NewsJuly 23, 2026

DoD Just Suspended a Cybersecurity Rule That Could Have Cost Small Defense Contractors $593,800 Each

The Department of War suspended CMMC Phase II on July 13, 2026, sparing small defense contractors a costly certification deadline — but the underlying security duty stays.

The U.S. Department of War suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program on July 13, 2026, just months before it was set to take effect on November 10. The move came after small defense contractors and the Small Business Administration warned the certification framework would push many small firms out of the defense industrial base entirely.

What happened

CMMC Phase II would have required many of the more than 120,000 small businesses in the Defense Industrial Base to complete either a self-assessment or a costly third-party assessment, depending on their contracts, to prove they could safeguard Controlled Unclassified Information and Federal Contract Information. According to figures cited by the SBA, a third-party certification could run approximately $593,800 per firm, while even the self-assessment-eligible track could cost around $388,600 — with only about 100 approved third-party assessors available nationwide to handle the volume.

The Department of War suspended the Phase II requirement after months of engagement with the SBA and small contractors who said the compliance burden was accelerating attrition from defense work. SBA Administrator Kelly Loeffler said cybersecurity “cannot come at the cost of bureaucracy that shuts out the very companies our warfighters depend on.”

A CMMC Reform Task Force is now being formed to review the program, with a report due within 60 days — around mid-September 2026. The Department has also opened a request for information seeking industry input on streamlining the framework, including expanded self-attestation options; contractors have until August 14, 2026 to respond.

Why it matters

This is a suspension of the certification mechanism, not the underlying obligation. Small defense contractors and subcontractors are still required to protect federal information under existing contract clauses (like DFARS 252.204-7012) — what’s paused is the expensive third-party audit process that was about to become mandatory for many of them.

What this means for small businesses

If your business holds or is bidding on defense contracts or subcontracts, this buys time rather than eliminating the requirement. It’s worth using that time productively:

  • Don’t stop cybersecurity investments — the baseline security obligations are still in force, and the eventual reformed framework will likely still require documented controls.
  • Budget conservatively rather than assuming CMMC costs disappear; a reformed program is coming, just on an unknown timeline and (hopefully) at a lower price point.
  • If you want influence over what the reformed rule looks like, the August 14 RFI comment window is the moment to weigh in, directly or through an industry association.
  • Keep any compliance spending documented and categorized separately in your books now — when a reformed rule lands, you’ll want a clean record of what you’ve already invested toward it.

“Cybersecurity cannot come at the cost of bureaucracy that shuts out the very companies our warfighters depend on.” — SBA Administrator Kelly Loeffler

The bottom line

Small defense contractors just got a reprieve from a six-figure compliance bill, but not a reprieve from cybersecurity obligations themselves. Treat the next two months as a planning window, not a pause button — the reformed rule is likely to arrive faster than the original one did.

Sources: SBA.gov, Regulatory Oversight

Share
WP Twitter Auto Publish Powered By : XYZScripts.com