Australiancybersecuritymagazine

Department of War suspends CMMC Phase II requirements during review


The U.S. Department of War has announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program, marking a shift in how cybersecurity requirements will be implemented across the Defence Industrial Base (DIB).

The decision pauses the introduction of mandatory third-party CMMC Level 2 certification requirements, originally scheduled to begin on 10 November 2026, while the Department undertakes a review aimed at reducing regulatory burden without compromising cybersecurity. The announcement forms part of Secretary of War Pete Hegseth’s broader Acquisition Transformation System (ATS) reforms intended to strengthen America’s defence industrial capacity.

Department of War Chief Information Officer Kirsten Davies said the Department remains committed to protecting Controlled Unclassified Information (CUI) and strengthening cyber resilience across the industrial base, but acknowledged that the current implementation of CMMC had become overly burdensome.

“In support of Secretary Pete Hegseth’s directive to aggressively scale warfighter readiness, I’m announcing the immediate suspension of the Cybersecurity Maturity Model Certification, or CMMC, Phase II requirements,” Davies said.

“We are not reducing cybersecurity through this measure. We are reducing the red tape.”

Reforming cybersecurity without reducing security

According to the Department of War, the suspension reflects concerns that the current certification model places significant compliance costs on defence contractors—particularly small businesses and non-traditional suppliers that are increasingly important to delivering innovation and capability to the U.S. military.

The Department has established a CMMC Reform Task Force, which will conduct a 60-day review of the certification framework to identify ways of maintaining strong cybersecurity protections while reducing unnecessary administrative complexity.

Officials said the review aligns with Secretary Hegseth’s objective of accelerating acquisition, increasing competition and expanding participation across the Defence Industrial Base.

Existing cybersecurity obligations remain

The Department stressed that the suspension does not reduce existing cybersecurity obligations for defence contractors.

Companies handling Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) must continue complying with existing Defence Federal Acquisition Regulation Supplement (DFARS) cybersecurity clauses, including DFARS 252.204-7012, and maintain implementation of the security controls contained within NIST Special Publication 800-171 Revision 2.

Existing CMMC Phase I self-assessment requirements also remain in force.

During the review period, cybersecurity assurance will continue through contractor self-assessments and government oversight rather than mandatory third-party certification assessments.

Relief for the Defence Industrial Base

The announcement has been welcomed by many organisations representing defence contractors, particularly small and medium-sized enterprises that have expressed concern over the cost and complexity of preparing for independent certification.

The U.S. Small Business Administration praised the Department of War’s decision, noting that many small defence contractors viewed the existing implementation model as an unnecessary barrier to participating in national security programs while remaining committed to strong cybersecurity practices.

Likewise, The Cyber AB—the official accreditation body supporting the CMMC ecosystem—acknowledged the suspension while confirming that assessor accreditation, certification services and ecosystem development will continue during the review period.

Implications for defence contractors

The suspension primarily affects the rollout of mandatory third-party CMMC Level 2 assessments that were expected to become contractual requirements later this year.

Contracting officers have been directed to suspend implementation of Phase II certification requirements in applicable solicitations while the review is completed.

For many organisations, this provides temporary relief from the cost and administrative burden associated with independent certification.

However, cybersecurity expectations remain unchanged.

Defence suppliers are still expected to safeguard Controlled Unclassified Information, maintain compliance with NIST SP 800-171 security controls and meet all existing contractual cybersecurity obligations.

Impact for Australian defence exporters

While CMMC is a U.S. program, the decision has implications across allied defence industries, including Australia.

Many Australian companies supporting U.S. defence programs, AUKUS initiatives and broader Defence Industrial Base supply chains have invested heavily in preparing for CMMC certification.

Although mandatory third-party certification has now been paused, organisations should not interpret the announcement as a weakening of cybersecurity expectations.

The Department of War has made clear that protecting sensitive defence information remains a fundamental requirement. What is changing is the certification process—not the underlying cybersecurity standards.

The outcome of the CMMC Reform Task Force is expected to influence cybersecurity assurance across the broader allied defence community and may shape future approaches to supply chain cybersecurity among AUKUS partners and other trusted defence nations.

For now, the Department of War’s message is clear: cybersecurity remains essential, but the path to demonstrating compliance must become simpler, faster and less burdensome for the companies responsible for delivering capability to the warfighter.





Source link