There you have it! The Pentagon just suspended Phase 2 of CMMC and killed the third-party audit r…
July 14, 2026 · 0 likes · 0 comments
China Threat Defense Cybersecurity AI
There you have it! The Pentagon just suspended Phase 2 of CMMC and killed the third-party audit requirement for defense contractors. Effective immediately. The tier that was supposed to force every company touching controlled unclassified information to get certified by outside assessors starting November 10 is dead for now.
I was never a fan of CMMC.
Not because security doesn't matter. Because they built it on the wrong foundation. CMMC runs on NIST 800-171. Meanwhile the rest of the government runs on 800-53 — FedRAMP, every ATO ever signed off on was 800-53. So we created an entirely separate compliance universe for the defense industrial base and then acted surprised when small businesses couldn't afford to live in two of them at once.
The DoW CIO put it perfectly to reporters: the math "just simply doesn't math." The SBA found the compliance costs were literally chasing innovative small companies out of the defense business. That is not a rounding error. That is the exact opposite of what you want when you are trying to out-build China.
So killing the bottleneck? I get it. CMMC was a massive impediment to attracting the small and mid-size shops the DOW actually needs.
But let me be honest about the other half.
We still need these companies to be secure — and that is not an easy feat. China has spent years hacking l contractors to steal weapons designs, and the weakest-link problem is real: a mid-tier machine shop with lousy cyber can be the backdoor into a fighter program. Nobody has shown yet that a self-attestation plus the occasional government spot-check catches what an independent audit catches.
The fix was never "audit harder" or "audit never." The fix is to stop running a bespoke 800-171 island and align the whole thing to 800-53 so a company earns its security posture ONCE and carries it across FedRAMP, ATOs, and DoW. Real controls that reduce risk, not paperwork that generates invoices.
The 60-day reform task force is the chance to actually do that. Use it.
And notice who is actually upset about the suspension. Not the warfighter. Not the small business owner. It is the assessor cabal — the third-party certification shops that spun up an entire business model around a mandatory stamp. They built a toll booth, and P2 was going to make every contractor pay to pass through. When the loudest objection to killing a bottleneck comes from the people who were selling tickets to the bottleneck, that tells you exactly the problem.
The real exception to this, are companies like Cloudfit and their easyCMMC product which brings a real turnkey SOLUTION to implement a stack compliant with CMMC and common sense security on day 1. This is what SMBs need and Kirsten Davies is paying attention.
Full breakdown here: https://lnkd.in/eqWWm6Hn
What are your thoughts — cut the compliance tax, or did we just hand our adversaries a softer target?
I was never a fan of CMMC.
Not because security doesn't matter. Because they built it on the wrong foundation. CMMC runs on NIST 800-171. Meanwhile the rest of the government runs on 800-53 — FedRAMP, every ATO ever signed off on was 800-53. So we created an entirely separate compliance universe for the defense industrial base and then acted surprised when small businesses couldn't afford to live in two of them at once.
The DoW CIO put it perfectly to reporters: the math "just simply doesn't math." The SBA found the compliance costs were literally chasing innovative small companies out of the defense business. That is not a rounding error. That is the exact opposite of what you want when you are trying to out-build China.
So killing the bottleneck? I get it. CMMC was a massive impediment to attracting the small and mid-size shops the DOW actually needs.
But let me be honest about the other half.
We still need these companies to be secure — and that is not an easy feat. China has spent years hacking l contractors to steal weapons designs, and the weakest-link problem is real: a mid-tier machine shop with lousy cyber can be the backdoor into a fighter program. Nobody has shown yet that a self-attestation plus the occasional government spot-check catches what an independent audit catches.
The fix was never "audit harder" or "audit never." The fix is to stop running a bespoke 800-171 island and align the whole thing to 800-53 so a company earns its security posture ONCE and carries it across FedRAMP, ATOs, and DoW. Real controls that reduce risk, not paperwork that generates invoices.
The 60-day reform task force is the chance to actually do that. Use it.
And notice who is actually upset about the suspension. Not the warfighter. Not the small business owner. It is the assessor cabal — the third-party certification shops that spun up an entire business model around a mandatory stamp. They built a toll booth, and P2 was going to make every contractor pay to pass through. When the loudest objection to killing a bottleneck comes from the people who were selling tickets to the bottleneck, that tells you exactly the problem.
The real exception to this, are companies like Cloudfit and their easyCMMC product which brings a real turnkey SOLUTION to implement a stack compliant with CMMC and common sense security on day 1. This is what SMBs need and Kirsten Davies is paying attention.
Full breakdown here: https://lnkd.in/eqWWm6Hn
What are your thoughts — cut the compliance tax, or did we just hand our adversaries a softer target?