# Pentagon Pauses CMMC Phase 2 Audits—But the Real Compliance Burden Remains
The U.S. Department of Defense has suspended the mandatory third-party assessment requirement for CMMC Phase 2, citing an inability to scale the auditor ecosystem and rising compliance costs that are pushing small and mid-sized defense contractors out of the industrial base. However, the move creates a precarious interim period where companies must continue self-attesting to their cybersecurity posture without independent verification—a situation that carries significant legal and operational risk.
The suspension, announced in mid-July 2026, does not pause the underlying legal obligations. A newly formed CMMC Reform Task Force will spend 60 days gathering industry feedback and is expected to report recommendations by mid-September. Until then, contractors remain bound by DFARS 252.204-7012 requirements, Phase 1 self-assessment obligations, and mandatory SPRS (Supplier Performance Risk System) score submissions.
## The Threat: A Compliance Verification Vacuum
The Pentagon's move addresses a critical bottleneck: approximately 100 authorized Certified CMMC Professional Auditors (C3PAOs) exist for over 100,000 companies in the defense industrial base. The math, as industry observers note, was never going to work. A mandatory Phase 2 rollout would have created an impossible queue and potentially excluded smaller contractors unable to afford the six-figure audit fees and multi-month timelines.
Yet the suspension creates a dangerous gap. Contractors must continue self-assessing against all 110 NIST 800-171 cybersecurity requirements, submit compliance scores to SPRS, and report their security posture to the government—but without the accountability mechanism of third-party verification.
What remains in effect:
What is suspended:
## Background: CMMC and the Path to Phase 2
The Cybersecurity Maturity Model Certification (CMMC) was introduced by the DoD in 2019 to establish a standardized, measurable approach to defense contractor cybersecurity. The program uses a five-level maturity model:
| Level | Focus | Scope |
|-------|-------|-------|
| Level 1 | Basic cyber hygiene | Foundational practices for all contractors |
| Level 2 | Intermediate practices | Organizations handling CUI |
| Level 3 | Advanced/proactive practices | Advanced persistent threat countermeasures |
| Level 4 | Optimized practices | Specialized DoD critical infrastructure |
| Level 5 | World-class practices | Continuous monitoring and optimization |
Phase 1, launched in 2021, introduced self-assessment at Levels 1–3, allowing contractors to certify their own compliance without external auditors. Phase 2, originally mandated to begin November 2023 and repeatedly delayed, would have made independent third-party assessment mandatory for contract renewals and eligibility—a move intended to eliminate self-certification bias and create accountability.
However, industry warnings about assessor scarcity, cost barriers, and timeline bottlenecks proved prescient. Smaller contractors—often innovative suppliers providing specialized capabilities to the defense supply chain—reported that audit costs exceeding $100,000 and wait times of 12+ months were making CMMC compliance economically unfeasible.
## The Legal and Compliance Minefield
The Pentagon's suspension does not eliminate legal exposure; it may amplify it. Under the False Claims Act, contractors who knowingly submit false compliance certifications to the government face penalties of $5,000 to $10,000 per claim, plus treble damages.
Recent DOJ settlements illustrate the risk:
All of these cases originated with companies self-attesting to compliance before any third-party verification occurred. The audit, when it came, revealed the gap—and triggered DOJ investigation.
With Phase 2 suspended, contractors now face a period where self-attestation is the only verification mechanism, yet the legal obligation to protect CUI remains absolute. The interim period creates what compliance experts call "False Claims Act exposure" on a wider scale than before.
## Industry Consensus: Obligation Remains, Solution Unclear
Industry professionals broadly agree on one point: the underlying requirement to protect CUI does not change. Whether Phase 2 resumes in its current form, gets redesigned, or is replaced remains uncertain.
### The Case for Third-Party Verification
Abdie Mohamed, GRC Engineering Lead at NR Labs, articulates the counterargument to suspension:
> "Phase 1 is still in place. If you handle CUI, you're still self-assessing against all 110 NIST 800-171 requirements and posting that score to SPRS. DFARS 252.204-7012 is still in your contracts. And if you report a perfect 110, the government audits you down the road, and it turns out you never did the due diligence, that's False Claims Act exposure."
Mohamed's concern reflects a fundamental tension: self-attestation without independent verification has historically failed to prevent overstated compliance claims. Third-party audits, despite their cost and timeline friction, serve as a deterrent and accountability mechanism.
### The Case for Suspension and Reform
Chris Nyhuis, CEO of Vigilant, takes the opposing view:
> "Suspending CMMC Phase II is the right call, and it's overdue. Speed done securely is a security requirement now, not a nice-to-have. When it takes a small defense supplier a year and six figures to clear a third-party audit before it can even bid, we're not protecting the mission, we're slowing it down."
Nyhuis emphasizes that the controls and requirements remain unchanged—only the verification mechanism is paused. He argues that the friction of the audit regime was pricing out smaller, innovative contractors who bring speed and edge capabilities to the defense industrial base.
## Technical Implications
The suspension does not alter NIST 800-171 requirements. Contractors must still implement controls across 14 security domains:
The difference is verification method, not technical requirement. Contractors must continue operating at their declared CMMC level, but without third-party auditors verifying compliance.
## The 60-Day Reform Window
The CMMC Reform Task Force has approximately 60 days to:
Industry observers anticipate three possible outcomes:
1. Scaled Phase 2: Streamlined assessments, automated tools, narrower scope
2. Risk-Based Sampling: Audit-on-demand for high-risk suppliers; self-attestation for others
3. Hybrid Model: Combination of self-assessment, spot audits, and continuous monitoring
Complete elimination of the program is considered unlikely, as no stakeholder publicly questioned whether independent verification should exist—only how to make it feasible.
---
## HackWire Analysis
The Pentagon's suspension reveals a pattern that extends far beyond CMMC: the gap between compliance frameworks and operational reality. DoD designed CMMC with legitimate security goals, but without adequately planning for the human and economic constraints of scaling 100,000+ audits across a fragmented contractor ecosystem.
What's instructive here is the timing of failure. The program had multiple warning signals—C3PAO scarcity, cost projections, timeline delays—that were raised publicly and repeatedly over three years. Yet the department proceeded toward mandatory Phase 2 until the math became literally impossible to execute. This pattern repeats across federal compliance programs: frameworks are built top-down, industry pushback is treated as resistance rather than intelligence, and suspension arrives only when implementation becomes unmistakably broken.
The False Claims Act exposure is the hidden story. Contractors are now in a position where they must attest to CMMC compliance without third-party verification, yet the legal precedent (Aerojet, Raytheon, MORSE) shows that overstated self-attestation is prosecuted aggressively. Smart contractors will over-invest in security to create a safety margin; smaller ones may simply de-emphasize CUI work and exit the defense industrial base entirely—which is precisely the outcome the Pentagon wanted to avoid.
The suspension also validates a broader insight: audit regimes work best when they're predictable, timely, and proportional to company size. When compliance costs dwarf contract value or timelines exceed contract decision windows, the system breaks. The CMMC Reform Task Force should prioritize automation and tiered assessment before expanding headcount.
— HackWire Editorial
---
## Recommendations for Defense Contractors
Immediate priorities during the suspension:
## Related Coverage