The Department of Defense’s decision to suspend CMMC Phase 2 and launch a 60-day reform review has sent shockwaves through the GovCon community. By stopping the November 10 rollout of third-party certifications, the DoD is fundamentally reassessing how we secure the defense industrial base (DIB).
The move highlights a deep tension within national security: How do we maintain strict cybersecurity without bankrupting the small innovators who build our critical capabilities?
Here is a look at both sides of this high-stakes debate.
Side A: The Case for Suspension (Pro-Innovation & Speed)
Voice: The Defense Leadership & Small Business Advocates
“Cybersecurity is vital, but compliance shouldn’t be a suicide pact for small businesses. If our best innovators leave the market, the enemy wins anyway.”
-
Protecting the Supply Chain Ecosystem: The Small Business Administration explicitly flagged that CMMC compliance costs were driving critical small-to-midsize firms out of the defense industrial base. Suspending Phase 2 prevents an accidental mass exodus of the very companies the military relies on for cutting-edge technology.
-
Prioritizing Speed Over Bureaucracy: Under Defense Secretary Pete Hegseth’s new acquisition initiatives, “acquisition is a warfighting function,” and speed is everything. Paralyzing companies with complex, expensive third-party audits delays the delivery of critical tools to operators in the field.
-
Embracing Modern Tech Realities: Requiring every contractor to undergo independent, bespoke CMMC audits ignores how the commercial market works. The DoD’s new Request for Information (RFI) asks a smart question: Why not recognize existing commercial cybersecurity tools and managed services that contractors already use? Eliminating redundant government red tape saves billions without abandoning security.
Side B: The Case Against Suspension (Pro-Security & Accountability)
Voice: National Security Hawks & Cyber Professionals
“Self-assessments have failed for a decade. Pausing independent audits just leaves the backdoor to our military secrets wide open.”
-
Honesty Boxes Don’t Work: Reverting to Phase 1 self-assessments essentially brings us back to the honors system. History shows that when companies grade their own homework, they overestimate their security. Without third-party verification, the DoD cannot truly know if its data is safe.
-
Sunk Costs and Wasted Effort: For years, forward-thinking contractors did the right thing. They invested millions of dollars, hired consultants, and upgraded their infrastructure to be ready for the November rollout. Abruptly pulling the rug penalizes the companies that took national security seriously and rewards the laggards who dragged their feet.
-
Our Adversaries Aren’t Taking a 60-Day Break: Foreign state actors actively target sub-tier defense contractors to steal intellectual property and compromise military systems. Every day the DoD spends reviewing, reforming, or watering down standards is another day our supply chain remains vulnerable to devastating cyberattacks.
Join the Debate
The CMMC Reform Task Force has opened a window until August 14 for contractors to submit feedback on cost drivers, administrative burdens, and which NIST 800-171 controls actually reduce risk.
