news.mlab.sh
Back to the feed
policy

Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules

Info
Summary

The Pentagon is delaying the second phase of the Cybersecurity Maturity Model Certification (CMMC) program, intended to streamline contractor cybersecurity rules and address a shortage of qualified third-party assessors. This pause aims to avoid hindering smaller businesses from participating in defense contracts, while still prioritizing robust cybersecurity across the Department of War.

The Pentagon is postponing the second phase of the Cybersecurity Maturity Model Certification (CMMC) program. This decision, announced on Monday, is driven by a current shortage of approved third-party assessors needed to conduct the required certifications. The CMMC program is designed to verify that companies handling government information meet baseline cybersecurity standards before they can win defense contracts.

Undersecretary of War for Acquisition and Sustainment Michael Duffey explained that the delay is intended to prevent smaller manufacturers from being disadvantaged by the compliance costs associated with CMMC. The CMMC program has evolved over time, initially consisting of five levels, which has been reduced to three: Level 1 focuses on protecting Federal Contract Information (FCI), Level 2 covers Controlled Unclassified Information (CUI) based on NIST 800-171, and Level 3 concentrates on critical CUI against advanced persistent threats.

The program’s phased rollout began on November 10, 2025, with phase one requiring Level 1 and Level 2 self-assessments. The second phase, originally scheduled to begin on November 10, 2026, would have involved Level 2 third-party certification assessments for new contracts. Phase three, slated for November 2027, would introduce Level 3 certification requirements, and the final phase would bring full implementation across applicable contracts by 2028.

Related: UK Government Rolls Out Agentic AI Defense Plan Alongside Industry Pledge

Related: CISA Reportedly Using Anthropic’s Mythos to Scan Government Software for Flaws

Related: White House Issues Memo to Bolster NSS Cybersecurity

Read the full article at SecurityWeek