cmmctrade-pressNewsThe Broadside1 min read

DoD suspends CMMC Phase 2 for 60-day review

A cost reprieve now leaves primes and subs guessing which cyber baseline DoD will actually buy against.


TL;DR

DoD said it suspended Cybersecurity Maturity Model Certification (CMMC) Phase 2 immediately, stopping the third-party certification launch set for Nov. 10 and halting Phases 3 and 4 during a 60-day reform review. Contractors, primes and subs keep Phase 1 self-assessments, with select government-led assessments. Small and mid-sized suppliers get breathing room; the defense industrial base now has an undefined compliance target.

DoD suspends CMMC Phase 2 for 60-day review
Editorial illustration · drawn by The Broadside

DoD has put the Cybersecurity Maturity Model Certification (CMMC) program into its first major retreat. According to NextGov, the department suspended Phase 2 effective immediately, stopping the third-party certification requirement scheduled to begin Nov. 10. DoD also suspended Phase 3, planned for November 2027, and Phase 4 full implementation. Phase 1 self-assessments remain, along with select government-led assessments.

The policy move reverses CMMC’s trajectory. The program began during the first Trump administration and was revised and streamlined during the Biden administration; this pause signals that DoD’s new acquisition leadership is willing to loosen third-party certification pressure to protect supplier count and delivery speed. DoD tied the decision to Secretary Pete Hegseth’s acquisition directives, which prioritize speed and lower barriers for new entrants, and to complaints that CMMC increased costs and administrative burden.

DoD Chief Information Officer Kirsten Davies has formed a CMMC Reform Task Force and opened a request for information, with responses due Aug. 14. The department wants feedback on cost drivers, administrative burdens, which NIST SP 800-171 controls provide meaningful risk reduction, how companies already use commercial cybersecurity tools and managed services, and how DoD might recognize those approaches inside a compliance framework instead of requiring separate assessments.

For primes and subs, the instruction is straightforward: keep Phase 1 self-assessments current, preserve certification evidence already assembled, and watch contract language until DoD answers the open questions. The department has not said whether Phase 2 requirements will be eliminated, modified, or reinstated after the 60-day review. It also has not said how third-party assessments already underway will be treated, or what cyber baseline would replace CMMC if Phase 2 does not resume.


Published ·Deep Fathom