Pentagon pauses cyber audit rule blamed for supplier exits

Reuters | July 13, 2026 at 09:19 PM UTC
Bullish 78% Confidence Majority Agreement
Read Original Article

Key Points

  • Program offices will now require only Level 1 or Level 2 self-assessments instead of the mandatory third-party audits that Phase 2 would have imposed
  • The Pentagon acknowledged that 'CMMC compliance is forcing innovative companies out of the Defense Industrial Base' and cited 'paralyzing costs' as a barrier to weapons production speed
  • A CMMC Reform Task Force will collect industry feedback through a public request for information and deliver recommendations within 60 days

AI Summary

Pentagon Suspends Cyber Audit Rule Amid Supplier Exodus Concerns

The Pentagon has immediately suspended Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program, which was scheduled to take effect November 10, 2025. The decision responds to industry warnings that compliance requirements were driving small suppliers out of defense contracting and narrowing competition in the defense supply chain.

Key Details:

  • The CMMC program launched in November 2025 to protect controlled unclassified information in the defense supply chain
  • Phase 2 would have mandated third-party cybersecurity audits for contractors
  • Instead, program offices will now require only Level 1 or Level 2 self-assessments
  • A 60-day review has been initiated, led by a newly formed CMMC Reform Task Force

Industry Impact:

Small and mid-sized aerospace and defense suppliers had complained about excessive compliance costs and long wait times for third-party audits, prompting some to exit defense work entirely. Industry lawyers also warned the rules risked squeezing out lower-tier suppliers and creating complications for international companies managing competing data-privacy standards.

Pentagon Rationale:

Pentagon Chief Information Officer Kirsten Davies acknowledged the program was "forcing innovative companies out of the Defense Industrial Base." Under Secretary Michael Duffey linked the suspension to efforts accelerating weapons production, stating it would remove "paralyzing costs" while maintaining "innovators and competition" in the defense supply chain.

The Reform Task Force will collect industry feedback through a public request for information and deliver recommendations within 60 days, signaling potential long-term modifications to the cybersecurity certification approach.

Model Analysis Breakdown

Model Sentiment Confidence
GPT-5-mini Neutral 75%
Claude 4.5 Haiku Bullish 75%
Gemini 2.5 Flash Bullish 85%
Consensus Bullish 78%