Pentagon suspends CMMC Phase II requirements for defense contractors
The U.S. Department of Defense announced an immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements that were slated to take effect in November. The decision, explained by Pentagon CIO Kirsten Davies, aims to ease “significant and often prohibitive burdens” on small and non‑traditional firms in the Defense Industrial Base that develop innovative technologies.
Under the suspension, complex audits, third‑party assessors and the Phase II milestones in current solicitations are being halted. Program managers and contracting officers have been directed to amend or remove the suspended requirements from active contracts. Phase I self‑assessment requirements remain in force, preserving a basic cybersecurity baseline.
DoD officials, including Undersecretary Michael Duffey, said the move is intended to reduce red tape without lowering security standards, and a 60‑day review of the CMMC program will be launched to align it with the department’s acquisition transformation goals and to keep innovative suppliers from exiting the defense supply chain.