Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Pentagon Suspends CMMC Phase 2, Kills Third-Party Cyber Audits for Defense Contractors

The Pentagon just gutted its own cybersecurity audit program. Not because cybersecurity stopped mattering, but because the paperwork got so expensive it was chasing small defense contractors out of the business entirely.
Defense Department Chief Information Officer Kirsten Davies announced Monday, July 13, that the Cybersecurity Maturity Model Certification program's Phase 2 requirements are suspended immediately, according to Defense One, Breaking Defense, and National Defense Magazine. Phase 2 was supposed to kick in November 10, 2026, and would have forced companies handling controlled unclassified information to get certified by outside third-party assessors. That's dead for now.
Phase 1 stays. Companies still have to self-assess how they protect sensitive data. But the third-party audit layer, the part that actually costs real money, is on ice.
Why the Pentagon pulled the plug
The Small Business Administration found that CMMC compliance costs were driving innovative companies out of the defense industrial base, according to a Defense Department release cited by National Defense Magazine and the Department of War's own announcement. That's the trigger. If small and mid-size defense suppliers can't afford the compliance overhead, they walk away, and the Pentagon loses access to their technology.
DefenseScoop's Brandi Vincent and Mikayla Easley reported CIO Davies put it bluntly to reporters: the math on requiring expensive third-party audits "just simply doesn't math" when the goal is expanding the industrial base, not shrinking it.
Under Secretary of Defense for Acquisition and Sustainment Michael Duffey didn't soften it either. "What is changing? Let me be direct. We are halting complex audits. We are stopping the requirement for third-party assessors and audits," Duffey told reporters, according to Breaking Defense.
This is happening inside Defense Secretary Pete Hegseth's broader Acquisition Transformation System, which prioritizes speed and lowering barriers to entry for smaller, non-traditional contractors. CMMC reform is one piece of that push.
The real tension
CMMC exists because America's enemies, China chief among them, have spent years hacking defense contractors to steal weapons designs and sensitive data. The program was built in 2019 under the first Trump administration specifically because the "weakest link" problem is real: a small subcontractor with lousy cybersecurity can be the backdoor into a major weapons program.
That's a legitimate concern, and it doesn't disappear because Phase 2 got suspended. If a mid-tier machine shop supplying parts for a fighter jet program gets breached because nobody verified its cyber controls independently, that's not a hypothetical. Chinese state-linked hackers have targeted the defense supply chain before, and self-assessment alone means companies are grading their own homework.
Davies pushed back on the idea that this is a security giveaway. "Every dollar spent on security is a wise dollar spent," she told DefenseScoop, insisting that companies who already invested in third-party assessments didn't waste their money and that Phase 1 self-assessments, plus "select government-led assessments," will hold the line in the meantime.
Whether self-assessment plus occasional government spot-checks is actually equivalent to independent third-party verification is an open question. The Pentagon hasn't published data yet showing self-assessments catch what third-party audits catch. The 60-day review is supposed to figure that out.
What happens next
DOD is standing up a CMMC Reform Task Force, effective immediately, pulling in representatives from the CIO's office, Acquisition and Sustainment, Research and Engineering, Legal, Legislative Affairs, and Public Affairs, according to DefenseScoop. The department also posted a new Request for Information asking contractors which NIST 800-171 security controls actually reduce risk versus which ones just generate paperwork, and how commercial cybersecurity tools might substitute for government-mandated audits.
The task force has 60 days to deliver findings and recommendations to the DOD CIO. Phase 3, originally set for November 2027, and Phase 4 full implementation are suspended too, pending that review.
For contractors who already spent money getting third-party certified ahead of the November 2026 deadline, Davies says that investment wasn't wasted. But for the ones who held off, this buys time, and possibly means a cheaper, lighter-touch version of CMMC replaces the one that was six months from taking effect. The unresolved question is whether "self-assessments and select government-led assessments" close the same security gaps third-party audits were built to catch, or whether the Pentagon is betting speed against risk and hoping it doesn't lose that bet to a foreign intelligence service.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.