The Department of Defense (DOD) has announced a change in its cybersecurity strategy, suspending a phase of a pre-existing plan to strengthen cybersecurity compliance over concerns about the cost and bureaucracy involved in implementing it. DOD said in a release that it was suspending phase two of the Cybersecurity Maturity Model Certification (CMMC) program due to costs for small businesses. It was originally scheduled to go into effect this November. CMMC was first established in 2019 under the first Trump administration to ensure third-party contractors were safely holding and transmitting Pentagon data, but it has proved controversial among third parties, who have raised concerns that it is cumbersome and expensive. Meanwhile, under his administration, President Donald Trump has prioritized streamlining government services and cutting waste and red tape to push for what he says is government efficiency. The new plan would have forced companies to pass a cybersecurity assessment from a certified third party before receiving contract awards. Bureaucratic Burdens But the DOD said the plan was creating "prohibitive compliance costs and bureaucratic burdens." “Every dollar spent on security is a wise dollar spent, and so those who have been forward-leaning in uplifting their cyber posture, in assessing what their posture is, and doing something about it, they have contributed to national security,” Defense Department Chief Information Officer Kirsten Davies told reporters. “That is not money that is spent in vain, and so that is a huge message.” She added that over 100,000 defense firms still needed to complete a third-party cybersecurity assessment to comply with the requirements but that just over 100 assessors were available to conduct those audits. In a release, she added: "Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness. We believe the DIB can achieve both, while we reduce