U.S. Department of Defense Halts Phase 2 of CMMC Program and Launches Comprehensive Review

Deep News
07/14

The U.S. Department of Defense announced on the 13th that it is suspending the advancement of the third-party assessment requirements for Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program and initiating a 60-day "top-to-bottom" comprehensive review of the certification initiative. This move signifies a major potential adjustment to the long-standing cybersecurity compliance mechanism for contractors used by the U.S. military.

In a memorandum signed on the 13th, Department of Defense Chief Information Officer Kirsten Davies stated that the DoD has decided to pause the CMMC Phase 2 requirements originally scheduled to take effect on November 10, 2026. According to the original plan, this phase would have mandated that all defense contractors handling sensitive but unclassified information undergo third-party cybersecurity assessments. Davies noted that the Phase 1 self-assessment requirements, which took effect last November, remain in force, but all pending and future CMMC milestone deadlines are now "paused pending further notice."

Defense officials revealed that the core rationale behind this suspension and review is a significant conflict between the cumbersome procedures of the current CMMC mechanism and the "Weapons Systems Acquisition Reform" initiative championed by Secretary of Defense Pete Hegseth. Hegseth's procurement reform aims to eliminate administrative bureaucracy and foster technological innovation.

In the memorandum, Davies emphasized that while the current version of the CMMC certification mechanism is designed to enhance security, it has imposed substantial and often exclusionary administrative and financial burdens on the U.S. Defense Industrial Base (DIB), particularly on small and non-traditional businesses that serve as engines of innovation. Data from the Department of Defense and feedback from the Small Business Administration (SBA) indicate that high compliance costs, a severe shortage of capacity among third-party assessment organizations, and a complex regulatory timeline are driving key new technology providers and small businesses away from bidding on military contracts, leading to a substantive loss of critical supply chain participants.

To address this, Davies has authorized the establishment of a 60-day "CMMC Reform Task Force" responsible for providing recommendations for a new alternative framework. This framework will prioritize the speed of delivering technical capabilities, lower the barrier to entry for small businesses and non-traditional suppliers, and replace high-cost, pro forma third-party certifications with scalable, practical, day-to-day cyber protection measures.

SBA Administrator Kelly Loeffler issued a statement the same day expressing support for the Defense Department's decision to pause. Loeffler pointed out that small businesses are the cornerstone of the national security supply chain, and CMMC compliance is becoming an insurmountable barrier, supporting the military's efforts to cut such high-cost administrative red tape.

The Cybersecurity Maturity Model Certification (CMMC) program was initially launched during former President Trump's first term, aiming to introduce independent third-party auditors to conduct mandatory assessments of cybersecurity levels across the vast defense contractor base, addressing long-standing issues with inaccurate contractor self-assessments. However, due to excessively high compliance costs, the program also faced suspension and simplification during the Biden administration. The U.S. military previously estimated that approximately 80,000 companies would be subject to its rules. This return to a review track reflects the deep-seated, difficult-to-reconcile conflict within the U.S. military between strengthening supply chain cybersecurity and maintaining the scale and vitality of its industrial base.

免責聲明:投資有風險,本文並非投資建議,以上內容不應被視為任何金融產品的購買或出售要約、建議或邀請,作者或其他用戶的任何相關討論、評論或帖子也不應被視為此類內容。本文僅供一般參考,不考慮您的個人投資目標、財務狀況或需求。TTM對信息的準確性和完整性不承擔任何責任或保證,投資者應自行研究並在投資前尋求專業建議。

熱議股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10