Pentagon pauses cyber audit rule blamed for supplier exits
Key Points
- Program offices will now require only Level 1 or Level 2 self-assessments instead of the mandatory third-party audits that Phase 2 would have imposed
- The Pentagon acknowledged that 'CMMC compliance is forcing innovative companies out of the Defense Industrial Base' and cited 'paralyzing costs' as a barrier to weapons production speed
- A CMMC Reform Task Force will collect industry feedback through a public request for information and deliver recommendations within 60 days
AI Summary
Pentagon Suspends Cyber Audit Rule Amid Supplier Exodus Concerns
The Pentagon has immediately suspended Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program, which was scheduled to take effect November 10, 2025. The decision responds to industry warnings that compliance requirements were driving small suppliers out of defense contracting and narrowing competition in the defense supply chain.
Key Details:
- The CMMC program launched in November 2025 to protect controlled unclassified information in the defense supply chain
- Phase 2 would have mandated third-party cybersecurity audits for contractors
- Instead, program offices will now require only Level 1 or Level 2 self-assessments
- A 60-day review has been initiated, led by a newly formed CMMC Reform Task Force
Industry Impact:
Small and mid-sized aerospace and defense suppliers had complained about excessive compliance costs and long wait times for third-party audits, prompting some to exit defense work entirely. Industry lawyers also warned the rules risked squeezing out lower-tier suppliers and creating complications for international companies managing competing data-privacy standards.
Pentagon Rationale:
Pentagon Chief Information Officer Kirsten Davies acknowledged the program was "forcing innovative companies out of the Defense Industrial Base." Under Secretary Michael Duffey linked the suspension to efforts accelerating weapons production, stating it would remove "paralyzing costs" while maintaining "innovators and competition" in the defense supply chain.
The Reform Task Force will collect industry feedback through a public request for information and deliver recommendations within 60 days, signaling potential long-term modifications to the cybersecurity certification approach.
Model Analysis Breakdown
| Model | Sentiment | Confidence |
|---|---|---|
| GPT-5-mini | Neutral | 75% |
| Claude 4.5 Haiku | Bullish | 75% |
| Gemini 2.5 Flash | Bullish | 85% |
| Consensus | Bullish | 78% |