MSC Security
← All posts
CMMC·July 18, 2026·8 min read

Defense Supply Chain Security: Navigating CMMC Adjustments for Small Businesses

The Pentagon has suspended key CMMC requirements for defense contractors, prompting a re-evaluation of the program to balance national security with the viability of small and medium-sized businesses in the Defense Industrial Base.

The U.S. Department of War has recently suspended the implementation of Phase II requirements for the Cybersecurity Maturity Model Certification (CMMC) program. This decision, announced by DoD CIO Kirsten Davies and supported by the U.S. Small Business Administration (SBA), underscores a critical re-evaluation of how best to secure the Defense Industrial Base (DIB) without imposing prohibitive burdens on small and medium-sized enterprises (SMEs).

CMMC: Balancing Security and Business Viability

CMMC is designed to enhance the cybersecurity posture of the DIB, ensuring that contractors handling sensitive federal contract information (FCI) and controlled unclassified information (CUI) meet specific security standards. The program features a tiered model, with different levels of compliance based on the sensitivity of the data handled. Initially, CMMC aimed for a phased rollout, culminating in mandatory third-party assessments for many contractors.

However, concerns quickly mounted regarding the practical implications, particularly for smaller businesses. The SBA, for instance, noted projected compliance costs for small firms could reach nearly $600,000, raising fears of these businesses being excluded from DoD contracts and impacting national security by reducing the pool of viable suppliers.

The Suspension and Its Implications

As of July 13, 2026, the Department of War suspended CMMC Phase II requirements, which were originally slated for full implementation by November 10, 2026. This pause initiates a 60-day review period, as announced by DoD CIO Kirsten Davies, to explore strategies that reduce compliance costs and enhance cybersecurity measures without stifling innovation within the DIB. The existing Phase I self-assessment requirements remain in place.

"This decision aims to reduce bureaucracy while maintaining security standards, supporting small and medium businesses in the defense supply chain." - U.S. Department of War

This move aligns with Secretary of War Pete Hegseth's Acquisition Transformation System (ATS), which seeks to reduce barriers for small to medium-sized enterprises and shift towards more scalable cybersecurity measures. A CMMC Reform Task Force will be formed to gather industry feedback and recommend practical cybersecurity strategies.

What Remains in Effect:

  • Phase I Self-Assessments: Contractors are still required to conduct annual self-assessments for CMMC Level 1, focusing on 15 security requirements. These assessments, and their results, must be submitted to the DoD's Supplier Performance Risk System (SPRS).
  • Protection of FCI and CUI: The fundamental obligation for contractors to protect federal data, specifically FCI and CUI, remains paramount.
  • Limited POA&Ms: Plans of Action and Milestones (POA&Ms) are permitted for deficiencies, though with stricter regulations for Level 1 requirements.

Why the Change? Addressing DIB Concerns

The driving force behind this suspension is a recognition of the significant challenges CMMC, in its initial form, posed to the DIB. The program's goals, while noble, generated substantial friction:

  1. High Compliance Costs: Small businesses, often operating with limited resources, found the projected costs of achieving and maintaining CMMC certification to be a major obstacle. This could lead to a reduction in competition and innovation within the defense supply chain.
  2. Bureaucratic Burden: The initial implementation was perceived as overly complex and bureaucratic, potentially hindering agile innovation crucial for national defense.
  3. Risk to Supply Chain Diversity: The SBA specifically highlighted that costly compliance burdens threatened the participation of small contractors, putting critical suppliers at risk and weakening the overall defense readiness.

The Department of War's focus is to balance these concerns with the imperative of robust cybersecurity. The review process will seek to refine the program to be more adaptable and less restrictive for businesses, while ensuring critical data protection.

What This Means for Defense Contractors

For defense contractors, particularly SMEs, this period represents both a reprieve and an opportunity. While the immediate pressure of external CMMC audits for Phase II is lifted, the underlying need for strong cybersecurity remains. The Department of War is actively seeking input to shape the program's future, highlighting the importance of current compliance with Phase I requirements.

Resources like Project Spectrum, detailed on the business.defense.gov website, continue to offer cybersecurity training and compliance support, emphasizing the ongoing commitment to bolstering the DIB's security posture.

Moving Forward: A Focus on Practical Security

The suspension of CMMC Phase II signals a strategic pivot by the Department of War toward a more pragmatic and scalable approach to cybersecurity within the DIB. This involves a commitment to reducing regulatory burdens without compromising the foundational requirement to protect sensitive government information.

For MSC Security, these developments underscore the enduring need for robust cybersecurity and compliance management tailored to regulated sectors like the defense industrial base. Our services, including Managed Detection & Response, AI Security, and Compliance Management (CMMC, FedRAMP, HIPAA), are designed to help organizations navigate evolving regulations and secure their critical assets effectively, ensuring they can continue to serve their mission-driven objectives with confidence, irrespective of CMMC's future iterations.

Key takeaways

  • CMMC Phase II requirements have been suspended as of July 13, 2026, for a comprehensive review. The goal is to reduce compliance burdens while maintaining security.
  • Phase I self-assessment requirements for Level 1 (15 security requirements) remain in effect. Contractors must continue to meet these annual self-assessments.
  • The decision was influenced by concerns from the SBA and others regarding the high compliance costs for small businesses, which threatened their participation in the DIB.
  • A 60-day review period and a CMMC Reform Task Force will gather industry feedback to shape future, more scalable cybersecurity strategies.
  • The core obligation to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) persists, emphasizing the ongoing need for robust cybersecurity practices.

Sources

CMMCDefense Industrial BaseCybersecurity ComplianceSmall Business SecurityDoD Contracts