The Department of War recently announced that it is suspending the Phase II rollout of the Cybersecurity Maturity Model Certification (CMMC) requirements while it conducts a comprehensive review of the program. For now, organizations pursuing Department of War contracts will continue to rely on Phase II self-assessments rather than mandatory third-party C3PAO assessments.
From our perspective, this is a welcome and practical decision.
Over the past several years, We've spoken with many small and mid-sized businesses that want to compete for Department of Defense contracts but have found the CMMC certification process to be one of the biggest obstacles—not because they lack the technical capability to secure their environments, but because of the cost, complexity, and availability of Certified Third-Party Assessment Organizations (C3PAOs).
For many organizations, preparing for a C3PAO assessment can require months of effort, significant consulting costs, technology investments, and then additional expenses for the assessment itself. Even companies that have already implemented the NIST SP 800-171 security controls often struggle with the documentation, evidence collection, and scheduling required to complete certification. The result has been that many qualified businesses simply decide not to pursue Department of War opportunities.
That creates a larger problem.
The Defense Industrial Base depends heavily on innovative small businesses. When compliance costs become too burdensome, fewer companies compete for contracts, reducing competition and limiting innovation. The Department of War acknowledged these concerns as a key reason for pausing Phase II while it evaluates improvements to the program.
It's important to note that this announcement should not be interpreted as a relaxation of cybersecurity requirements. Contractors that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) are still expected to implement the required security controls, and the underlying contractual obligations—including protecting CUI in accordance with NIST SP 800-171 where applicable—remain unchanged. Only the immediate requirement for mandatory third-party C3PAO assessments has been suspended while the program is reviewed.
Our recommendation to organizations is simple: don't stop preparing.
Companies that continue implementing NIST SP 800-171, documenting their security controls, performing regular assessments, and maturing their cybersecurity programs will be in a much stronger position regardless of what changes ultimately emerge from the review. Good cybersecurity is still good business, whether it's required by regulation or expected by your customers.
At Penn Parsons, we continue helping organizations build practical cybersecurity programs that satisfy today's requirements while preparing them for tomorrow's. Whether CMMC ultimately returns in its current form or evolves into a more streamlined model, organizations that invest in strong security fundamentals today will be the ones best positioned to compete for future government contracts.
Department of War Announcement can be viewed here:
https://www.war.gov/News/News-Stories/Article/Article/4542849/war-department-changes-cybersecurity-maturity-model-certification-requirements/