Stamp and Press
Live
Processes

CMMC Phase 2 Delay Announced by DOD

The Department of Defense has paused Phase 2 of its Cybersecurity Maturity Model Certification program, but experts advise defense contractors to continue

The Department of Defense has paused Phase 2 of its Cybersecurity Maturity Model Certification program, but experts...

The Department of Defense has paused Phase 2 of its Cybersecurity Maturity Model Certification program. Experts told Manufacturing Dive that defense contractors must continue working toward compliance despite the delay.

Phase 2 was set to begin on November 10, 2026. The DOD temporarily halted it on July 13, 2026. The CMMC program verifies that contractors have implemented security measures to protect federal contract information and controlled unclassified data.

Task Force to Review Program Structure

During the pause, the DOD will establish a CMMC Reform Task Force. CIO Kirsten Davies outlined this in a July 13 memo. The group will conduct a 60-day review. Its goal is to restructure the DOD's supply chain cybersecurity approach.

The review must align with the agency's Acquisition Transformation Strategy. That strategy, released in November 2025, focuses on accelerating production for key military systems. After the 60-day review, the task force has 15 days to write recommendations. Matthew Travis, CEO of Cyber AB, said contractors may see these recommendations in early October.

The task force will also consider industry feedback from a request for information that closed on August 14. Brian Kirk, director of cybersecurity at Cherry Bekaert, clarified a key point. The 60-day timeframe applies only to the review, not the duration of the Phase 2 pause.

Compliance Costs and Contractor Concerns

Costs to implement CMMC requirements vary widely. Kirk explained that costs depend on the contract and the type of sensitive information a company handles. Many contractors operate in both commercial and defense sectors. They must decide if defense compliance costs are justified by the revenue.

An analysis by the Small Business Administration estimated high costs for small entities. For small firms needing third-party assessments, compliance could reach $593,800 per verification. For those doing self-assessments, estimated costs are about $388,600.

Separate data from a CyberSheath survey found different figures. It showed 302 U.S.-based defense contractors spent an average of $155,204 annually on compliance. CyberSheath noted the comparison isn't perfect. The SBA estimate is a one-time cost, while the survey measures annual spending.

Ryan Heidorn, CTO of C3, said the big debate is assessment cost. He argued that the required security implementation has been in contracts for a decade. CMMC adds the cost of a third-party verification. Heidorn said some clients never did the initial implementation. They now face both implementation and certification costs.

Timeline Confusion and Supplier Pressure

There has been significant confusion about the Phase 2 date. Kirk and Heidorn both noted this. DOD contracting officers and major prime contractors mistakenly treated November 10, 2026, as a hard deadline.

Kirk stated it was never a deadline. It was only when contracting officers could start requiring third-party assessments in contracts. Despite this, primes like Boeing and Lockheed Martin issued CMMC notices to suppliers. Leonardo DRS told its level 2 suppliers they needed verification by November 10.

Kirk explained the prime contractors' rationale. They are pushing suppliers to prevent supply chain risks. If a supplier isn't certified, the prime must decide if that supplier is critical or find a replacement.

Implementing the cybersecurity requirements takes time. Heidorn said it can take nine to eighteen months. Many contractors were running out of time. Heidorn suggested this is a factor behind the current pause.

The Path Forward After the Pause

It is unknown when the DOD will resume Phase 2. After the task force completes its review, it will report to CIO Kirsten Davies and Undersecretary Michael Duffy. They will suggest program changes that comply with federal law. Any modifications must go through the rulemaking process, which can take up to two years.

Kirk sees a positive side to the delay. It reduces pressure and gives contractors more time to understand the requirements. He also issued a warning. The pause should not be a reason to delay implementation further.

Heidorn echoed that companies should continue their compliance work. A verification mechanism will eventually return. The timeline for preparation will remain challenging. The SBA warned that rushing certification would have increased costs and locked qualified suppliers out of the defense contracting process.

Related coverage

More from Processes