Skip to main content
How DoD Suspended CMMC Phase 2 and What It Means for Your ProgramRegulatory Compliance
3 min readFor GRC Professionals

How DoD Suspended CMMC Phase 2 and What It Means for Your Program

The Challenge

On July 13, 2026, the Department of Defense admitted a flaw in its compliance mechanism by suspending CMMC Phase 2. This wasn't a retreat from security; all DFARS clauses, NIST SP 800-171 requirements, and incident-reporting obligations remained. What changed was the need to pay a third-party assessor for certification.

The economics were clear. The Small Business Administration estimated CMMC Level 2 certification could cost a small firm nearly $593,800, often exceeding the annual profit of a 40-person subcontractor. The rational response was to abandon the contract.

The Pentagon saw small firms leaving the Defense Industrial Base, realizing the structure was pricing out the innovation pipeline it relies on. The issue wasn't enforcing security standards but whether the delivery mechanism had become the barrier.

The Environment and Constraints

Three cost centers drove the problem: licensing, assessment, and control implementation.

Licensing was a burden, especially for Microsoft-dependent shops. Handling Controlled Unclassified Information (CUI) in email meant switching from commercial Microsoft 365 to GCC High, a government-grade tenant costing 40% to 70% more per seat.

Assessment was another bottleneck. Fewer than 100 CMMC Third-Party Assessment Organizations (C3PAOs) served tens of thousands of contractors. Fees ranged from $30,000 to $75,000, with long wait times.

Control implementation added costs: MFA, endpoint detection, logging, backups, and tools to satisfy 110 NIST SP 800-171 controls. First-year compliance costs ranged from $50,000 to $200,000 for most small contractors, with high-end estimates nearing $600,000.

For a 750-person enterprise, that's manageable. For a 41-person manufacturer, it's the entire contract.

The Approach Taken

The Pentagon formed a 60-day CMMC Reform Task Force and opened a Request for Information (RFI) to gather industry input on fixing the program. The comment window closed on August 14, 2026.

The approach was to change who pays for expensive parts and who does the work without lowering security standards. Three reforms emerged:

Reform 1: Negotiate affordable Microsoft licensing for CUI. The government would use its scale to negotiate special arrangements so small businesses could access GCC High or an equivalent without the premium. This reform aimed to level the playing field.

Reform 2: Let the government run the assessment. Instead of hiring private assessors, DIBCAC or a dedicated small-business unit would perform assessments. This would eliminate the $30,000, $75,000 fee and long wait times.

Reform 3: Pre-approve security vendors. The government would verify that specific tools map to NIST SP 800-171 controls and publish a vetted list, similar to FedRAMP's approach with cloud services.

Each reform targeted firms with fewer than 250 employees, U.S.-headquartered, primarily U.S. workforce, and a current or near-term contract involving FCI or CUI.

Results and What Comes Next

The suspension of Phase 2 third-party certification requirements is the immediate result. The Task Force is developing alternatives, asking which cost drivers hurt most and how commercial tools might count toward compliance.

The risk isn't abandoning security standards but that reform either doesn't happen or lacks the necessary investment. A government-run assessment only helps if adequately staffed. Licensing negotiations must remain open to equivalent providers to avoid a single-vendor situation. The pre-approved vendor list must be maintained and updated.

Takeaways for Your Team

If you're advising small contractors in the Defense Industrial Base, note these changes:

The compliance timeline is uncertain, but security requirements aren't. DFARS, NIST SP 800-171, and incident reporting remain in force. Don't delay control implementation.

The reform window is real. The RFI sought solutions to cost drivers. If you've built a compliance program, your insights are valuable now.

The economics test your program's defensibility. If compliance costs exceed contract revenue, you're not building security; you're pricing clients out. The reforms aim to fix structural issues but don't excuse ignoring cost-effectiveness.

For GRC professionals, the suspension signals that the delivery mechanism is under scrutiny. The next version will likely differ, but the security bar won't drop. The challenge is making the path to compliance viable for firms without enterprise budgets.

You Might Also Like