DoD Suspends CMMC Phase II, Launches Review to Cut Costs and Aid Small Firms

DoD suspends Phase II CMMC requirements and all future milestones (Phase 3 and Phase 4) and launches a 60-day top-to-bottom review to align CMMC with the Acquisition Transformation System, while Phase I self-assessments remain in place and third-party assessments are paused for now.
The move is framed as reducing costly compliance burdens; DoD cites SBA data indicating CMMC compliance has driven some innovative firms out of the defense industrial base and delayed warfighter capability delivery.
In a memo, DoD CIO Kirsten Davies characterizes the current CMMC framework as imposing 'significant and often prohibitive burdens' on the defense industrial base, especially small and nontraditional businesses, and argues that 'administrative compliance cannot come at the cost of warfighting capability and industrial base growth.'
The policy context centers on the Acquisition Transformation System, aiming to speed capability delivery and replace bureaucratic compliance with scalable, resilient cybersecurity; the push includes emphasis on expanding access to leading-edge commercial capabilities (the 'Arsenal of Freedom').
The Pentagon has suspended Phase 2 of its Cybersecurity Maturity Model Certification program and launched a 60-day top-to-bottom review, according to Washington Technology and Nextgov. The move pauses all third-party assessment requirements and freezes Phase 3 and Phase 4 milestones as well. Phase 1 self-assessments remain in effect.
DoD framed the suspension as a cost-cutting move. Officials say heavy compliance requirements have pushed small, innovative firms out of the defense industrial base and slowed delivery of wartime capabilities, according to MeriTalk.
DoD Chief Information Officer Kirsten Davies issued a memo calling the current CMMC framework a source of 'significant and often prohibitive burdens' on the defense industrial base. She singled out small and nontraditional businesses as the hardest hit. Davies argued that 'administrative compliance cannot come at the cost of warfighting capability and industrial base growth.'
DoD cited Small Business Administration data showing that CMMC compliance costs have driven some innovative companies out of defense contracting entirely. The department said that outcome directly delays the delivery of capabilities to warfighters, according to Defense Daily.
CMMC stands for Cybersecurity Maturity Model Certification. It is a DoD program designed to verify that defense contractors meet cybersecurity standards before winning government contracts. Phase 1 requires companies to assess themselves. Phase 2, now suspended, required independent third-party audits — a far costlier step.
Phase 2 covered a large portion of the defense supply chain, especially mid-tier contractors handling sensitive but unclassified military data. Suspending it means thousands of firms no longer face imminent third-party audit requirements, according to Washington Technology.
The 60-day review will examine how CMMC fits into Secretary Pete Hegseth's Acquisition Transformation System. That initiative aims to speed up how the military buys and fields new technology. The goal is to replace checkbox compliance with cybersecurity rules that actually scale with the size and risk level of each contractor, according to Nextgov.
DoD officials say the review will also look at how to expand access for nontraditional vendors — companies outside the usual defense contractor world. The department called this push the 'Arsenal of Freedom,' a nod to bringing commercial innovation into military supply chains faster.
Not everyone sees the suspension as good news. Critics argue that CMMC exists precisely because defense contractors have been repeat targets of foreign cyber espionage. Pausing third-party audits, even temporarily, removes a key layer of independent verification from the supply chain, according to National Defense Magazine.
Davies acknowledged the tension directly. She stressed that 'robust cybersecurity remains essential' and that the review is not a rollback of security standards. DoD says the goal is to protect national innovation without slowing down the warfighter — a balance the 60-day review must now define.
Publishers
15
Articles
15
Reach
30