
Defense Department officials have paused CMMC Phase II, stopping a costly third-party certification step that had been set to hit defense contractors this fall.
Quick Take
- The Department of War suspended CMMC Phase II requirements immediately.
- Phase I self-assessment rules stay in place.
- Officials tied the pause to cost, red tape, and barriers for smaller firms.
- The department launched a 60-day review of the program.
Why the Pentagon Hit Pause
The Department of War said the current CMMC program has created “prohibitive compliance costs and bureaucratic burdens,” especially for smaller and non-traditional suppliers. The pause affects Phase II, which had been scheduled to start on November 10, 2026, and would have pushed more contractors into third-party cybersecurity assessments. Officials said the review is meant to improve speed, cut barriers, and protect the defense industrial base.
The move fits a larger conservative concern: federal rules often swell until they squeeze out the very businesses that keep the supply chain alive. The department said it will keep Phase I self-assessments in place, so this is not a surrender on cybersecurity. It is a reset of the timing and the burden. That matters for small firms that were staring at high costs and a tight deadline.
What Changes for Contractors Now
Under the suspension, contractors are not being forced into the Phase II third-party certification step on the original timeline. The department said it will continue enforcing baseline compliance through self-assessments and select government-led assessments during the review period. That means the government is still watching cyber hygiene, but it is stepping back from the broad new certification requirement that many vendors feared would become a gatekeeper.
The government has not dropped the underlying cybersecurity standards, and that point is important. Reporting on the pause says obligations tied to National Institute of Standards and Technology Special Publication 800-171 revision 2 and Defense Federal Acquisition Regulation Supplement 252.204-7012 remain in place. In plain terms, the rules on paper still matter, but the most burdensome certification trigger has been put on hold while officials rethink the rollout.
Why Small Businesses Welcomed the Shift
The Small Business Administration praised the suspension and said small contractors had warned for months that the framework imposed heavy bureaucratic costs. The agency said those pressures were pushing firms to leave or consider leaving defense work, which would weaken the supply base instead of strengthening it. That warning lines up with the department’s own stated concern that compliance can choke off innovation if the process becomes too expensive or too slow.
The CMMC Phase II pause is real.
It is not a reset button.
If your SPRS score, SSP, POA&M, or affirmation is unsupported, the C3PAO calendar was not the only problem.
The problem is signing a story the company cannot prove.
— Trawvid Sec (@TrawvidSec) July 25, 2026
Officials also tied the review to broader acquisition goals, including faster delivery and lower barriers for small, medium, and non-traditional businesses. For readers who are tired of Washington making everything more expensive, that is the key point. The Pentagon is not just changing a deadline. It is admitting that the old plan risked turning cybersecurity compliance into another expensive federal hurdle for the firms the military needs most.
What the Review Could Mean Next
The department said the review will last 60 days, and it may reshape how CMMC Phase II is carried out. Published guidance and outside analysis say the pause covers pending and future implementation milestones, not the entire cybersecurity program. That leaves open the possibility of a narrower, more practical system that still protects sensitive data without punishing smaller suppliers with a one-size-fits-all rush to certification.
That is where the story now sits. The Defense Department has paused a major compliance step, kept the basic security rules alive, and signaled that cost and capacity matter when federal policy reaches deep into private industry. For defense contractors, the next 60 days will show whether Washington finally trims the red tape or simply repackages it with a new label.
Sources:
military.com, business.defense.gov, crowell.com, dentons.com, youtube.com















