What the CMMC Pause Means for the Defense Industrial Base

On July 13, 2026, the Department of Defense (DOD) suspended the second implementation phase of the Cybersecurity Maturity Model Certification (CMMC) program. Phase II was scheduled to take effect on November 10 and would have required contractors handling controlled unclassified information (CUI)—sensitive government information that is not classified but cannot be made public—to obtain an assessment from an accredited certified third-party assessment organization (C3PAO). The department also announced a 60-day review of the program’s future. The impact of CMMC on small businesses was the principal reason for the pause; in separate releases, Small Business Administration (SBA) Administrator Kelly Loeffler called the program an “untenable barrier,” while Under Secretary of War for Acquisition and Sustainment Michael Duffey cited its “paralyzing costs” and described the suspension as part of a broader effort to cut red tape. Critics have argued that CMMC risks shutting small suppliers out of the defense market by imposing excessive compliance costs, although some conflate the cost of an outside assessment with the more significant cost of actually meeting the cybersecurity standards.

Q1: How did CMMC come about?

A1: Since 2017, defense contractors handling CUI have been required to follow standards developed by the National Institute of Standards and Technology (NIST). These protocols, outlined in NIST SP 800-171.3, cover areas including personnel training, two-factor authentication, and risk-monitoring procedures.

Such protections have become increasingly important as defense contractors face state-sponsored efforts to obtain sensitive military and technological information through phishing, exploitation of software misconfigurations, and other means. Because even small suppliers may hold critical data or connect to larger defense networks, a weakness at one company can create risk throughout the supply chain.

For eight years, the government largely relied on contractors to report their own compliance. Oversight remained thin, and audits found serious weaknesses. A 2022 DOD inspector general review of 10 research contractors found all in violation of NIST standards.

The Pentagon developed the CMMC not to replace NIST standards but to create a framework for implementation, assessment, and enforcement. The first version of CMMC, announced in 2019, drew criticism for its cost and complexity. CMMC 2.0, finalized in 2024, reduced the number of certification levels, expanded the use of self-assessments, and reserved outside reviews for contractors handling more sensitive information.

CMMC has three levels of cybersecurity requirements for companies doing business with the DOD. Level 1 applies to contractors handling Federal Contract Information and requires the implementation of basic cyber hygiene practices outlined in Federal Acquisition Regulation clause 52.204-21. The DOD expected that most small businesses would only require CMMC Level 1 certification because they largely do not handle CUI. Level 2 applies to organizations that process, store, or transmit CUI and requires compliance with the security requirements in NIST SP 800-171.3. Level 3 is intended for contractors supporting high-priority defense programs facing sophisticated cyber threats. It mandates additional security controls derived from NIST SP 800-172.3 and a government-led assessment to demonstrate enhanced resilience against advanced persistent threats.

Q2: What was the CMMC implementation plan?

A2: The Pentagon planned to roll out CMMC in four phases.

Phase I began on November 10, 2025, when the DOD began phasing CMMC requirements into defense procurement. Contractors could meet these new requirements through self-assessments.

Phase II, scheduled for November 2026, would mark the major shift. Many contractors handling CUI would need an assessment from a C3PAO before they could compete for covered contracts. This review would examine company policies and technical records, interview employees, and test selected security measures to determine whether the contractor had actually implemented the required controls, rather than relying solely on self-attestation. Certifications would generally last three years.

Phase III, scheduled for November 2027, would have introduced Level 3 reviews. Phase IV, scheduled for November 2028, would have applied CMMC across all covered solicitations, contracts, and option periods.

The phased schedule was intended to give contractors time to prepare and allow the assessment industry to grow. By late 2025, however, the system had only 92 approved assessment organizations and 633 certified assessors. The Government Accountability Office (GAO) warned that the Pentagon had not shown whether this workforce could meet demand.

Q3: What implementation challenges did CMMC face, particularly with small businesses?

A3: The principal reason for the CMMC pause was the perceived impact on small businesses. Small contractors faced three primary compliance costs: the cost of the CMMC assessment, the cost of preparing evidence for it, and the cost of fixing security weaknesses that should already have been addressed.

While CMMC Level 1 requirements were intended to be sufficient for most small businesses, prime contractors and government solicitations have increasingly put CMMC Level 2 requirements on small business subcontractors even when their work does not presently require access to CUI. Uncertainty about whether CUI might later be shared has caused primes to adopt a very broad compliance scope.

The compliance risk for primes is real, however, so the flowing down of Level 2 CMMC requirements could be viewed as an insurance or risk mitigation policy. Some DOD program offices, meanwhile, have started putting CMMC Level 2 assessment requirements in solicitations this year.

The Pentagon estimated that an initial Level 2 third-party assessment and affirmation would cost a small company approximately $102,000, including roughly $31,000 paid to the assessment organization, along with the contractor’s preparation, documentation, and participation time. However, these estimates assume the underlying NIST security controls are already implemented—not unreasonably, as contractors handling CUI have been required to implement those controls since 2017. The Pentagon therefore excluded the cost of buying new systems, hiring security staff, and bringing a deficient network into compliance. Such remediation can be more expensive than the assessment itself. A contractor may need to invest in new databases, login tools, network segmentation, encryption, or a separate CUI environment, followed by recurring expenses for licenses, cloud hosting, monitoring, patching, managed services, training, and cybersecurity personnel. The SBA estimates that total costs can reach about $594,000.

Another controversy concerns reimbursement. During the rulemaking process, industry commenters asked the Pentagon to state that reassessment and recertification expenses would be reimbursable. The Pentagon declined. This suggests that while contractors with cost-reimbursement contracts may be able to charge allowable cybersecurity costs to the government, fixed-price contractors must include expected CMMC expenses in future bids.

That distinction creates a cash-flow problem for small firms. A contractor might cover compliance expenses in several ways: charge costs directly to a contract; allocate shared cybersecurity systems, personnel, and consulting expenses through overhead; or incorporate an estimated share into the price of future fixed-price bids. Even reimbursed costs must be documented, scrutinized, and permitted by the contract.

Non-reimbursability may also create competition problems. A company seeking its first defense award may have to finance new systems, training, and an assessment before it can compete, giving incumbents with already compliant networks an asymmetric advantage.

Despite these challenges, small business status does not reduce the national security damage of stolen weapons data, production information, or software. The Pentagon has a strong reason to seek evidence beyond a company’s own assurance that its systems are secure.

Q4: What exactly did the Pentagon pause, and why did it act now?

A4: The pause delays the move from self-assessment to widespread independent certification. It also suspended future milestones and required the removal of C3PAO requirements from active solicitations during the review. During the review, contractors may continue to self-assess and must still protect CUI, submit required self-assessments, and undergo select government spot-checks.

The pause followed months of discussions with Pentagon officials and small business groups. Phase II implementation might have necessitated the issuance of a large number of waivers to avoid disrupting ongoing Pentagon procurement programs. However, the GAO has warned that the Pentagon had only partly addressed the external risks posed by assessor shortages and that relying on waivers to manage them would undermine the program’s core purpose.

The timing also reflects a broader Pentagon push to speed up defense acquisition and attract commercial and nontraditional suppliers, with Under Secretary Duffey citing a “strategic imperative to reduce bureaucracy” in the suspension announcement.

Q5: What happens next, and how can the government address small business concerns?

A5: The DOD’s chief information officer has established a CMMC Reform Task Force and issued an industry request for information to evaluate compliance challenges and develop new security measures optimized for rapid adoption and minimal barriers to entry. The task force held its first meeting on July 16 and announced plans to issue a public report at the conclusion of a 60-day review period.

The clearest path to address small business concerns would be to create or expand loan or grant programs to help address the upfront CMMC certification costs. For instance, the SBA could establish a program to offer 10-year loans for eligible small business contractors to offset one-time expenses associated with CMMC compliance. Repayment could be integrated over time into contract rates, or loan forgiveness could be tied to performance targets.

Several states have created grants or cost-sharing programs to reduce the cost of CMMC readiness for small manufacturers and defense suppliers. Connecticut’s Cybersecurity Adoption Program, Massachusetts’s Manufacturing Cybersecurity Program, and Oregon’s Advanced Manufacturing Federal Contract Competitiveness Funding all list CMMC compliance as eligible for grants. Such programs could be expanded, emulated by other states, or replicated at a federal level.

Other policy choices can also affect the size of the burden. Excessive designation of data as CUI can pull unnecessary systems and employees into the assessment boundary. The DOD could refine how it defines the systems covered by an assessment. Primes could be discouraged from unnecessarily flowing down CMMC Level 2 requirements to firms for which Level 1 would be appropriate. The DOD could also set clearer standards about the eligibility of CMMC costs for reimbursement.

While CMMC’s rollout has been heavily criticized, the underlying need for cybersecurity enhancement in the defense sector is widely acknowledged and growing. To meet this strategic necessity, CMMC—in one form or another—will happen. The open questions are how and when. The current pause gives the DOD and SBA an opportunity to adequately address the small business compliance concerns that have been repeatedly raised and put CMMC on a path toward successful implementation.

Jerry McGinn is the director of the Center for the Industrial Base and a senior fellow with the Defense and Security Department at the Center for Strategic and International Studies (CSIS) in Washington, D.C. Oliver Buntin is a research assistant in the Center for the Industrial Base at CSIS.

Image
Jerry McGinn
Director, Center for the Industrial Base and Senior Fellow, Defense and Security Department

Oliver Buntin

Research Assistant, Center for the Industrial Base