cmmctrade-pressNewsThe Broadside3 min read

DoD suspends CMMC third-party assessments indefinitely

Small-business cost pressure has stopped the verification model DoD built after deciding self-attestation was failing.


TL;DR

Federal News Network reports that DoD has suspended Cybersecurity Maturity Model Certification (CMMC) third-party assessment requirements indefinitely and opened a 60-day program review, with recommendations expected by late September. Primes and subcontractors face frozen certification pathways, while CMMC Third-Party Assessment Organizations (C3PAOs) lose near-term assessment revenue. DoD is reopening the verification model it built because contractor self-attestation did not work.

DoD suspends CMMC third-party assessments indefinitely
Editorial illustration · drawn by The Broadside

Federal News Network reports that DoD has suspended Cybersecurity Maturity Model Certification (CMMC) third-party assessment requirements indefinitely and opened a 60-day “top-to-bottom” review, with recommendations expected by late September. Officials also plan listening sessions for defense contractors, small businesses, cybersecurity operators, Cyber AB and assessors. This is CMMC’s first broad halt of third-party assessment requirements, after a rollout that had finally begun moving from rulemaking into contract pressure.

DoD Chief Information Officer Kirsten Davies tied the pause to small-business costs, saying Small Business Administration reports showed the planned compliance progression created “prohibitive costs and unacceptable burdens” for the defense industrial base. She also called CMMC assessments a “burdensome, red-tape ridden, check-the-box, point-in-time view” of a company’s handling of sensitive data. That is more than routine program review language. It is DoD publicly questioning the mechanism it spent years assembling.

What stops now

Under Secretary of Defense for Acquisition and Sustainment Michael Duffey issued a memo directing program officers to remove CMMC third-party certification requirements from active solicitations, Federal News Network reported. Those requirements had been on track to become standard in many defense contracts starting Nov. 10. Voluntary Level 2 assessments had already gained momentum, and Cyber AB says nearly 2,000 defense contractors have been certified at Level 2. Those certifications remain. The market signal behind the next wave of assessments has changed.

What still binds contractors

DoD says CMMC self-assessments remain in force, and the department is not changing the underlying requirements to secure controlled unclassified information (CUI) under National Institute of Standards and Technology controls. Davies pointed to Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) reviews and services from the National Security Agency’s Cybersecurity Directorate and the DoD Cyber Crime Center. Federal News Network reported that those services cover only a small portion of the required NIST controls. That matters because DoD stood up Cyber AB and CMMC Third-Party Assessment Organizations (C3PAOs) because the government lacked capacity to audit tens of thousands of defense contractors itself.

The review’s real question is whether third-party assessments survive as a mandatory gate, become one input among self-scoring and DIBCAC reviews, or get replaced by some cheaper cost-sharing structure for smaller vendors. If DoD leans harder on self-assessments, it moves back toward the system CMMC was designed to fix. The immediate savings for small businesses may be real. So is the legal exposure. Kate Growley of Crowell & Moring told Federal News Network that reliance on contractor self-assessment creates False Claims Act risk when companies misrepresent their scores.

For primes and subcontractors, the Monday instruction is dull and important: keep implementing the controls. Existing obligations still matter, self-assessment scores still travel into procurement, and bad representations can become enforcement evidence later. For C3PAOs and Cyber AB, the pause cuts near-term assessment revenue and leaves standards in flux until the review lands. For contracting officers, the uncomfortable part is procedural. They have to strip assessment language now while waiting to learn whether September’s recommendations will be binding direction, advisory cover, or the start of another CMMC rewrite.


Published ·Deep Fathom