On June 8, we published a piece called "CMMC Enforcement Just Got Real — and Most Contractors Aren't Ready." The argument was straightforward: the Pentagon's cybersecurity certification program was about to hit small defense contractors with requirements they couldn't afford, and the numbers didn't add up.
Yesterday, the Pentagon announced it is suspending CMMC Phase II.
The timing is striking. Phase II — the requirement for third-party assessments every three years — was scheduled to take effect November 10, 2026. That's four months from now. The Department of War just hit pause.
What Actually Happened
The Pentagon's chief information officer, Kirsten Davies, announced the "immediate suspension" of Phase II requirements on July 13. A July 10 memo released alongside the announcement is blunt about why: the current version of CMMC imposes "significant and often prohibitive burdens on the Defense Industrial Base, particularly the small and non-traditional businesses that are the engine of American innovation."
Davies put it even more plainly: "We are not reducing cybersecurity through this measure. We are reducing the red tape."
The core requirement that just got shelved was the third-party assessment. Under Phase II, contractors handling Controlled Unclassified Information would have needed both a self-assessment and an outside audit from a certified assessor — every three years. For a small machine shop in Colorado Springs with a single defense contract, that's a five-figure recurring cost with no offsetting revenue.
The Colorado Angle
Colorado's defense sector employs roughly 55,000 people, many of them at small and mid-size suppliers that feed into larger prime contractors. For those businesses, CMMC Phase II wasn't a compliance checkbox — it was an existential question. Do you spend tens of thousands on assessments and system upgrades for a contract that might represent 15% of your revenue? Or do you walk away from defense work entirely?
The Pentagon's own analysis suggested 15 to 20 percent of the defense industrial base could exit by 2027 under the current framework. That's not a cybersecurity problem. That's a supply chain problem.
What This Doesn't Mean
The suspension doesn't eliminate cybersecurity requirements. Contractors still have a legal obligation to protect federal data. The underlying NIST standards haven't changed. What's on hold is the formal certification process — the audits, the assessors, the paperwork.
Davies was explicit: "This action does not eliminate the legal requirement for our industry partners to protect federal data."
So the work of securing your systems doesn't go away. What goes away — at least for now — is the expensive, time-consuming process of proving it to a third party on a fixed schedule.
What Comes Next
The Pentagon says it's going back to the drawing board on how to verify contractor cybersecurity without crushing the small businesses it depends on. There's no timeline yet for what replaces Phase II.
For Colorado defense contractors, this is a reprieve — not a pardon. The smart move is to use the extra time to get your security house in order on your own terms, at your own pace, rather than scrambling when the next version of the requirements lands.
The fundamental problem hasn't changed: adversaries are targeting the supply chain, and the weakest link determines everyone's security. What's changed is the recognition that you can't solve that problem by making compliance so expensive that the supply chain disappears. If you're trying to figure out what this suspension means for your contracts, talk to someone who understands both the compliance landscape and the business reality.