Industry Reacts to Pentagon Pause on CMMC Phase 2

Pentagon paused mandatory CMMC Phase 2 third‑party assessments for 60 days to review assessor capacity and costs; self‑assessments, SPRS reporting and DFARS protections remain in force.

The Pentagon has paused mandatory third‑party assessments under CMMC Phase 2 for 60 days to review whether assessor capacity can scale and to address compliance cost concerns. A CMMC Reform Task Force will gather industry feedback and issue recommendations by mid‑September.

The suspension applies to independent verification by authorized C3PAOs but does not remove contractors’ obligations under existing contract terms to implement NIST SP 800‑171 controls, submit accurate Supplier Performance Risk System (SPRS) scores, or meet DFARS 252.204‑7012 requirements for protecting controlled unclassified information (CUI).

Pentagon officials cited an assessor pipeline that could not meet projected demand and certification costs that threatened to push small and mid‑size suppliers out of the defense industrial base. The department estimated roughly 76,598 entities would require Level 2 certification under its previous roll‑out projections.

Industry capacity figures published by assessors show 107 authorized C3PAOs, more than 590 Lead Certified CMMC Assessors (LCCAs), over 1,000 Certified CMMC Assessors (CCAs) and nearly 2,000 Certified CMMC Professionals (CCPs). Lead assessor background checks at Tier 3 can take six months or longer and were identified as a bottleneck.

Some security practitioners welcomed the pause and called for changes to reduce cost and delay for small, fast suppliers. “When it takes a small defense supplier a year and six figures to clear a third‑party audit before it can even bid, we are slowing the mission,” said Chris Nyhuis, chief executive of Vigilant, who urged stronger personal accountability for executives who sign contracts.

Other cybersecurity professionals warned the suspension increases legal risk if contractors treat self‑attestation as optional. Abdie Mohamed of NR Labs pointed to prior False Claims Act settlements — Aerojet Rocketdyne ($9 million), Raytheon ($8.4 million), Penn State ($1.25 million) and MORSE Corp ($4.6 million) — that stemmed from gaps between self‑reported SPRS scores and later assessor findings.

Some assessors and consultants proposed changes to keep third‑party checks but reduce volume pressure. Ned Butler of Redspin suggested narrowing mandatory assessments to prioritize firms that handle genuinely sensitive CUI, targeting roughly 15,000–20,000 entities. Robert Teague of Redspin highlighted staffing rules and long background investigations as key constraints and proposed more flexible team staffing and broader use of CCPs to lower assessment costs.

Other experts recommended more technical validation and automation. Tyler Fordham of Dark Wolf called for red teaming, automated checks and machine‑readable compliance formats to scale verification without imposing high fees on small contractors.

Legal and advisory voices urged firms to use the pause to strengthen governance and evidence. Emil Sayegh of CyberSheath reminded contractors that NIST SP 800‑171 and DFARS obligations remain and that the Department of Justice’s Civil Cyber‑Fraud Initiative can be used to pursue inaccurate SPRS submissions. Michael Gruden of Steptoe recommended attorney‑client privileged readiness reviews to identify gaps. Kate Growley of Crowell & Moring noted many contracts already require NIST implementation and annual affirmations, and the suspension only removes the immediate certification timeline.

Experts and advisers suggested practical steps during the review: clarify what constitutes CUI and where it resides, tighten access controls and logging, verify encryption and incident response plans, and ensure senior attestations are backed by demonstrable controls. Suggested structural changes included delta assessments after mergers, clearer flow‑down of CUI requirements by prime contractors and program offices, and government incentives to offset compliance costs for small and mid‑size suppliers.

The 60‑day review ends in mid‑September. Until the task force issues recommendations, contractors must continue self‑assessing, submit truthful SPRS scores and maintain the safeguards required under DFARS 252.204‑7012.

Articles by this author