool of third‑party assessors. The announcement coincides with a wider trend of cybersecurity belt‑tightening across the federal government; for example, the Office of the Director of National Intelligence (ODNI) recently reduced staff in its cyber threat‑tracking units by nearly 50 % as part of a broader effort to cut agency personnel. These moves reflect an ongoing effort to balance security imperatives with fiscal responsibility and operational efficiency.
Review Process and Path Forward
The DOD has committed to conducting a comprehensive review of its CMMC certification program and related cybersecurity initiatives, with the goal of recommending revised measures within 60 days. The review will likely examine alternatives to the current third‑party assessment model, such as expanded use of automated security scoring tools, risk‑based audits, or tiered self‑assessment frameworks that retain rigor while reducing administrative overhead. Stakeholders from industry, academia, and government will be consulted to ensure that any new approach sustains robust protection of defense data without imposing prohibitive costs on the suppliers that support the nation’s warfighters.
By suspending Phase Two of CMMC, the Department of Defense seeks to recalibrate its cybersecurity strategy: preserving essential security standards while addressing the genuine cost and bureaucratic challenges voiced by the defense industrial base, particularly small businesses.

