CYBERSECURITY Future of Pentagon Cybersecurity Program Thrown into Question By Josh Luckenbaugh and Stew Magnuson iStock illustration The Defense Department July 13 announced it was suspending the Phase 2 requirements for its Cybersecurity Maturity Model Certification program and would be conducting a comprehensive 60-day review of the effort. The program — known as CMMC — has been in the works for seven years and is meant to serve as the department’s mechanism for verifying defense contractors are compliant with its cybersecurity requirements. While the initiative is designed to enhance cybersecurity, “instead it has created prohibitive compliance costs and bureaucratic burdens,” according to a Pentagon release. Small Business Administration data shows that the program is “forcing innovative companies out of the defense industrial base, which will delay the delivery of critical capabilities to the warfighters,” it said. The ongoing pause and review of CMMC puts the fate of the program — and the assessment organizations planning to certify contractors’ cybersecurity posture — into doubt. This is not the first time CMMC has faced headwinds since it was announced by the first Trump administration in 2019. The initial version of the program was met with so much blowback that then-Deputy Secretary of Defense Kathleen Hicks initiated her own review of the program shortly after the Biden administration took office in 2021. The Pentagon unveiled “CMMC 2.0” — the iteration of the program as it exists today — in November 2021, consisting of three compliance levels instead of the original version’s five. It took four more years of rulemaking and industry feedback for the first phase of implementation to begin in November 2025, which introduced in applicable Pentagon solicitations requirements for CMMC Level 1 and Level 2 self-assessments. Phase 2, which was scheduled to begin Nov. 10, would have seen the introduction in