CMMC Phase II Paused: What Small Defense Vendors Need to Know
The hosts break down the Department of War’s sudden suspension of CMMC Phase II, what stays in place for contractors, and why the move is meant to reduce compliance overhead without weakening core cyber requirements. They also dig into prime contractor flowdowns, supply chain bottlenecks, and the shift toward practical security controls over paperwork-heavy certification.
Chapter 1
Why did the Department of War hit pause on CMMC Phase II right when industry expected it to turn on?
Eric Marquette
So, Paul, Elias, I- I- I'm looking at this press release from July 13th, 2026, and it is a complete bombshell. The Department of War is immediately suspending the CMMC Phase II requirements. I mean, these were literally supposed to go live on November 10th, 2026. That is just months away. If I'm a small defense contractor, I've spent the last year sweating this deadline, and now... boom. Suspended. What- what actually changes for me on Monday morning?
Paul Netopski
Well, Eric, the- the short answer is... practically, almost nothing on the ground, but legally, a massive breather. Let's- let's be very clear about what did not change. The safeguarding requirements under DFARS 252.204-7012? Still there. NIST SP 800-171 Rev 2? Still the standard. Phase I self-assessments? Firmly in place. This isn't a get-out-of-jail-free card for security. It's a- it's a pause on the external third-party assessment mechanism... the- the C3PAO gate.
Roz the Rulemaker
Exactly, Paul. And from a- from an administrative law perspective, this is a fascinating move. You have 32 CFR Part 170, which was codified back in late 2024, laying out this massive, rigid four-phase rollout. And suddenly, the CIO, Kirsten Davies, pulls the emergency brake. They are launching a sixty-day top-to-bottom review with a new CMMC Reform Task Force. It's- it's an admission that the bureaucratic machinery they built was about to collide head-on with reality.
Eric Marquette
So it's- it's like they're trying to separate actual, tangible cyber hygiene from what- what we might call... compliance theater? Like, writing policies just to pass an audit versus actually locking down the network.
Paul Netopski
Yes! Exactly. The- the phrase the CIO used is "tangible cyber hygiene rather than administrative overhead." If you're a small machine shop making a- a non-sensitive bolt, do you really need a half-million-dollar third-party certification just to prove you have an onboarding checklist? The DoW is saying... maybe not. Let's focus on the basics first.
Chapter 2
What problem is the pause trying to solve — the rule, or the way primes are using the rule?
Eric Marquette
But okay, why now? Why wait until the eleventh hour to pause this? Is the rule itself broken, or is it... is it how the industry is reacting to it? Because I keep hearing about prime contractors- you know, the big defense giants- just dumping these requirements down their entire supply chain.
Roz the Rulemaker
Oh, the flowdown issue is massive, Eric. Under 32 CFR 170.23, the rule actually has a logical flowdown structure. If a sub only handles Federal Contract Information, they only need Level 1. If they handle Controlled Unclassified Information, or CUI, then they need Level 2. But what we're seeing in practice is blanket risk dumping. Primes are terrified of non-compliance, so they just write into every subcontract: "You must be CMMC Level 2 Certified." Even if that sub is just- I don't know, providing catering or basic commercial parts.
Paul Netopski
It's a complete defensive crouch by the primes. They- they don't want to do the hard work of scoping. They don't want to look at a subcontractor and say, "Okay, what data are we actually sending you? Is it CUI? Where does it live on your network?" It's much easier for their legal teams to just say, "Sign this and show us a C3PAO certificate or you're off the team." And that is- it's paralyzing the supply chain.
Eric Marquette
Wait, so the primes are basically using CMMC as a shield, saying... "We're not going to manage the risk, we're just going to make our smallest vendors pay for it"?
Roz the Rulemaker
Precisely. And that runs completely counter to Secretary Pete Hegseth’s Acquisition Transformation System directives. The whole ATS doctrine is about speed to capability and lowering barriers for non-traditional businesses. When the Small Business Administration put out data showing that a third-party CMMC Level 2 assessment costs a small firm nearly six hundred thousand dollars... I mean, five hundred and ninety-three thousand eight hundred dollars, to be exact... that's a death sentence for a small innovator. They just walk away from defense entirely.
Chapter 3
What does a real supply chain risk approach look like, and why does the current behavior fail that test?
Paul Netopski
And the tragedy is, the- the rule itself actually has the tools to prevent this. If you look at 32 CFR 170.19, the scoping rules are incredibly detailed. It defines in-scope assets like CUI Assets, Security Protection Assets... but it also has categories like Contractor Risk Managed Assets and Specialized Assets, which have much lighter requirements. There's even a provision for Virtual Desktop Infrastructure... VDI... where if the endpoint is configured to prevent CUI from leaving the screen, that endpoint can be out of scope!
Eric Marquette
So if- if I'm a small supplier, and I only access the prime's data through a secure remote viewer... like, key-keyboard, video, mouse... I shouldn't have to secure my entire local network to a Level 2 standard?
Paul Netopski
Exactly! But because the primes are doing blanket flowdowns, they're completely ignoring those scoping nuances. They're treating everything as a full CUI system. It's- it's like requiring a- a security guard at the front gate of a factory to wear a full hazmat suit because there's a sealed vial of chemicals in a lab three miles away. It makes no sense, and it's destroying the- the very agility the military needs.
Roz the Rulemaker
And we have to remember, the Department has other ways to verify compliance. The- the Revolutionary FAR Overhaul deviations from earlier this year relocated self-assessments to DFARS 252.240-7997 and kept the government-led Medium and High assessments. That means the DCMA's DIBCAC team can still go in and audit you if they need to. We don't need this army of private C3PAO assessors... who, by the way, the SBA pointed out only numbered about a hundred approved assessors nationwide for over one hundred and twenty thousand small businesses!
Eric Marquette
Wow. A hundred assessors for a hundred and twenty thousand companies. That math... that math doesn't work at all. It's a complete bottleneck.
Chapter 4
Is the 60-day review really about cybersecurity — or about changing the incentives?
Eric Marquette
So this 60-day review... is this just a political delay, or is there a deeper shift happening in how the Department views cyber risk?
Paul Netopski
I think it's a fundamental shift in doctrine, Eric. If you look at the "Brilliant at the Basics" campaign the DoW CIO launched alongside this... it's all about high-efficacy, tangible controls. They're talking about phishing-resistant MFA... moving away from SMS and push notifications entirely. They're talking about logical segmentation to limit lateral movement, and dynamic asset inventory. These are things that actually stop hackers, not paperwork exercises.
Roz the Rulemaker
Yes, and the concurrent Request for Information... the RFI... has seven very pointed questions. They are literally asking industry: "Which controls deliver the most actual risk reduction, and which ones just create massive administrative overhead?" They want to slim down the baseline. They're also asking about "commercial reciprocity"... how to accept SOC 2 or ISO 27001 certifications instead of forcing contractors to pay for a duplicate CMMC audit. That is a massive olive branch to the commercial tech sector.
Eric Marquette
So instead of "did you write a three-hundred-page System Security Plan," the question becomes "did you turn on phishing-resistant MFA on your actual systems?"
Paul Netopski
Precisely. It's shifting the focus to operational resilience. The threat environment isn't pausing, and the DoW knows that. But they've realized that a- a fragile supply chain with five giant primes who can pass an audit is actually a much bigger national security risk than a diverse supply chain with thousands of innovative suppliers who have good, basic cyber hygiene.
Chapter 5
If small businesses are disappearing, what should we be watching next?
Eric Marquette
But that brings up a really dark question. If these small, innovative businesses are being crushed by compliance costs... where are they going? Are they just closing up shop, or is something else happening?
Roz the Rulemaker
Well, that's the- the quiet crisis, Eric. Some are just walking away from defense work. But others... when their valuation drops because they can't afford CMMC compliance and are about to lose their subcontracts... they become prime acquisition targets. Quite literally. The big primes can swoop in, buy them for pennies on the dollar, and absorb their intellectual property. It drives further consolidation in an industrial base that has already shrunk from fifty-one primes after the Cold War to just five today.
Paul Netopski
And that is- it's a terrible outcome for the taxpayer and the warfighter. Less competition means higher costs, slower innovation, and single points of failure for critical components. If a prime's behavior under CMMC actually helps them swallow their own supply chain... that's a- a perverse incentive that the Department of War has to stop.
Eric Marquette
Man. So this 60-day review... it's not just an IT policy update. It's a battle for the- the economic survival of the Arsenal of Freedom. We'll be watching the RFI responses closely until they close on August 14th. Paul, Elias, thanks for breaking this down.
Paul Netopski
Good chatting, Eric. We'll see where the Task Force lands.