19.7.26

DoD Plans CMMC Listening Sessions as Questions Swirl Around Review


 DoD Plans CMMC Listening Sessions as Questions Swirl Around Review


**The Pentagon is hitting pause on the most controversial part of its cybersecurity certification program. Now they want to hear directly from the contractors who've been struggling to comply.**


---


## Introduction: A Program in Limbo


On July 13, 2026, the Defense Department did something that sent shockwaves through the defense industrial base. It suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program—the part that would have required costly third-party audits for thousands of contractors starting November 10.


The suspension wasn't a retreat from cybersecurity. It was an admission that the program, as currently designed, was creating "prohibitive costs and unacceptable burdens" for the very companies the Pentagon needs to keep its supply chain strong.


Now, the DoD is launching a 60-day "top-to-bottom" review of the entire CMMC program. And as part of that review, officials will hold listening sessions across the country to get feedback from defense contractors—"especially the small businesses, and from the cybersecurity operators and executives who serve your companies," said DoD Chief Information Officer Kirsten Davies.


**Here's what's happening, what's at stake, and what defense contractors need to know.**


---


## The Backstory: Why CMMC Is Being Overhauled


### A Program Born from Threats


CMMC was first introduced during the first Trump administration to ensure that defense contractors and subcontractors were properly protecting sensitive government information from increasingly sophisticated cyberattacks. The program created a tiered cybersecurity framework that graded companies based on the sensitivity of the work they performed.


In 2021, the Biden administration streamlined the program from five levels to three under "CMMC 2.0". The final rule took effect on November 10, 2025, launching Phase I with self-assessment requirements. Phase II—which would have required mandatory third-party assessments by CMMC Third-Party Assessment Organizations (C3PAOs)—was set to begin November 10, 2026.


### The Breaking Point


What changed? According to DoD CIO Kirsten Davies, the department had been receiving "recent data and feedback" that painted a troubling picture.


Small businesses—the engine of American innovation and a critical part of the defense supply chain—were being priced out of the market. The combination of prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines was "actively forcing innovative new entrants and small businesses to opt out of DoD contracts and freezing critical suppliers out of the market," Davies wrote in a memo.


The Small Business Administration had been raising these concerns for months. In a statement, SBA Administrator Kelly Loeffler applauded the DoD's decision, noting that CMMC compliance was "becoming an untenable barrier pushing them out of the Defense Industrial Base".


### The Hegseth Factor


The suspension also aligns with Defense Secretary Pete Hegseth's Acquisition Transformation System (ATS) initiative, which prioritizes speed, lowering barriers for new entrants, and eliminating bureaucratic red tape.


"The current iteration of the CMMC program, while intended to enhance security, imposes significant and often prohibitive burdens on the Defense Industrial Base," Davies wrote. "While cybersecurity is essential, administrative compliance cannot come at the cost of warfighting capability and industrial base growth".


---


## The Listening Sessions: What We Know


### A "Top-to-Bottom" Review


The review team met for the first time on Thursday, July 16, just three days after the suspension was announced. Davies, along with Small Business Administrator Kelly Loeffler and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey, toured the factory floor at Kform, a small defense manufacturer in Sterling, Virginia, to see the challenges firsthand.


Davies said the review could lead to "everything from an overhaul, to small tweaks here and there". But she emphasized that the goal isn't change for the sake of change. "What we're not going to do is death by a thousand cuts and just change for the sake of change," she said.


### How to Participate


The DoD has published a Request for Information (RFI) on the CMMC review. Responses are due by **August 14**.


The department wants feedback on:

- Cost drivers and administrative burdens tied to CMMC compliance

- Which NIST 800-171 security controls deliver meaningful risk reduction

- How companies are already using commercial cybersecurity tools and managed services

- How the DoD might recognize those tools in a compliance framework instead of requiring separate assessments


The listening sessions will supplement the RFI, giving contractors a chance to speak directly with officials. The review team has 60 days to gather feedback and review the program, then 15 days to provide a report with recommendations. The final report is expected by late September.


---


## What's Suspended—and What's Not


### Phase II Is Paused


The suspension applies to Phase II requirements, which would have mandated third-party C3PAO assessments for most contractors handling Controlled Unclassified Information (CUI). All pending and future CMMC implementation milestones are also suspended "until further notice".


### Phase I Remains in Effect


Phase I self-assessment requirements, which went into effect in November 2025, remain in place. DoD programs can continue writing CMMC self-assessment requirements into new contracts.


### The Legal Obligation to Protect Data Remains


Importantly, the suspension does not eliminate the legal requirement for defense contractors to protect federal data. "We are not reducing cybersecurity through this measure," Davies said. "We are reducing the red tape".


---


## The Industry Reaction: Relief, Confusion, and Questions


### Relief for Small Businesses


For many small defense contractors, the suspension is a welcome reprieve. The costs of preparing for CMMC audits—hiring consultants, implementing new controls, and paying for third-party assessments—had been a significant barrier.


Davies herself called the current CMMC assessments a "burdensome, red-tape ridden, check-the-box, point-in-time view of a company's handling" of sensitive data.


### Lingering Questions


But the suspension also creates uncertainty. Contractors who have already invested heavily in CMMC preparation are left wondering whether their efforts will be recognized—or whether the program will change so much that their investments become obsolete.


Industry groups have also raised questions about subcontractor flow-down requirements and the lack of a standardized mechanism for verifying compliance across the supply chain.


### The Assessor Ecosystem in Limbo


The C3PAO ecosystem—the third-party assessors who were preparing to conduct the audits—is now in limbo. Davies did not say whether the review would eliminate third-party assessments altogether. But the suspension of Phase II has thrown the entire assessment industry into uncertainty.


---


## What Comes Next: The Timeline


| Date | Milestone |

|------|-----------|

| July 13, 2026 | DoD suspends Phase II, launches 60-day review |

| July 16, 2026 | Review team meets for first time |

| Aug. 14, 2026 | RFI responses due |

| Mid-September 2026 | Review team finalizes recommendations |

| Late September 2026 | Report made public (expected) |


Davies said the department is "hoping shortly thereafter that we'll be able to make that report public along with the recommendations".


---


## How to Get Involved: Practical Steps for Contractors


**1. Submit RFI responses by August 14.**

The RFI is the most direct way to provide input. Be specific about which controls create the most burden and which commercial tools you're already using.


**2. Monitor announcements for listening sessions.**

The DoD has not yet released dates or locations, but officials have said they will hold sessions across the country.


**3. Continue Phase I compliance.**

The suspension does not eliminate self-assessment requirements. Contractors should continue preparing for self-assessments under the existing framework.


**4. Don't stop preparing.**

Even though Phase II is paused, the legal requirement to protect CUI remains. Continue implementing NIST SP 800-171 controls.


**5. Document your efforts.**

If the review results in a new framework that recognizes commercial tools, your documentation will be valuable.


---


## Frequently Asked Questions


### Q: Why did the DoD suspend CMMC Phase II?


A: The DoD cited prohibitive compliance costs, severe shortages in third-party assessment capacity, and concerns that small businesses were being forced out of the defense industrial base. The suspension aligns with Secretary Hegseth's Acquisition Transformation System initiative.


### Q: Does this mean CMMC is going away?


A: Not necessarily. The DoD is conducting a 60-day review that could lead to "everything from an overhaul, to small tweaks here and there". But the legal requirement for contractors to protect sensitive data remains.


### Q: Are self-assessments still required?


A: Yes. Phase I self-assessment requirements, which went into effect in November 2025, remain in place.


### Q: What should I do if I'm a small contractor?


A: Submit comments to the RFI by August 14, monitor for listening session announcements, continue Phase I self-assessments, and keep implementing NIST 800-171 controls.


### Q: What happens to contracts that already included Phase II requirements?


A: DoD has directed program managers and contracting officers to amend or modify solicitations and contracts that contain the suspended Phase II requirements as soon as possible.


---


## Conclusion: A Program at a Crossroads


The CMMC suspension is a recognition that the Pentagon's cybersecurity certification program, however well-intentioned, had become a barrier to the very companies it was meant to protect. The "burdensome, red-tape ridden" assessments that Davies described were pushing small businesses out of the defense industrial base—a risk the DoD simply could not ignore.


Now, the listening sessions and the 60-day review offer a real opportunity to recalibrate. The goal, as Davies put it, is to "incorporate the voice of small companies to make sure that we are truly reducing barriers to entry for them to do business with DoD".


But the timeline is tight. The review team has 60 days to gather feedback and 15 days to deliver recommendations. Contractors have until August 14 to respond to the RFI. And the entire C3PAO ecosystem is waiting to see what comes next.


For defense contractors, the message is clear: the suspension is a reprieve, not a pardon. The legal obligation to protect sensitive data remains. The self-assessments continue. And the future of CMMC—whether overhauled, tweaked, or replaced—will be shaped by the voices of the companies that live with its requirements every day.


**The listening sessions are coming. The questions are swirling. And the answers will determine the future of cybersecurity in the defense industrial base.**


---


## Disclaimer


**IMPORTANT:** This article is for informational and educational purposes only and does not constitute legal or professional advice. CMMC requirements, suspension details, and compliance obligations are subject to change. Contractors should consult with qualified legal and cybersecurity professionals regarding their specific compliance obligations. The information contained herein is based on publicly available sources and reflects the author's understanding as of the publication date.


---


*Published: July 20, 2026*


--Read more-


**Tags:** CMMC, Cybersecurity Maturity Model Certification, DoD CMMC, CMMC Phase II, defense contractors, C3PAO, cybersecurity compliance, NIST 800-171, Department of Defense, CMMC review, Kirsten Davies, small business defense contractors, defense industrial base, CMMC listening sessions, CMMC RFI, Acquisition Transformation System, Pete Hegseth, CMMC self-assessment, defense cybersecurity, government contracting

No comments:

Post a Comment

science

science

wether & geology

occations

politics news

media

technology

media

sports

art , celebrities

news

health , beauty

business

Featured Post

The $4 Gallon Is Back: Why Your Trip to the Pump Just Got More Painful

The $4 Gallon Is Back: Why Your Trip to the Pump Just Got More Painful **Just weeks after drivers celebrated falling gas prices, the nationa...

Wikipedia

Search results

Contact Form

Name

Email *

Message *

Translate

Powered By Blogger

My Blog

Total Pageviews

Popular Posts

welcome my visitors

Welcome to Our moon light Hello and welcome to our corner of the internet! We're so glad you’re here. This blog is more than just a collection of posts—it’s a space for inspiration, learning, and connection. Whether you're here to explore new ideas, find practical tips, or simply enjoy a good read, we’ve got something for everyone. Here’s what you can expect from us: - **Engaging Content**: Thoughtfully crafted articles on [topics relevant to your blog]. - **Useful Tips**: Practical advice and insights to make your life a little easier. - **Community Connection**: A chance to engage, share your thoughts, and be part of our growing community. We believe in creating a welcoming and inclusive environment, so feel free to dive in, leave a comment, or share your thoughts. After all, the best conversations happen when we connect and learn from each other. Thank you for visiting—we hope you’ll stay a while and come back often! Happy reading, sharl/ moon light

Pages

labekes

Followers

Blog Archive

Search This Blog