The Cybersecurity Maturity Model Certification (CMMC) is the U.S. Department of War’s framework that was created to verify that defense contractors and subcontractors adequately protect sensitive unclassified government data – including the Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) – on their computer networks.

Prior rules required cyber guidelines, but companies only had to self-promise to follow them. CMMC added formal verification. CMMC is designed to enhance cybersecurity and ensure that military and defense secrets are protected on third-party vendors’ networks. Companies must therefore earn the appropriate CMMC level to win or retain future Pentagon contracts.

However, last month, the department announced an immediate suspension of CMMC Phase II requirements (scheduled for November 10) to stop bureaucratic red tape and high audit costs from pushing critical small and mid-sized businesses out of the defense industrial base. The newly formed CMMC Reform Task Force also has a 60-day window to analyze industry feedback and deliver recommendations by mid-September 2026 regarding whether to restructure, scale back, or alter the program.

RFI Comment Period Closed

On Friday, August 14 the CMMC Reform Task Force’s Request for Information (RFI) public comment period on the reshaping of the cybersecurity framework will come to a close.

The question is what happens next?

In the short term, it is business as usual. But the Phase II requirements may expire.

It would have made mandatory third-party cybersecurity assessments (C3PAO) a requirement for contracts involving CUI.

“Last year’s pause of phase II requirements was intended to lighten the administrative burden of compliance,” explained Dr. Jim Purtilo, associate professor of computer science at the University of Maryland

“We get it: third-party audits are indeed expensive, and the tight deadlines would have excluded a number of smaller companies from competing in the DoW space,” Purtilo told ClearanceJobs. “Now the task force is in the tough position of trying to find a way for DoW to have its cake and eat it too, which is to say, come up with low-burden practices that will still yield high technical standards of assurance.”

The mandatory third-party cybersecurity assessments were seen as being a necessary tool for national security, but they imposed heavy financial and operational burdens that critics argue can push small businesses out of the defense industrial base.

The hiring of certified third-party assessors and upgrading technical systems can cost tens or hundreds of thousands of dollars, straining tighter operating budgets. Such a heavy burden risks forcing smaller, innovative suppliers to drop out of government contracting entirely, reducing competition.

“We get nothing for free,” Purtilo added. “Higher assurance will demand stronger scrutiny and more discipline in operating practices. The task force will thus inevitably need to grapple with tradeoffs. And that’s really tough since in many ways the science for objectively vetting such things isn’t there yet.”

Risk and Reward

The mandatory third-party audits by a C3PAO could be removed. It was supposed to reward firms, as achieving and proving compliance would ensure a company was qualified to participate in the Defense Industrial Base (DIB).

Certified vendors would stand out as trusted partners in secure government supply chains.

In addition, inaccurate self-attestations or false compliance claims would have triggered severe liabilities under the False Claims Act.

Instead, the barrier to entry may be lowered, but that may not be in the best interest of the DIB.

“In software engineering – an evidence-based field – savvy managers will know a lot about balance of risk and reward,” said Purtilo.

He told ClearanceJobs it works because the metrics inform where to focus energy for best value.

“We’d like for this to be the case in cybersecurity, except too often the data needed for best decisions remain cloaked by the very practices they should be informing,” Purtilo continued. “Practices thus risk degenerating into implementation of folklore and guesses, meaning expense that arises from ‘abundance of caution.’ That this is what the task force will need to cut through.”

In addition, Phases 3 and 4 and later timeline expansions are on hold until the review concludes.

“In the meantime, the industry has been back to self-assessment, which honestly is not a high bar to get over at all,” Purtilo cautioned. “So the sooner that we’re given strong guidance, the better.”

Related News

Peter Suciu is a freelance writer who covers business technology and cyber security. He currently lives in Michigan and can be reached at petersuciu@gmail.com. You can follow him on Twitter: @PeterSuciu.