Particle.news

Pentagon Pauses Mandatory CMMC Phase II Certification

It shifts near-term verification to contractor self-assessments and selected government audits as a 60-day reform review explores a risk-based or hybrid validation model.

Overview

  • The Department of Defense and Small Business Administration suspended the requirement for third-party CMMC Phase II assessments and opened a 60-day review that includes a request for information and a CMMC Reform Task Force.
  • Through the pause the Pentagon will enforce baseline cybersecurity duties under NIST SP 800-171 by accepting Level 1 and Level 2 self-assessments and using targeted government-led audits.
  • DoD officials pointed to a shortage of certified assessors and high compliance costs for small suppliers as the immediate reasons for the pause and the call for program redesign.
  • Industry experts warn the shift to self-attestation creates an evidence gap that could raise uncertainty across program offices and contractors and increase False Claims Act exposure if assertions cannot be independently verified.
  • Commentators and former CMMC proponents expect the department to adopt a more scalable approach that reserves independent or government assessments for higher-risk systems while reducing burdens for lower-risk suppliers.