← GOVCON NEWS

CMMC Phase II Is Suspended — a Reprieve for Small Defense Contractors

The Pentagon paused the next phase of its cybersecurity certification mandate after SBA pushback over compliance costs. Here's what's paused, what isn't, and how to use the breathing room.

What happened

On July 13, the SBA’s Office of Advocacy announced that the Department of War has agreed to suspend Phase II of the Cybersecurity Maturity Model Certification (CMMC) program and run a comprehensive review of its costs and regulatory burden.

Quick refresher: CMMC is the Pentagon’s system for verifying that contractors handling federal contract information and controlled unclassified information (CUI) actually meet cybersecurity requirements. Phase II is the stage where third-party assessments (paid audits by certified assessors, called C3PAOs) started becoming a condition of award for many defense contracts — instead of companies just self-attesting.

Those third-party assessments are the expensive part. For a small shop, getting assessment-ready plus the audit itself routinely runs into six figures once you count consultants, tooling, and remediation. That cost burden on small businesses is exactly what the SBA’s Office of Advocacy pushed on, and why it’s calling the suspension a pivotal win for small defense contractors.

Why it matters to you

If you sell to the Pentagon — or subcontract under someone who does — the immediate practical effects:

  • Near-term solicitations are less likely to require a completed third-party CMMC assessment as a condition of award while the review runs.
  • Your compliance timeline just got longer, which matters if you were staring down a five-to-six-figure assessment bill you couldn’t schedule until 2027 anyway (assessor capacity has been a real bottleneck).
  • Primes may relax flow-down pressure on subs to produce certification dates — but don’t count on every prime updating its teaming paperwork quickly.

What this is not

This is not a repeal of cybersecurity requirements. The underlying rules still stand: if you handle CUI, NIST SP 800-171 compliance is still in your contracts through DFARS 252.204-7012, and self-assessment score reporting into SPRS is still required. False cybersecurity claims remain a favorite target of Department of Justice enforcement under the Civil Cyber-Fraud Initiative.

What to do about it

  1. Don’t stop your security work — keep closing out your 800-171 gaps and keep your SPRS score current and honest. The requirements that survive any review will be built on that same baseline.
  2. Pause big-ticket assessment spending if you haven’t signed yet. Scheduling a C3PAO audit right now, before the review concludes, may be paying for something whose rules are about to change.
  3. Check your active proposals and teaming agreements for CMMC certification commitments and align them with the new reality.
  4. Watch the review’s outcome. A cost-focused review invites comment opportunities — that’s where small-business voices actually moved the needle this time.

PUT THE NEWS TO WORK

See what it means for your pipeline.

GovCon ONE turns live federal notices into evidence-backed bid decisions.

Start free