The DoD’s decision to suspend CMMC Phase II caught much of the GovCon industry by surprise. But should it have?
One side says:
CMMC had become too expensive and burdensome, especially for small and mid-sized contractors. The compliance costs were pushing innovative companies out of the Defense Industrial Base and creating barriers to competition. From this perspective, the suspension was a logical course correction.
The other side says:
Cybersecurity threats haven’t disappeared. While certification requirements may be paused, the obligation to protect CUI and comply with NIST 800-171 remains. Contractors who interpret the pause as a reason to slow down their cyber efforts could be making a costly mistake.
My question to the GovCon community:
Did CMMC become a compliance exercise that outpaced practical security outcomes, or is pausing Phase II a step backward for protecting the defense supply chain?
What’s your take:
- Reduce compliance burden and keep innovators in the fight
- Maintain strict certification requirements to strengthen cybersecurity
1 Like
The suspension highlights the ongoing challenge in federal procurement: balancing robust supply chain security with the need to keep the industrial base open to commercial innovation. If compliance costs push agile, innovative companies out of the market, the DoD loses its competitive edge. A course correction was necessary, but the industry must ensure this pause is used to refine the framework into something sustainable, rather than letting cyber readiness slip backward.
1 Like
I agree that the real challenge is finding the right balance between security and innovation. Strong cybersecurity is non-negotiable, but compliance frameworks must be practical and scalable for companies of all sizes. The pause should be viewed as an opportunity to improve the model, reduce unnecessary burden, and focus on measurable security outcomes rather than compliance for compliance’s sake. The goal should be a stronger, more resilient Defense Industrial Base, not simply more paperwork.
The reason CMMC was created in the first place was that voluntary adherence to NIST SP 800-171 was largely a failure of self-attestation and pencil-whipping. Adversaries aren’t pausing their supply chain exfiltration campaigns while the DoD recalibrates.
Taking the pressure off third-party verification (C3PAOs) signals to leadership teams that cybersecurity can return to the back burner. For defense contractors handling Controlled Unclassified Information (CUI), basic cyber hygiene should be treated as a cost of doing business, just like quality assurance or physical security. Pausing verification creates a dangerous false sense of security across lower-tier suppliers.
1 Like