The U.S. Department of Defense has suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, halting the planned move to mandatory third-party assessments for defense contractors that had been scheduled to begin in November. The Pentagon said Phase 1 self-assessments and other existing cybersecurity obligations will remain in effect while it pauses later CMMC phases and conducts a 60-day review of the broader framework.
Defense officials said the review is aimed at reducing compliance costs, administrative burden, and barriers for small, medium-sized, and nontraditional firms in the defense industrial base, while preserving core security requirements such as NIST SP 800-171 controls. A newly formed CMMC reform task force will collect industry feedback on cost and effectiveness, and officials also cited a shortage of approved third-party assessors as a practical reason the original Phase 2 rollout was no longer feasible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Defense suspended Phase 2 of the Cybersecurity Maturity Model Certification program and paused later phases while beginning a 60-day review of the framework. During the review, Phase 1 self-assessments remain in place, and a newly formed reform task force will gather industry feedback on compliance costs, administrative burden, and the effectiveness of current controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcedefensescoop.com
Open sourcetechrepublic.com
Open sourcecysecurity.news
Open sourcescworld.com
Open sourcesecurityweek.com
Open sourcegovconwire.com
Open sourcenextgov.com
Open sourcecrowdstrike.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.