Get all your news in one place.
100's of premium titles.
One app.
Start reading
International Business Times UK
International Business Times UK
Jim Manzon

Pentagon CMMC Pause Explained and Why Thousands of Small Business Owners Just Dodged a Six-Figure Bill

Defence contractors must still meet strict NIST security standards while a Pentagon task force reviews the programme's future (Credit: U.S. Air Force Staff Sgt. Brittany A. Chase/Wikimedia)

The Pentagon suspended its Cybersecurity Maturity Model Certification (CMMC) Phase II audit mandate on 13 July, freeing more than 120,000 small US defence contractors from third-party assessments that federal analysis priced at up to $593,800 (£444,000) each.

The Department of War halted the requirements immediately, nearly four months before their 10 November 2026 start date, along with all pending and future CMMC milestones across its solicitations and contracts. Chief Information Officer Kirsten Davies ordered a 60-day study of the programme's future.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.