Defense contractors, both primes and subs, should continue to comply with the Department of Defense’s cybersecurity regulation despite Phase 2 being postponed, experts told Manufacturing Dive.
The agency temporarily paused Phase 2 of the Cybersecurity Maturity Model Certification program on July 13. CMMC focuses on verifying contractors that have implemented required security measures necessary to safeguard federal contract information not intended for public release. The regulations also shield controlled unclassified information created or owned by or for the government that’s deemed sensitive.
Two CMMC rules were finalized and went into effect in 2024: One that oversees the legal contractual requirements and another that establishes the structural framework and streamline the security levels, from five levels to three.
Phase 1 of the CMMC program began on Nov. 10, 2025 and remains in place. Phase 2 was set to begin exactly a year after.
During the Phase 2 pause, DOD will establish a CMMC Reform Task Force and conduct a 60-day review charged with restructuring DOD’s supply chain cybersecurity approach so that it “strictly aligns” with the agency’s Acquisition Transformation Strategy, according to a July 13 memo by CIO Kirsten Davies.
After the 60 days have passed, the task force will have 15 days to write up recommendations, Matthew Travis, CEO, Cyber AB, said during a July 28 town hall. Congractors may see what the CMMC group’s recommendations are in early October, he added.
The stakeholders in DOD's CMMC Task Force
The ATS directive, released in November 2025, focuses on increasing and accelerating production capacity for key systems, weapons and munitions for the U.S. military and prioritizing the country’s allies and partners.
The task force will also consider feedback from the defense industry through a request for information, which closed on Aug. 14.
The 60-day timeframe only pertains to the review, not the Phase 2 pause, said Brian Kirk, director of cybersecurity at accounting firm Cherry Bekaert.
To spend or not to spend
Costs to implement CMMC requirements vary from contract to contract, as well as the types of sensitive information companies have access to and the environments they operate in, Kirk said.
Many contractors have commercial and defense operations, and some companies have to determine how much of their revenue comes from the latter segment, he said. They also have to decide whether defense compliance costs are worth the revenue.
Business owners should consider the opportunity to get certified and evaluate whether they can incur the compliance costs for the chance to win additional contracts.
“It's kind of a double-edged sword, depending on where you are, and your CMMC journey, and whether you’re at risk of not being compliant or you’re in good shape,” Kirk said.
CMMC defense contractor levels explained
The ATS directive is supposed to lower barriers in an effort to reduce burdens on small, medium-sized and nontraditional defense businesses.
However, an analysis by the Small Business Administration estimated that compliance costs can reach up to $593,800 per CMMC verification for small entities that require third-party assessments. For small firms that conduct self-assessments, the estimated compliance costs would be about $388,600.
Had Phase 2 launched Nov. 10, the cybersecurity regulations would have required more than 120,000 small defense industrial based businesses to seek out compliance with one of over 100 approved assessors.
“Rushing the certification process would have increased assessment costs, delayed certification, and locked otherwise qualified suppliers out of the defense contracting process, threatening our national security,” the SBA said in a statement. “For small manufacturers and other defense suppliers, those delays mean lost revenue, reduced competition, and greater strain on critical supply chains.”
Separate data found 302 U.S.-based defense contractors spent an average of $155,204 in compliance costs a year, according to a survey conducted by Merrill Research and commissioned by CyberSheath.
“The comparison isn’t perfectly apples-to-apples, as the SBA estimate reflects a one-time certification cost for small businesses, while this survey measures annual cybersecurity spending across contractors of varying sizes,” CyberSheath said in the report. “However, the magnitude of the difference is still noteworthy.”
The big debate is the cost of the assessment, said Ryan Heidorn, chief technology officer at IT and cybersecurity services provider C3.
“The argument would be that the implementation is what’s been in contracts under default for a decade,” Heidorn said. “CMMC is not adding to that cost, other than to say you need to go get a third-party assessment to verify that you've done the implementation.”
CMMC has been in the works since 2019, and in Heidorn’s view, an “enforcement mechanism” for cybersecurity requirements under the Defense Federal Acquisition Regulation Supplement, or DFARS.
“Any manufacturer on a defense supply chain is going to have those DFARS flow-down clauses in their contracts,” he said.
Moreover, Congress included the framework for DOD to improve its cybersecurity under the National Defense Authorization Act for fiscal year 2020.
Contractors have also been required to implement security to protect controlled unclassified information due to a separate law in 2016.
However, Heidorn’s clients have reported that contractual cybersecurity obligations have not been consistently enforced for many years. A 2019 DOD Office of Inspector General audit came to the same conclusion, finding that contractors did not consistently implement National Institute of Standards and Technology requirements to safeguard sensitive information.
The audit also found that DOD’s component contracting offices did not establish processes to verify whether a company complied with NIST’s regulations before awarding a contract. The agency also did not set up notification procedures to inform companies whether they were meeting the contract requirements.
“So when they’re looking at CMMC, they’re saying, ‘Oh, my cost is $100,000 because they never did the implementation to begin with,’” Heidorn said. “And so for those organizations that have effectively kicked the can on security requirements, they're now looking at the cost of implementation plus the cost of certification.”
Timeline and deadline misconceptions
There has been a lot of confusion regarding the Phase 2 implementation date, Heidorn and Kirk said.
For one, DOD contracting officers have mistakenly treated Nov. 10 as the Phase 2 deadline.
“It was never intended to be a deadline,” Kirk said. “It was only intended to be when the DOD contracting officers can start to require third-party assessments into contracts.”
Many prime contractors such as Boeing and Lockheed Martin have also treated Nov. 10 as a deadline, issuing CMMC notices to their suppliers over the past few months. For example, Leonardo DRS told its level 2 suppliers before the program pause that they had to be CMMC verified by Nov. 10.
“Primes pushing their suppliers to be CMMC-verified by then is their way of preventing supply chain risks,” Kirk said. “If the supplier doesn’t get certified, then the prime contractor has to decide whether or not the supplier is critical or find another. The prime can also decide whether to help out or acquire the supplier to make them compliant.”
Implementing the cybersecurity requirements can take months, depending on the complexity of the supplier’s operations environment, Heidorn said.
“You’re looking at like nine months, 12 months, even up to 18 months, and so you might be out of runway,” Heidorn said. “I think that's a big factor in what we’re seeing with this pause right now is that a lot of contractors were out of runway.”
What suppliers should do during the pause
It’s unknown when DOD will resume Phase 2. After the CMMC Task Force completes its 60-day review and reports its findings to the CIO and Undersecretary of Defense Michael Duffy, they will suggest changes to the program that comply with federal laws.
Any modifications they come up with will have to go through the rulemaking process, which can take up to two years.
On the positive side, the delay gives contractors more time to understand and implement the CMMC requirements, Kirk said. “I think one of the pros is that it just kind of reduces the pressure valve that was building within the CMMC ecosystem.
On the other hand, they pause could give entities a reason to continue delaying implementation. “By no means should this be construed as we can let the foot off the gas for contractors,” Kirk said.
The pause is also an opportunity for companies to continue carrying out the CMMC requirements in their operations, Heidorn said.
“Because when we get to the other side of this pause, there's going to be some sort of verification mechanism, and the timeline's still going to be the same,” Heidorn said. “And if you did nothing, you're going to be in an even worse shape.”