Pentagon Suspends CMMC Phase Two Requirements, Launches Review of Program (2026)

The Pentagon's decision to suspend the Cybersecurity Maturity Model Certification (CMMC) phase two requirements and launch a comprehensive review of the program has sparked a new chapter in the ongoing saga of contractor cyber compliance. This move, announced on July 13, 2026, raises critical questions about the future of the CMMC regime and its impact on the Defense Industrial Base (DIB).

The CMMC Conundrum

The CMMC program, designed to enhance cybersecurity through third-party assessments, has faced significant challenges. While the intent is noble, the practical implementation has proven to be a bureaucratic nightmare, particularly for small and non-traditional businesses. The program's requirements, as currently structured, impose a heavy burden on these entities, threatening to exclude them from DoD contracts.

A Step Towards Reform

The suspension of phase two requirements and the launch of a 60-day review by the CMMC Reform Task Force is a bold move by DoD Chief Information Officer Kirsten Davies. Davies' memo highlights the conflict between the CMMC program and Defense Secretary Pete Hegseth's Acquisition Transformation System initiative, which aims to eliminate bureaucracy and foster innovation. Personally, I believe this is a crucial step towards addressing the concerns raised by the Small Business Administration (SBA) and other stakeholders.

Implications and Challenges

The suspension of phase two requirements will provide some relief to contractors, especially small businesses, by temporarily halting the third-party assessment process. However, it also creates uncertainty. With all pending and future CMMC milestones suspended, the question arises: what happens next? How will the DoD ensure cybersecurity without the third-party assessments? Davies' focus on "tangible cyber hygiene" suggests a shift towards a more practical and scalable approach, but the details remain unclear.

A Deeper Dive

The CMMC program's evolution over the years is a fascinating case study in government policy-making. From its inception during the first Trump administration to the Biden administration's pause and subsequent rulemaking process, the program has been a rollercoaster. The departure of key architects like Katie Arrington and Stacey Bostjanick, coupled with the arrival of a new DoD CIO, Kirsten Davies, adds an interesting layer to the narrative. Davies' commitment to reviewing the program and her background in the private sector bring a fresh perspective to the table.

Looking Ahead

The future of the CMMC program is uncertain, but the suspension and review offer an opportunity for a much-needed course correction. The challenge lies in finding a balance between robust cybersecurity measures and an accessible, innovative defense industrial base. As we await the recommendations of the CMMC Reform Task Force, one thing is clear: the DoD is taking a critical step towards addressing the concerns of small businesses and ensuring a more resilient supply chain.

In my opinion, this is a pivotal moment for the CMMC program, and the outcome will have far-reaching implications for the defense industry and national security.

Pentagon Suspends CMMC Phase Two Requirements, Launches Review of Program (2026)
Top Articles
Latest Posts
Recommended Articles
Article information

Author: Msgr. Refugio Daniel

Last Updated:

Views: 5731

Rating: 4.3 / 5 (54 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Msgr. Refugio Daniel

Birthday: 1999-09-15

Address: 8416 Beatty Center, Derekfort, VA 72092-0500

Phone: +6838967160603

Job: Mining Executive

Hobby: Woodworking, Knitting, Fishing, Coffee roasting, Kayaking, Horseback riding, Kite flying

Introduction: My name is Msgr. Refugio Daniel, I am a fine, precious, encouraging, calm, glamorous, vivacious, friendly person who loves writing and wants to share my knowledge and understanding with you.