top of page

CMMC Phase II Suspended: What the Department of War's Decision Really Means

  • Writer: Brian Couzens
    Brian Couzens
  • Jul 14
  • 3 min read

The United States Department of War has announced the immediate suspension of CMMC Phase II requirements while it undertakes a 60-day review of the programme.

Predictably, headlines have already begun suggesting that CMMC has been paused or that cybersecurity requirements are being rolled back. Neither interpretation is correct.

The announcement is not a retreat from cybersecurity. It is a reassessment of how cybersecurity assurance should be delivered.

What Has Changed?

The Department has suspended the implementation of CMMC Phase II third-party assessment requirements while a newly established CMMC Reform Task Force conducts a comprehensive review.

However, several critical requirements remain unchanged:

  • Phase I self-assessments continue.

  • NIST SP 800-171 Revision 2 remains the required cybersecurity baseline.

  • DFARS obligations to safeguard Controlled Unclassified Information remain fully enforceable.

  • Protection of defence information remains a non-negotiable requirement.

In other words, organisations are still expected to implement robust cybersecurity controls. What is under review is the assurance framework used to demonstrate compliance.

Why Was This Necessary?

According to the Department, the existing CMMC implementation was creating excessive cost and administrative burden, particularly for small, medium-sized and non-traditional suppliers within the Defence Industrial Base.

That is an important acknowledgement.

Every governance programme eventually reaches a point where policymakers must ask a difficult question:

Is the assurance process improving security, or has it become an objective in its own right?

If demonstrating compliance becomes disproportionately expensive, organisations inevitably divert resources away from improving security and towards satisfying administrative requirements.

The result is often more paperwork, more assessment activity and greater cost without a corresponding improvement in operational resilience.

Security Has Not Been Suspended

Perhaps the most dangerous misunderstanding would be to assume this announcement weakens cybersecurity expectations.

It does not.

Threat actors have not paused their activities.

Supply chain attacks have not become less sophisticated.

Nation-state cyber operations have not slowed because a compliance programme is being reviewed.

The obligation to protect sensitive defence information remains exactly as important today as it was before this announcement.

Only the method used to demonstrate assurance is under examination.

The Wider Governance Lesson

This announcement has implications that extend far beyond CMMC.

Across cybersecurity, AI governance, operational resilience, privacy and emerging technologies, organisations continue to build increasingly complex governance ecosystems.

Policies become frameworks.

Frameworks become assessments.

Assessments become audits.

Audits become certification programmes.

Over time, these activities can accumulate to the point where governance itself becomes a significant operational burden.

That does not mean governance is unnecessary.

It means governance must continually demonstrate that it delivers measurable improvements in decision quality, resilience and risk reduction.

Evidence should exist to support decisions.

It should never become the product.

What Happens Next?

The newly established CMMC Reform Task Force has been given sixty days to conduct a comprehensive review of the programme.

This review is likely to focus on several critical questions:

  • Can assurance be delivered more efficiently?

  • Which assessment activities genuinely reduce cyber risk?

  • Which requirements create administrative overhead without improving security?

  • How can smaller suppliers participate without disproportionate compliance costs?

  • How should government balance trust, assurance and operational capability?

The answers will be closely watched across both government and industry.

Why This Matters Beyond Defence

The issues raised by CMMC are not unique to defence procurement.

Every major governance initiative eventually encounters the same challenge.

How much assurance is enough?

How much evidence is proportionate?

At what point does demonstrating compliance begin to consume the very resources needed to improve security?

These questions are equally relevant to AI governance, operational resilience, quantum readiness and enterprise risk management.

The most effective governance programmes are those that strengthen operational capability while remaining proportionate, evidence-based and commercially sustainable.

Final Thoughts

The suspension of CMMC Phase II should not be viewed as a weakening of cybersecurity expectations.

It should be viewed as an opportunity to improve how assurance is delivered.

Strong cybersecurity remains essential.

Independent assurance remains essential.

The challenge is ensuring that assurance supports resilience rather than becoming an obstacle to it.

If this review produces a framework that reduces unnecessary bureaucracy while maintaining confidence in supplier security, it could become an important case study in modern governance reform.



 
 
 

Comments


bottom of page