DoD Plans CMMC Listening Sessions as Questions Swirl Around Review
**The Pentagon is hitting pause on the most controversial part of its cybersecurity certification program. Now they want to hear directly from the contractors who've been struggling to comply.**
---
## Introduction: A Program in Limbo
On July 13, 2026, the Defense Department did something that sent shockwaves through the defense industrial base. It suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program—the part that would have required costly third-party audits for thousands of contractors starting November 10.
The suspension wasn't a retreat from cybersecurity. It was an admission that the program, as currently designed, was creating "prohibitive costs and unacceptable burdens" for the very companies the Pentagon needs to keep its supply chain strong.
Now, the DoD is launching a 60-day "top-to-bottom" review of the entire CMMC program. And as part of that review, officials will hold listening sessions across the country to get feedback from defense contractors—"especially the small businesses, and from the cybersecurity operators and executives who serve your companies," said DoD Chief Information Officer Kirsten Davies.
**Here's what's happening, what's at stake, and what defense contractors need to know.**
---
## The Backstory: Why CMMC Is Being Overhauled
### A Program Born from Threats
CMMC was first introduced during the first Trump administration to ensure that defense contractors and subcontractors were properly protecting sensitive government information from increasingly sophisticated cyberattacks. The program created a tiered cybersecurity framework that graded companies based on the sensitivity of the work they performed.
In 2021, the Biden administration streamlined the program from five levels to three under "CMMC 2.0". The final rule took effect on November 10, 2025, launching Phase I with self-assessment requirements. Phase II—which would have required mandatory third-party assessments by CMMC Third-Party Assessment Organizations (C3PAOs)—was set to begin November 10, 2026.
### The Breaking Point
What changed? According to DoD CIO Kirsten Davies, the department had been receiving "recent data and feedback" that painted a troubling picture.
Small businesses—the engine of American innovation and a critical part of the defense supply chain—were being priced out of the market. The combination of prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines was "actively forcing innovative new entrants and small businesses to opt out of DoD contracts and freezing critical suppliers out of the market," Davies wrote in a memo.
The Small Business Administration had been raising these concerns for months. In a statement, SBA Administrator Kelly Loeffler applauded the DoD's decision, noting that CMMC compliance was "becoming an untenable barrier pushing them out of the Defense Industrial Base".
### The Hegseth Factor
The suspension also aligns with Defense Secretary Pete Hegseth's Acquisition Transformation System (ATS) initiative, which prioritizes speed, lowering barriers for new entrants, and eliminating bureaucratic red tape.
"The current iteration of the CMMC program, while intended to enhance security, imposes significant and often prohibitive burdens on the Defense Industrial Base," Davies wrote. "While cybersecurity is essential, administrative compliance cannot come at the cost of warfighting capability and industrial base growth".
---
## The Listening Sessions: What We Know
### A "Top-to-Bottom" Review
The review team met for the first time on Thursday, July 16, just three days after the suspension was announced. Davies, along with Small Business Administrator Kelly Loeffler and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey, toured the factory floor at Kform, a small defense manufacturer in Sterling, Virginia, to see the challenges firsthand.
Davies said the review could lead to "everything from an overhaul, to small tweaks here and there". But she emphasized that the goal isn't change for the sake of change. "What we're not going to do is death by a thousand cuts and just change for the sake of change," she said.
### How to Participate
The DoD has published a Request for Information (RFI) on the CMMC review. Responses are due by **August 14**.
The department wants feedback on:
- Cost drivers and administrative burdens tied to CMMC compliance
- Which NIST 800-171 security controls deliver meaningful risk reduction
- How companies are already using commercial cybersecurity tools and managed services
- How the DoD might recognize those tools in a compliance framework instead of requiring separate assessments
The listening sessions will supplement the RFI, giving contractors a chance to speak directly with officials. The review team has 60 days to gather feedback and review the program, then 15 days to provide a report with recommendations. The final report is expected by late September.
---
## What's Suspended—and What's Not
### Phase II Is Paused
The suspension applies to Phase II requirements, which would have mandated third-party C3PAO assessments for most contractors handling Controlled Unclassified Information (CUI). All pending and future CMMC implementation milestones are also suspended "until further notice".
### Phase I Remains in Effect
Phase I self-assessment requirements, which went into effect in November 2025, remain in place. DoD programs can continue writing CMMC self-assessment requirements into new contracts.
### The Legal Obligation to Protect Data Remains
Importantly, the suspension does not eliminate the legal requirement for defense contractors to protect federal data. "We are not reducing cybersecurity through this measure," Davies said. "We are reducing the red tape".
---
## The Industry Reaction: Relief, Confusion, and Questions
### Relief for Small Businesses
For many small defense contractors, the suspension is a welcome reprieve. The costs of preparing for CMMC audits—hiring consultants, implementing new controls, and paying for third-party assessments—had been a significant barrier.
Davies herself called the current CMMC assessments a "burdensome, red-tape ridden, check-the-box, point-in-time view of a company's handling" of sensitive data.
### Lingering Questions
But the suspension also creates uncertainty. Contractors who have already invested heavily in CMMC preparation are left wondering whether their efforts will be recognized—or whether the program will change so much that their investments become obsolete.
Industry groups have also raised questions about subcontractor flow-down requirements and the lack of a standardized mechanism for verifying compliance across the supply chain.
### The Assessor Ecosystem in Limbo
The C3PAO ecosystem—the third-party assessors who were preparing to conduct the audits—is now in limbo. Davies did not say whether the review would eliminate third-party assessments altogether. But the suspension of Phase II has thrown the entire assessment industry into uncertainty.
---
## What Comes Next: The Timeline
| Date | Milestone |
|------|-----------|
| July 13, 2026 | DoD suspends Phase II, launches 60-day review |
| July 16, 2026 | Review team meets for first time |
| Aug. 14, 2026 | RFI responses due |
| Mid-September 2026 | Review team finalizes recommendations |
| Late September 2026 | Report made public (expected) |
Davies said the department is "hoping shortly thereafter that we'll be able to make that report public along with the recommendations".
---
## How to Get Involved: Practical Steps for Contractors
**1. Submit RFI responses by August 14.**
The RFI is the most direct way to provide input. Be specific about which controls create the most burden and which commercial tools you're already using.
**2. Monitor announcements for listening sessions.**
The DoD has not yet released dates or locations, but officials have said they will hold sessions across the country.
**3. Continue Phase I compliance.**
The suspension does not eliminate self-assessment requirements. Contractors should continue preparing for self-assessments under the existing framework.
**4. Don't stop preparing.**
Even though Phase II is paused, the legal requirement to protect CUI remains. Continue implementing NIST SP 800-171 controls.
**5. Document your efforts.**
If the review results in a new framework that recognizes commercial tools, your documentation will be valuable.
---
## Frequently Asked Questions
### Q: Why did the DoD suspend CMMC Phase II?
A: The DoD cited prohibitive compliance costs, severe shortages in third-party assessment capacity, and concerns that small businesses were being forced out of the defense industrial base. The suspension aligns with Secretary Hegseth's Acquisition Transformation System initiative.
### Q: Does this mean CMMC is going away?
A: Not necessarily. The DoD is conducting a 60-day review that could lead to "everything from an overhaul, to small tweaks here and there". But the legal requirement for contractors to protect sensitive data remains.
### Q: Are self-assessments still required?
A: Yes. Phase I self-assessment requirements, which went into effect in November 2025, remain in place.
### Q: What should I do if I'm a small contractor?
A: Submit comments to the RFI by August 14, monitor for listening session announcements, continue Phase I self-assessments, and keep implementing NIST 800-171 controls.
### Q: What happens to contracts that already included Phase II requirements?
A: DoD has directed program managers and contracting officers to amend or modify solicitations and contracts that contain the suspended Phase II requirements as soon as possible.
---
## Conclusion: A Program at a Crossroads
The CMMC suspension is a recognition that the Pentagon's cybersecurity certification program, however well-intentioned, had become a barrier to the very companies it was meant to protect. The "burdensome, red-tape ridden" assessments that Davies described were pushing small businesses out of the defense industrial base—a risk the DoD simply could not ignore.
Now, the listening sessions and the 60-day review offer a real opportunity to recalibrate. The goal, as Davies put it, is to "incorporate the voice of small companies to make sure that we are truly reducing barriers to entry for them to do business with DoD".
But the timeline is tight. The review team has 60 days to gather feedback and 15 days to deliver recommendations. Contractors have until August 14 to respond to the RFI. And the entire C3PAO ecosystem is waiting to see what comes next.
For defense contractors, the message is clear: the suspension is a reprieve, not a pardon. The legal obligation to protect sensitive data remains. The self-assessments continue. And the future of CMMC—whether overhauled, tweaked, or replaced—will be shaped by the voices of the companies that live with its requirements every day.
**The listening sessions are coming. The questions are swirling. And the answers will determine the future of cybersecurity in the defense industrial base.**
---
## Disclaimer
**IMPORTANT:** This article is for informational and educational purposes only and does not constitute legal or professional advice. CMMC requirements, suspension details, and compliance obligations are subject to change. Contractors should consult with qualified legal and cybersecurity professionals regarding their specific compliance obligations. The information contained herein is based on publicly available sources and reflects the author's understanding as of the publication date.
---
*Published: July 20, 2026*
--Read more-
**Tags:** CMMC, Cybersecurity Maturity Model Certification, DoD CMMC, CMMC Phase II, defense contractors, C3PAO, cybersecurity compliance, NIST 800-171, Department of Defense, CMMC review, Kirsten Davies, small business defense contractors, defense industrial base, CMMC listening sessions, CMMC RFI, Acquisition Transformation System, Pete Hegseth, CMMC self-assessment, defense cybersecurity, government contracting

No comments:
Post a Comment