Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
The Department of War has temporarily paused the mandatory third-party assessment requirement for CMMC Phase 2, citing concerns about the capacity of the assessor ecosystem and the potential for CMMC to price small and medium-sized defense contractors out of the market. Industry experts largely agree that the pause affects only the verification process, not the underlying obligation to protect Controlled Unclassified Information (CUI). However, there are concerns that self-attestation without verification could lead to False Claims Act exposure. The Department of War is reviewing the program and expects to deliver recommendations within 60 days. The key takeaway is that while the pause addresses capacity issues, the fundamental need for robust cybersecurity practices and accurate reporting remains, and a focus on organizational resilience rather than simply ticking boxes is crucial.
The Department of War has suspended the mandatory third-party assessment requirement for CMMC Phase 2, citing concerns that the assessor ecosystem couldn’t scale to meet demand and that compliance costs were pushing small and mid-sized firms out of the defense industrial base. A newly formed CMMC Reform Task Force will spend 60 days reviewing the program, gathering industry feedback, and reporting recommendations by mid-September.
Crucially, the pause only affects independent verification, with Phase 1 self-assessment obligations, SPRS score submissions, and the underlying DFARS 252.204-7012 requirement to protect controlled unclassified information (CUI) remaining fully in effect. Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI, warning that self-attestation without verification raises False Claims Act exposure.
According to sources, including Abdie Mohamed of NR Labs, the issue stems from a mismatch between the number of authorized C3PAOs (around 100) and the estimated number of entities needing Level 2 C3PAO certification (around 76,598). Redspin’s Robert Teague notes that the narrative of a limited number of assessors is inaccurate, highlighting the presence of over 1,000 Certified CMMC Assessors (CCAs) and nearly 2,000 Certified CMMC Professionals (CCPs). However, a significant bottleneck remains: the Tier 3 background investigation required for assessors can take six months or longer, delaying qualified personnel.
Chris Nyhuis, CEO of Vigilant, argues that the DoD’s concerns are valid, as CMMC has already priced many small, fast, innovative shops out of the defense industrial base. He emphasizes that speed and security are now paramount, and that pausing assessments allows for a more streamlined approach. Chetrice Romero, Senior Cybersecurity Advisor at Ice Miller, stresses that CMMC should be viewed as an opportunity to build organizational resilience, rather than simply fulfilling compliance requirements. She advises organizations to focus on their business operations and prioritize the highest risks, rather than simply implementing disconnected controls.
Emil Sayegh, CEO of CyberSheath, clarifies that the DoD’s decision doesn’t repeal existing cybersecurity obligations – NIST SP 800-171, DFARS requirements, and truthful SPRS reporting remain in effect. Ned Butler, Manager, CMMC Services and Lead Assessor at Redspin, points out that the cost of CMMC is often driven by the underlying DFARS 252.204-7012 requirements, and that a more targeted approach – focusing on contractors handling genuinely sensitive CUI – could significantly reduce costs and improve efficiency.
Industry feedback suggests that a more effective solution might involve shrinking the scope of assessments, allowing C3PAOs to scale teams based on assessment scope, and permitting CCPs to fill appropriate assessment roles. Ultimately, the Department of War’s review will determine the future direction of CMMC, with a focus on addressing capacity constraints and ensuring that cybersecurity practices are robust and consistently enforced.