The Pentagon’s decision to suspend CMMC Phase 2 implementation has created a sharp divide across the Defense Industrial Base (DIB), but one thing remains clear: cybersecurity requirements are not going away. The Department of War announced a pause on the November 2026 transition to Phase 2, halted future implementation milestones, and launched a 60-day review through a newly formed CMMC Reform Task Force. The stated rationale is that compliance costs and assessment burdens may be pushing innovative small and mid-sized businesses out of the defense supply chain, potentially slowing critical capability delivery to the warfighter.
Leapfrog Chief Security Officer Bryant G. Tow says: “The Department of War is right to reassess whether the current CMMC model creates an unfunded mandate for the companies that support our national defense.”
Supporters of the pause argue that CMMC’s third-party assessment model created a scalability problem. Many believe the combination of NIST 800-171 implementation costs and mandatory C3PAO assessments placed an unsustainable burden on smaller contractors, particularly those whose core business is not cybersecurity. Some industry leaders view the pause as an opportunity to develop a more practical, risk-based approach that improves security without creating barriers to participation in the defense market.
Critics, however, warn that the pause risks repeating past mistakes. They point out that contractors have been contractually obligated to meet NIST SP 800-171 requirements since 2017 and that self-attestation has historically failed to produce consistent security outcomes. Several experts emphasized that DFARS cybersecurity obligations remain in force, DOJ Cyber-Fraud Initiative enforcement continues, and nation-state threats have not slowed simply because the compliance timeline changed. Organizations that delay security improvements may ultimately find themselves less prepared regardless of what changes emerge from the review process.
Bryant added, “However, the pause should not be interpreted as a pause on cybersecurity. The threats remain, the contractual obligations remain, and the expectation to protect Controlled Unclassified Information remains.”
The bottom line is that the standards that the 800-171 requires are for the most part, basic cyber hygiene. The Pentagon is launching the “Brilliant at the Basics” campaign with its own similar guidelines. Defense contractors should avoid treating this announcement as a reprieve. Instead, they should view it as an opportunity to mature cybersecurity programs while helping shape a more effective framework.
In conclusion, Bryant says: “Our industry should use this time to advocate for a more scalable and risk-based certification process while continuing to invest in NIST 800-171 compliance, operational resilience, and demonstrable cyber maturity. The goal should be a stronger defense industrial base, not simply a cheaper compliance program.”
Our team at Leapfrog can help assess your current NIST 800-171 posture, identify gaps, prioritize remediation, and build a practical roadmap for improving operational resilience before the next phase of requirements takes shape. The review period is an opportunity to prepare, not pause, and organizations that act now will be better positioned to protect sensitive information, meet contractual expectations, and respond with confidence when the updated framework is released. If your organization needs support getting ahead of the CMMC process, reach out to Leapfrog today.
Bryant G. Tow – Chief Security Officer, Leapfrog Services
Bryant G. Tow is the Chief Security Officer at Leapfrog Services, where he leads comprehensive security programs grounded in the Ring of Security methodology. With more than 25 years of experience across cyber and physical risk management, he has held executive roles at global enterprises, consulting firms, and multiple startups. Bryant has contributed to national security initiatives through leadership roles with DHS, ISSA, ISACA, and InfraGard, and he is a published author and award‑winning cybersecurity innovator. He is also a current Thought Leader on the Forbes Technology Council.
Bryant G. Tow – Chief Security Officer, Leapfrog Services