The Pentagon paused CMMC over a labelling problem
The Department of War paused its own flagship cybersecurity rule in July 2026 and asked industry to name the single biggest cost driver. Almost every answer came back the same: nobody can agree what counts as sensitive.
By Katie Delaney · 2026-08-26 · 11 min read
The Pentagon pressed pause on its own rule#
types of Controlled Unclassified Information a defence contractor may have to correctly spot before CUI marking requirements even let a single security control get built
folkfox has sat across the table from enough defence contractors to know that a compliance deadline rarely breaks a business on its own. What breaks it is the paperwork nobody can pin down underneath the deadline. On 13 July 2026 the Department of War suspended the third-party assessment requirements of CMMC Phase 2, the tier of the Cybersecurity Maturity Model Certification programme that was due to take effect that November, and opened a 60-day review through a freshly formed CMMC Reform Task Force.
DoD CIO Kirsten Davies put the maths plainly when she announced the pause: "the math just simply doesn't math for small to medium-sized businesses." The Pentagon had leaned on roughly 100 certified third-party assessors to clear a Defence Industrial Base many times that size, and every fresh solicitation added to a queue that was never going to move fast enough. Phase 1 self-assessment, already in force since November 2025, was left standing. Phases 2 through 4 were not.
The U.S. Small Business Administration put real numbers on that squeeze: roughly $593,800 for a small firm still needing an outside audit, and about $388,600 for one eligible to self-assess. Administrator Kelly Loeffler called the framework "bureaucracy that shuts out the very companies our warfighters depend on." Both figures assume the scope of required controls is accurate. That assumption is exactly what the next problem undoes.
Why unclear cui marking requirements topped the list#
Ask the trade groups that actually filed comments and the pattern repeats without prompting. It is not the 110 controls in NIST SP 800-171 that small firms object to. It is not knowing, contract to contract, which documents those controls are meant to protect. The National Defense Industrial Association told the task force that inconsistent CUI marking requirements lead to "confusion, increased costs, and decreased security for all parties," a sentence that could sit at the top of every comment letter this review received.
Why CUI marking became the single biggest line item#
Read those five bullets together and a quieter story than "CMMC is too strict" comes into focus. Industry is not asking to protect less. It is asking to be told, clearly and in writing, what actually needs protecting, so the controls it builds match the data it is genuinely holding rather than a defensive guess at every category the government might mean.
Vague, blanket, unliftable
This document may contain information requiring protection and should be handled accordingly by all recipients.
Specific, sourced, actionable
This attachment is marked CUI//SP-CTI under DFARS 252.204-7012 and DD Form 254 item 10a; safeguard per NIST SP 800-171 control family 3.1.
The first version is the one a busy programme office actually writes under deadline pressure. The second is the one a contractor can act on without escalating to legal. Getting from one to the other is not a technology purchase, it is a habit, and it is the habit five separate trade groups asked the CMMC Reform Task Force to enforce.
| Organisation | What it told the task force | Its recommended fix |
|---|---|---|
| SBA Office of Advocacy | CUI uncertainty is the most frequently cited small-business concern | A government-wide process defining CUI categories before CMMC applies |
| National Defense Industrial Association | Inconsistent CUI marking requirements breed confusion, cost and weaker security for everyone | Formalised, consistent CUI identification guidance |
| Professional Services Council | Contracting officers apply CUI certification requirements inconsistently | Periodic review of legacy CUI markings |
| Alliance for Digital Innovation | Prime contractors impose blanket Level 2 rules on subcontractors that never touch CUI | Stop the blanket flow-down |
| Associated Builders and Contractors | Access needs vary sharply by role and contract stage | A tiered access model instead of one certification for everyone |
The small-business squeeze underneath the suspension#
Certified assessors nationwide
Against a Defence Industrial Base many times that size.
Self-assessment cost estimate
SBA's figure for a firm eligible to self-assess against NIST SP 800-171.
Third-party cost estimate
SBA's figure for a firm still needing an outside C3PAO audit.
Small businesses were never a side note in this story, they were the main character. A Government Accountability Office report published in March 2026 warned that the Department had not fully assessed or documented how it intended to mitigate the risk of private-sector assessment capacity simply being insufficient for the volume of companies the programme required. That is a careful, understated sentence for what turned out to be the whole problem.
Every trail this review has followed leads back to the same clearing: a contractor cannot price a control it cannot scope, and it cannot scope a document category the government itself marks inconsistently. Emil Sayegh, CEO of the compliance firm CyberSheath, put the legal reality of the pause in one sharp sentence that every marketer in this space should sit with.
The Pentagon didn't repeal a law with a press conference.
The underlying DFARS safeguarding clause, the False Claims Act exposure of a false attestation, and the NIST controls themselves never paused for a single day. Only the outside check on whether a contractor is telling the truth did. That distinction is the whole story for anyone selling into this market right now.
What the reform could actually look like#
SBA Advocacy wants DoD to name the anticipated CUI categories, markings and data flows before CMMC requirements attach, rather than leaving contractors to guess and over-protect.
The Alliance for Digital Innovation wants prime contractors barred from forcing Level 2 certification on subcontractors who will never actually handle CUI.
The Professional Services Council wants periodic checks that contractors are not still protecting documents whose CUI status was set years ago and never revisited.
Associated Builders and Contractors proposed separate tiers for bid-only access, view-only access inside a certified enclave, and full subcontractor storage.
A proposed rule under 32 CFR could finally tie CMMC's scope directly to a single, consistent CUI acquisition standard rather than each programme office's own habit.
None of these five asks touch the security controls themselves. Government contracts attorney Sandeep Kathuria, quoted by Federal News Network, called the wider CUI programme "too complex" at more than 100 categories, and floated an executive order to consolidate it. Whether reform reaches that far is anyone's guess. What is not a guess is that the CMMC Reform Task Force now has five specific, source-linked proposals sitting in its inbox instead of a vague complaint about cost.
The cmmc third-party assessors question nobody has answered yet#
Nothing in the RFI questions asks how the Pentagon plans to grow assessor capacity once Phase 2 resumes, only how to shrink the number of companies that need one. That is a sensible short-term fix and an unfinished long-term one: a programme built to lean on roughly 100 certified assessors was never going to clear a market this size, however cleanly the CUI question eventually gets answered.
What this means for compliance marketers right now#
This is the moment a CMMC consultancy, an MSSP or a vCISO practice earns its keep, and the moment most of them will get it wrong by selling fear about a deadline that no longer exists. The fox that does best here is not the loudest one in the thicket, it is the one that has already worked out which trail the client is actually on. That means leading every piece of marketing with the standard that survived the pause, not the one that did not.
folkfox's cybersecurity work starts from the same instinct: a prospect three quarters of the way through a compliance thicket does not need a brochure, it needs someone to name what is actually slowing them down. Right now, for most of the Defence Industrial Base, that is not a control gap. It is a CUI marking requirements gap, and it is a story a compliance practice can tell honestly using nothing but sources a regulator, a trade group or the SBA itself already published this summer.
Let there be no doubt: the small businesses that undergird our defense industrial base are committed to protecting our nation's digital domain, but cybersecurity cannot come at the cost of bureaucracy that shuts out the very companies our warfighters depend on.
We expect businesses to adhere to the standards that NIST has outlined.
That combination, a suspended audit and an unmoved standard, is a genuinely rare content angle: neither fear-mongering nor false reassurance, just an accurate account of what actually changed. Pair it with content built to that standard and a compliance practice can spend the review window building trust instead of burning budget on a countdown clock nobody can verify. folkfox's own read on the wider Phase 2 story, including what happened before this RFI, sits in our piece on CMMC compliance and the third-party audit reform fight.
The fox that outfoxes the market this quarter will not be the one shouting loudest about a suspended deadline. It will be the one already publishing the honest, sourced answer to the question every prospect is quietly asking: what actually changed, and what still applies to me.
Frequently asked questions#
Why did the Pentagon suspend CMMC Phase 2?
On 13 July 2026 the Department of War paused CMMC Phase 2's third-party assessment requirement, due to take effect that November, after concluding it imposed prohibitive costs on small and non-traditional defence businesses. DoD CIO Kirsten Davies said the maths did not work for small firms given roughly 100 certified assessors against a far larger pool of companies needing review. A 60-day CMMC Reform Task Force review is now underway, and Phase 1 self-assessment obligations remain fully in force.
What is CUI marking for CMMC compliance?
CUI marking is how a contractor identifies which documents and data actually contain Controlled Unclassified Information, the category CMMC and NIST SP 800-171 exist to protect. Clear cui marking requirements tell a contractor exactly what to lock down; unclear ones push it to protect everything by default, which is expensive and, several industry groups told the Reform Task Force, no more secure for it.
What counts as Controlled Unclassified Information under CMMC?
CUI covers unclassified government information that still needs safeguarding, defined across more than 100 categories in the National Archives' CUI Registry and applied to a specific contract through DFARS 252.204-7012. A document only counts as covered defense information once it is marked or otherwise identified in the contract, which is exactly the step industry says the Pentagon applies inconsistently.
How much does CMMC Level 2 certification cost a small business?
The U.S. Small Business Administration put the cost at roughly $593,800 for a small firm needing third-party assessment, or about $388,600 for one eligible to self-assess, figures it cited when it welcomed the Phase 2 suspension. Both numbers assume the scope of required controls is accurate, which is precisely what unclear CUI marking requirements put in doubt.
When will the CMMC Reform Task Force finish its review?
The task force was given 60 days from its 13 July 2026 launch, which points to a report around mid-September 2026. Its recommendations follow a public comment period that closed 14 August 2026, drawing responses from the National Defense Industrial Association, the Professional Services Council, the SBA Office of Advocacy and others.
Does CMMC Phase 1 self-assessment still apply during the suspension?
Yes. Only the Phase 2 third-party assessment requirement, and the later phases behind it, are suspended. Contractors must still self-assess against NIST SP 800-171 and meet the underlying DFARS safeguarding clause; the pause changes who checks the work, not whether the work is required.
Read more on this topic#
CMMC compliance and the third-party audit reform fight
Where the Phase 2 suspension started, and what changed in the months before this RFI.
Read the pieceNIST compliance and the AI CSF guidance gap
The standards body behind SP 800-171 is also shaping the AI risk guidance worth watching next.
Read the pieceKnown exploited vulnerabilities and mid-market ransomware
Why the businesses CMMC is meant to protect are exactly the ones ransomware crews are already finding.
Read the pieceAI supply chain security and the Phantom Raven campaign
A fresh reminder that a defence contractor's supply chain risk rarely stops at CUI.
Read the pieceReady to market clarity instead of confusion?
folkfox builds content and campaigns for compliance consultants, MSSPs and vCISOs selling into the defence industrial base, the kind of work that actually explains what cui marking requirements mean for a buyer's budget.