READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Pentagon Suspends CMMC Cyber Audits for Contractors, But Compliance Rules Still Apply

Pentagon Suspends CMMC Cyber Audits for Contractors, But Compliance Rules Still Apply
On July 13, the Department of War hit pause on the third-party cybersecurity audits it was set to require of defense contractors starting November 10. Contractors still have to follow the underlying rules and self-certify, but nobody outside the company is checking their work right now, and the two-month task force review promised to fix that has just started.

Since the Department of War announced on July 13 that it would suspend Phase II of the Cybersecurity Maturity Model Certification program, the defense contracting world has been trying to figure out what's actually still required versus what got shelved.

The paperwork obligations stayed. The referee left the field.

What got paused

CMMC Phase II required contractors to bring in outside auditors, called C3PAOs, to verify they meet the government's 110-point cybersecurity checklist before handling controlled unclassified information. That third-party check was supposed to kick in November 10, 2026, according to Reed Smith. It's now suspended, along with Phase III's more intensive DIBCAC assessments for higher-level contracts.

Secretary of War Pete Hegseth's office ordered the pause under his Acquisition Transformation System directives, which are aimed at cutting red tape and making it easier for smaller, non-traditional companies to work with the Pentagon, according to Reed Smith. The Small Business Administration flagged CMMC compliance costs as a barrier keeping innovative firms out of the defense industrial base entirely.

Magna5, a Pittsburgh-based IT and cybersecurity firm that works with defense contractors, says small businesses have warned compliance costs could run into the hundreds of thousands of dollars, and the SBA identified CMMC as a top nationwide concern for the sector. With more than 100,000 companies in the defense industrial base needing eventual assessment and a limited pool of approved third-party assessors, the system was genuinely bottlenecked.

What did not get paused

The underlying cybersecurity standards, NIST SP 800-171 Rev 2, are untouched. Contractors still have to comply with those 110 requirements, still have to submit accurate self-assessments, and still have to report cyber incidents under DFARS 252.204-7012, according to Reed Smith. Where DFARS 252.204-7020 assessment language is baked into a contract, that stays too.

Companies are still on the hook to grade their own homework. Nobody from outside the company is checking the grading anymore, at least for now.

The oversight gap, according to the people who built CMMC

Katie Arrington, widely credited as the architect of CMMC, said in a video posted to LinkedIn that the pause "shouldn't be a shocker to anybody" and predicted the Pentagon will eventually land back where it started, because there's "no other way to get compliance," according to Breaking Defense.

Jacob Horne, Chief Cybersecurity Evangelist at Summit 7, put the underlying problem more bluntly. The Defense Department's Inspector General flagged the same issue seven years ago: letting contractors grade their own homework doesn't work, because there's no way to verify the self-assessment is accurate, Horne told Breaking Defense.

Michael Brooks, a lead CMMC Certified Assessor at A-LIGN, said the lack of third-party validation increases uncertainty for program offices and prime contractors, and raises the odds that a company's cybersecurity claims turn out to be false when nobody checked them, which opens the door to False Claims Act liability down the road, according to Breaking Defense.

The government is now trusting written assertions from contractors handling sensitive defense data, with no outside check, at the exact moment adversary hacking of the defense industrial base is a live concern. If a contractor's network gets breached and it turns out their self-assessment was fiction, the government finds out after the fact, not before.

The counter-argument, made by Magna5's Bill Osborne, is that cost wasn't really the core issue. "The biggest challenge has not been the cost of an assessment, it has been readiness," Osborne said, adding that many contractors underestimated the documentation and operational discipline NIST SP 800-171 actually demands. Osborne also noted that many approved assessors have had open capacity for months, suggesting the "assessor shortage" excuse doesn't fully hold up.

What happens next

DoW Chief Information Officer Kirsten A. Davies is running a newly formed CMMC Reform Task Force, which is expected to deliver findings to the CIO within 60 days of the July 13 pause, putting a report roughly due by mid-September, according to Reed Smith. A public request for information is coming to collect industry feedback before then.

Until that review wraps, contractors are stuck in a gray zone: still legally bound to the same cybersecurity standards, still required to self-report through the Supplier Performance Risk System, but with zero independent verification standing behind any of it. Magna5 is telling clients to treat the pause as a planning window, not a reprieve, warning that companies who let compliance work lapse now risk scrambling if a revised, tougher CMMC rule lands in the fall.

The open question is whether the Reform Task Force actually simplifies the underlying 110-requirement standard, or just changes who checks compliance and how often. Nothing announced so far touches NIST SP 800-171 itself.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
Breaking DefenseCMMC may be paused, but cybersecurity audits likely to return: Industry, experts
unknown
reedsmithCMMC pause: DoW halts certification rollout – but cyber obligations remain
unknown
prnewswireThe CMMC Pause is Not a Pass: What Defense Contractors Should Do Now