Skip to main content

folkfox

Skip to main content
Skip to content
Compliance and Certification

The Pentagon paused CMMC over a labelling problem

The Department of War paused its own flagship cybersecurity rule in July 2026 and asked industry to name the single biggest cost driver. Almost every answer came back the same: nobody can agree what counts as sensitive.

Quick answerThe Pentagon suspended CMMC Phase 2 in July 2026 after industry told the CMMC Reform Task Force that unclear cui marking requirements, not the security controls themselves, were pricing small defence contractors out of the market.
Section 01

The Pentagon pressed pause on its own rule#

100+

types of Controlled Unclassified Information a defence contractor may have to correctly spot before CUI marking requirements even let a single security control get built

Federal News Network, August 2026

folkfox has sat across the table from enough defence contractors to know that a compliance deadline rarely breaks a business on its own. What breaks it is the paperwork nobody can pin down underneath the deadline. On 13 July 2026 the Department of War suspended the third-party assessment requirements of CMMC Phase 2, the tier of the Cybersecurity Maturity Model Certification programme that was due to take effect that November, and opened a 60-day review through a freshly formed CMMC Reform Task Force.

DoD CIO Kirsten Davies put the maths plainly when she announced the pause: "the math just simply doesn't math for small to medium-sized businesses." The Pentagon had leaned on roughly 100 certified third-party assessors to clear a Defence Industrial Base many times that size, and every fresh solicitation added to a queue that was never going to move fast enough. Phase 1 self-assessment, already in force since November 2025, was left standing. Phases 2 through 4 were not.

The bottleneck behind the pause
Certified third-party assessors
~100 nationwide
Small defence businesses awaiting Phase 2
120,000+
Roughly 100 certified assessors stood between the Pentagon's own audit requirement and more than 120,000 small defence businesses, the exact mismatch the Small Business Administration named when it welcomed the July 2026 suspension, and the shortage sitting underneath every CUI marking requirements complaint.

The U.S. Small Business Administration put real numbers on that squeeze: roughly $593,800 for a small firm still needing an outside audit, and about $388,600 for one eligible to self-assess. Administrator Kelly Loeffler called the framework "bureaucracy that shuts out the very companies our warfighters depend on." Both figures assume the scope of required controls is accurate. That assumption is exactly what the next problem undoes.

Why unclear cui marking requirements topped the list#

Ask the trade groups that actually filed comments and the pattern repeats without prompting. It is not the 110 controls in NIST SP 800-171 that small firms object to. It is not knowing, contract to contract, which documents those controls are meant to protect. The National Defense Industrial Association told the task force that inconsistent CUI marking requirements lead to "confusion, increased costs, and decreased security for all parties," a sentence that could sit at the top of every comment letter this review received.

Section 02

Why CUI marking became the single biggest line item#

Read those five bullets together and a quieter story than "CMMC is too strict" comes into focus. Industry is not asking to protect less. It is asking to be told, clearly and in writing, what actually needs protecting, so the controls it builds match the data it is genuinely holding rather than a defensive guess at every category the government might mean.

Vague, blanket, unliftable

This document may contain information requiring protection and should be handled accordingly by all recipients.

Specific, sourced, actionable

This attachment is marked CUI//SP-CTI under DFARS 252.204-7012 and DD Form 254 item 10a; safeguard per NIST SP 800-171 control family 3.1.

The first version is the one a busy programme office actually writes under deadline pressure. The second is the one a contractor can act on without escalating to legal. Getting from one to the other is not a technology purchase, it is a habit, and it is the habit five separate trade groups asked the CMMC Reform Task Force to enforce.

Five industry groups filed public comments on the RFI naming CUI marking requirements as a cost driver, each pointing at a different fix.
OrganisationWhat it told the task forceIts recommended fix
SBA Office of AdvocacyCUI uncertainty is the most frequently cited small-business concernA government-wide process defining CUI categories before CMMC applies
National Defense Industrial AssociationInconsistent CUI marking requirements breed confusion, cost and weaker security for everyoneFormalised, consistent CUI identification guidance
Professional Services CouncilContracting officers apply CUI certification requirements inconsistentlyPeriodic review of legacy CUI markings
Alliance for Digital InnovationPrime contractors impose blanket Level 2 rules on subcontractors that never touch CUIStop the blanket flow-down
Associated Builders and ContractorsAccess needs vary sharply by role and contract stageA tiered access model instead of one certification for everyone
Section 03

The small-business squeeze underneath the suspension#

The numbers the SBA put on the pause

Certified assessors nationwide

100

Against a Defence Industrial Base many times that size.

Self-assessment cost estimate

$388600

SBA's figure for a firm eligible to self-assess against NIST SP 800-171.

Third-party cost estimate

$593800

SBA's figure for a firm still needing an outside C3PAO audit.

Small businesses were never a side note in this story, they were the main character. A Government Accountability Office report published in March 2026 warned that the Department had not fully assessed or documented how it intended to mitigate the risk of private-sector assessment capacity simply being insufficient for the volume of companies the programme required. That is a careful, understated sentence for what turned out to be the whole problem.

The reform task force's own clock
Bullet chart showing 44 days elapsed against a 60-day target for the CMMC Reform Task Force reviewDays into the review: 44 of 60Days into the review44 days
The CMMC Reform Task Force is 44 days into the 60-day review window it set itself on 13 July 2026, and its comment period closed 14 August 2026 with CUI marking requirements as the single most repeated complaint, which points to a report around mid-September.

Every trail this review has followed leads back to the same clearing: a contractor cannot price a control it cannot scope, and it cannot scope a document category the government itself marks inconsistently. Emil Sayegh, CEO of the compliance firm CyberSheath, put the legal reality of the pause in one sharp sentence that every marketer in this space should sit with.

The Pentagon didn't repeal a law with a press conference.
Emil Sayegh, CEO, CyberSheath, via SecurityWeek

The underlying DFARS safeguarding clause, the False Claims Act exposure of a false attestation, and the NIST controls themselves never paused for a single day. Only the outside check on whether a contractor is telling the truth did. That distinction is the whole story for anyone selling into this market right now.

Section 04

What the reform could actually look like#

Five fixes industry actually asked for
Define CUI before the contract, not after

SBA Advocacy wants DoD to name the anticipated CUI categories, markings and data flows before CMMC requirements attach, rather than leaving contractors to guess and over-protect.

Stop the blanket subcontractor rule

The Alliance for Digital Innovation wants prime contractors barred from forcing Level 2 certification on subcontractors who will never actually handle CUI.

Review legacy markings on a schedule

The Professional Services Council wants periodic checks that contractors are not still protecting documents whose CUI status was set years ago and never revisited.

Tier access instead of certifying everyone the same

Associated Builders and Contractors proposed separate tiers for bid-only access, view-only access inside a certified enclave, and full subcontractor storage.

Write one governmentwide CUI rule

A proposed rule under 32 CFR could finally tie CMMC's scope directly to a single, consistent CUI acquisition standard rather than each programme office's own habit.

None of these five asks touch the security controls themselves. Government contracts attorney Sandeep Kathuria, quoted by Federal News Network, called the wider CUI programme "too complex" at more than 100 categories, and floated an executive order to consolidate it. Whether reform reaches that far is anyone's guess. What is not a guess is that the CMMC Reform Task Force now has five specific, source-linked proposals sitting in its inbox instead of a vague complaint about cost.

The cmmc third-party assessors question nobody has answered yet#

Nothing in the RFI questions asks how the Pentagon plans to grow assessor capacity once Phase 2 resumes, only how to shrink the number of companies that need one. That is a sensible short-term fix and an unfinished long-term one: a programme built to lean on roughly 100 certified assessors was never going to clear a market this size, however cleanly the CUI question eventually gets answered.

Section 05

What this means for compliance marketers right now#

This is the moment a CMMC consultancy, an MSSP or a vCISO practice earns its keep, and the moment most of them will get it wrong by selling fear about a deadline that no longer exists. The fox that does best here is not the loudest one in the thicket, it is the one that has already worked out which trail the client is actually on. That means leading every piece of marketing with the standard that survived the pause, not the one that did not.

folkfox's cybersecurity work starts from the same instinct: a prospect three quarters of the way through a compliance thicket does not need a brochure, it needs someone to name what is actually slowing them down. Right now, for most of the Defence Industrial Base, that is not a control gap. It is a CUI marking requirements gap, and it is a story a compliance practice can tell honestly using nothing but sources a regulator, a trade group or the SBA itself already published this summer.

Let there be no doubt: the small businesses that undergird our defense industrial base are committed to protecting our nation's digital domain, but cybersecurity cannot come at the cost of bureaucracy that shuts out the very companies our warfighters depend on.
Kelly Loeffler, SBA Administrator, via SBA.gov
We expect businesses to adhere to the standards that NIST has outlined.
Michael Duffey, USD for Acquisition, via Breaking Defense

That combination, a suspended audit and an unmoved standard, is a genuinely rare content angle: neither fear-mongering nor false reassurance, just an accurate account of what actually changed. Pair it with content built to that standard and a compliance practice can spend the review window building trust instead of burning budget on a countdown clock nobody can verify. folkfox's own read on the wider Phase 2 story, including what happened before this RFI, sits in our piece on CMMC compliance and the third-party audit reform fight.

The fox that outfoxes the market this quarter will not be the one shouting loudest about a suspended deadline. It will be the one already publishing the honest, sourced answer to the question every prospect is quietly asking: what actually changed, and what still applies to me.

Questions

Frequently asked questions#

Why did the Pentagon suspend CMMC Phase 2?

On 13 July 2026 the Department of War paused CMMC Phase 2's third-party assessment requirement, due to take effect that November, after concluding it imposed prohibitive costs on small and non-traditional defence businesses. DoD CIO Kirsten Davies said the maths did not work for small firms given roughly 100 certified assessors against a far larger pool of companies needing review. A 60-day CMMC Reform Task Force review is now underway, and Phase 1 self-assessment obligations remain fully in force.

What is CUI marking for CMMC compliance?

CUI marking is how a contractor identifies which documents and data actually contain Controlled Unclassified Information, the category CMMC and NIST SP 800-171 exist to protect. Clear cui marking requirements tell a contractor exactly what to lock down; unclear ones push it to protect everything by default, which is expensive and, several industry groups told the Reform Task Force, no more secure for it.

What counts as Controlled Unclassified Information under CMMC?

CUI covers unclassified government information that still needs safeguarding, defined across more than 100 categories in the National Archives' CUI Registry and applied to a specific contract through DFARS 252.204-7012. A document only counts as covered defense information once it is marked or otherwise identified in the contract, which is exactly the step industry says the Pentagon applies inconsistently.

How much does CMMC Level 2 certification cost a small business?

The U.S. Small Business Administration put the cost at roughly $593,800 for a small firm needing third-party assessment, or about $388,600 for one eligible to self-assess, figures it cited when it welcomed the Phase 2 suspension. Both numbers assume the scope of required controls is accurate, which is precisely what unclear CUI marking requirements put in doubt.

When will the CMMC Reform Task Force finish its review?

The task force was given 60 days from its 13 July 2026 launch, which points to a report around mid-September 2026. Its recommendations follow a public comment period that closed 14 August 2026, drawing responses from the National Defense Industrial Association, the Professional Services Council, the SBA Office of Advocacy and others.

Does CMMC Phase 1 self-assessment still apply during the suspension?

Yes. Only the Phase 2 third-party assessment requirement, and the later phases behind it, are suspended. Contractors must still self-assess against NIST SP 800-171 and meet the underlying DFARS safeguarding clause; the pause changes who checks the work, not whether the work is required.

Keep reading

Read more on this topic#

Ready to market clarity instead of confusion?

folkfox builds content and campaigns for compliance consultants, MSSPs and vCISOs selling into the defence industrial base, the kind of work that actually explains what cui marking requirements mean for a buyer's budget.