The recent CMMC suspension put all of us in something of a state of shock and confusion, and I have been closely following the discussion in the Defense Industrial Base (DIB) community, including vendors, customers, and cybersecurity specialists. In a memo to my clients, I shared some details for the decision. A common theme among those reasons is cost and capacity. We’ve learned that:
- CMMC has prohibitive compliance costs, with individual bills approaching $600,000; SBA estimates above $7 billion annually across the base
- There is a severe assessor shortage; roughly 100,000+ firms need assessments from only about 100 approved organizations
- DoD stood up a 60-day CMMC Reform Task Force to recommend a lower-barrier replacement framework
Even though the assessment timeline has changed, we advise staying the course. Basic cyber hygiene is good for all organizations, and the suspension does not change cybersecurity requirements. Organizations that receive CUI or plan to, should continue to implement NIST 800-171r2. Self-assessments and SPRS score reporting are still required and are not affected by the suspension.
To continue reading this article, which appeared in the August 2026 edition of SMT007 Magazine, click here.