On July 13, 2026, the Department of Defense halted the planned November 10 expansion of mandatory Cybersecurity Maturity Model Certification audits, preserving only the lighter self-assessment requirements that have been in place since Phase I. A Pentagon task force now has 60 days to craft a leaner, more scalable replacement—one that Defense Department CIO Kirsten Davies says must stop being “red tape-driven” and start measuring real security outcomes.
The Immediate Freeze: What’s on Hold and What Isn’t
The July 13 action suspends Phase II CMMC implementation, which would have forced thousands of defense contractors handling Controlled Unclassified Information (CUI) to pass pricey third-party assessments. Instead, the existing Phase I self-attestation framework remains the compliance floor.
That does not mean cybersecurity obligations vanish. Contractors must still:
- Meet the safeguarding requirements in their contracts and in the Defense Federal Acquisition Regulation Supplement (DFARS).
- Submit self-assessments that attest to their security posture.
- Protect Federal Contract Information (FCI) and CUI according to the NIST SP 800-171 standards that underpin Level 2.
Under Secretary of Defense for Acquisition and Sustainment Michael Duffey cited an estimated average Level 2 compliance cost of $150,000 per contractor—money he argued would be better spent on actual security hardening and manufacturing. During a tour of defense manufacturer Kform on July 15, Davies acknowledged the program had strayed from its original national security purpose. “What it has become,” she said, “is a burdensome red tape-driven check-the-box point-in-time view of a company’s handling of this federal data.”
The department is also gathering public input through a request for information on SAM.gov, asking contractors and assessors to detail the financial and operational toll of the CMMC regime.
Who Bears the Brunt—and Who Gets Breathing Room
For small and medium defense suppliers, the pause is a temporary reprieve from an approaching financial cliff. Kform CEO Callye Keen put it bluntly: “Year after year we have to make the decision: Do I buy another piece of equipment? Do I invest in another robot? Do I hire another engineer, or do I meet CMMC compliance?”
Larger primes with dedicated governance, risk, and compliance teams, along with dedicated endpoint management and security staff, absorb such audits more easily. A small machine shop or engineering firm, by contrast, often lacks the resources to simultaneously fund a CNC machine, hire an engineer, and pay a third-party assessor.
For the Windows administrators and IT pros who keep these firms running, the freeze doesn’t change the immediate technical to-do list. Even without a scheduled audit, the same controls that would satisfy an assessor—multifactor authentication, disciplined patch management, centralized logging, least-privilege access—remain essential for defending against ransomware and data theft. The difference is that the evidence-gathering scramble gets postponed, giving teams time to instrument their environments for continuous monitoring rather than a single snapshot.
How the Program Reached a Breaking Point
CMMC was born from a genuine problem: self-attestation alone proved unreliable. Repeated assessments by the Defense Contract Management Agency’s Defense Industrial Base Cybersecurity Assessment Center found that contractors routinely overreported their security posture by 100 points or more. The response was a tiered certification model that would force independent verification for companies handling sensitive information.
But scaling that model has been an operational nightmare. The defense industrial base numbers roughly 50,000 prime contractors and a much larger web of subcontractors and suppliers. The pool of certified third-party assessors is small, leading to long wait times, rising prices, and a system that favors firms with deep pockets. “If they cut third-party assessment, they’re taking a tool out of their toolbox, a scalable tool,” warned Jacob Hill, a director at Summit Seven Cybersecurity. “They still can assess through DIBCAC, but they are limited auditors.”
Matthew Travis, CEO of the certifying body Cyber AB, insisted that independent verification remains indispensable, saying it would “prove itself indispensable under a rigorous review.” In practice, the Pentagon must now balance that indispensability against the risk of pricing small businesses out of the defense supply chain.
What This Means for Your Windows Security Operations
Most defense contractors run their operations on Windows endpoints, Active Directory, and Microsoft 365 or Azure tenants. The CMMC pause does not alter the fundamental security priorities for those environments. Attackers looking for CUI will still target overprivileged accounts, unpatched workstations, and misconfigured cloud tenants.
Security teams should continue to:
- Enforce phishing-resistant multifactor authentication for every administrator and remote user.
- Keep Windows 10/11 builds current and apply security patches within tight windows.
- Deploy endpoint detection and response (EDR) across all devices—including engineering and factory-floor systems.
- Separate privileged accounts and eliminate shared local-administrator credentials.
- Protect audit logs from tampering and centralize them in a SIEM or Sentinel instance.
- Test backups for integrity and recoverability.
If the review yields a shift toward continuous, outcome-based validation—an idea championed by former Principal Deputy CIO Leslie Beavers—then telemetry from Microsoft Defender for Endpoint, Intune, and Entra ID could become more valuable than a static compliance binder. Companies that can demonstrate high patch compliance, low mean time to remediate critical vulnerabilities, and strong identity hygiene may find themselves in a better position irrespective of the final certification model.
Your Action Plan for the Next 60 Days
While Washington debates policy, your security posture shouldn’t idle. Here’s what to do now:
- Keep investing. Do not pause endpoint upgrades, identity projects, or detection tool deployments. The threat landscape will not wait for the task force.
- Automate evidence collection. Configure MD-Insider reports, patch dashboards, and configuration baselines to generate compliance evidence as a byproduct of daily operations.
- Harden identities ruthlessly. Audit every privileged account, remove legacy authentication protocols, and apply conditional access policies to all users.
- Segment your network. Isolate manufacturing, IoT, and legacy systems behind firewalls and jump hosts so a compromise on one subnet doesn’t spread.
- Engage with the review. Respond to the SAM.gov request for information if the compliance burden has hit your business. Concrete data from real companies will shape the next framework.
- Prepare for outcome-based validation. Start tracking metrics like patch compliance percentage, average time to remediate, and user awareness training completion. These may replace or supplement traditional audits.
Looking Past the 60-Day Window
A complete walk-back of CMMC is unlikely. The Pentagon still needs a mechanism to verify that contractors protect federal information. What’s emerging instead is a hybrid design built on a few predictable pillars:
- Risk-tiered verification. Higher-risk contractors and those with incident histories will face independent audits; lower-risk firms may rely on self-attestation plus automated external scans.
- Continuous monitoring. Regular automated checks of public-facing assets, endpoint health, and identity posture will supplement point-in-time evidence.
- Recognition of prior investments. Companies that have already completed a credible assessment or operate mature security programs should receive credit in any new system.
Davies summed up the philosophy driving the review: “You can outsource the work, but you can’t outsource the risk.” A durable successor to the current CMMC plan will treat cybersecurity as a continuous discipline, rewarding real improvements in Windows endpoint security, identity protection, and incident readiness—and it will reserve the most costly audits for environments where the risk truly warrants them.