The Department of Defense’s July 2026 suspension of Phase II didn’t happen because of a policy disagreement. It happened because the math stopped working.
According to a July 2026 SBA press release, total compliance costs for small defense contractors requiring a third-party assessment can reach approximately $593,800 per CMMC certification. That’s before you account for the contracts some of those firms are holding. When compliance costs the same as, or more than, the revenue from the work you’re trying to stay eligible for, you don’t have a security program. You have an attrition mechanism.
Over 120,000 small businesses across the Defense Industrial Base (DIB) had been staring at that math long before the suspension was announced. The suspension is the right call. The harder work is what comes next: whether the CMMC Reform Task Force uses its 60-day window to fix the structural problem, or just moves the deadline.
There’s a working model for how to do this right: PCI DSS.
CMMC Level 2 compliance costs small businesses significantly more than DoD’s published estimates suggest. The Department’s figure (approximately $104,670 for a C3PAO third-party assessment) covers only the audit itself, not the implementation work required to pass it. Add remediation, tooling, documentation, personnel time, and annual maintenance, and the picture changes substantially.
A 2025 analysis by Atlantic Digital, drawing on the DoD’s data, put the three-year total for a representative small business at approximately $487,970. In practice, year-one Level 2 costs range from $50,000 for organizations that enter the process relatively prepared to $250,000 or more for those starting from a lower baseline.
The SBA put a sharper point on it. In the official July 2026 Phase II suspension announcement, SBA analysis pegged total compliance costs at approximately $593,800 for small firms requiring third-party assessment, and $388,600 for firms eligible for self-assessment. A March 2026 GAO report (GAO-26-107955) had already warned that these costs would push small businesses out of the defense supply chain entirely.
The assessment ecosystem compounded the problem. More than 120,000 small DIB businesses needed third-party certification from a pool of roughly 100 approved C3PAO organizations. There was no realistic path to clearing that volume before the November 2026 Phase II deadline.
The core problem is that CMMC’s Level 2 applies the same 110-control burden to every contractor that touches CUI, regardless of how much CUI they access, how they access it, or what they do with it.
|
Controlled Unclassified Information (CUI) Sensitive government information requiring protection under federal law (e.g., technical drawings, test data, engineering documents) that isn’t classified. CMMC Level 2 applies all 110 NIST SP 800-171 controls to any contractor whose environment includes CUI. |
Consider two organizations that both qualify as Level 2 contractors:
Both organizations face the same 110-control certification requirement. Neither volume of CUI exposure, the method of access, nor the actual risk profile factors into the compliance pathway they’re required to follow.
This is the problem the CMMC Reform Task Force has been formally asked to address. The DoD’s public request for information explicitly asks about compliance burden by data interaction level, and the DoD has stated its goal as reducing burden without lowering the security baseline. Whether the resulting framework makes a structural change or just moves the timeline is the question that matters.
|
Factor |
CMMC (Current Model) |
PCI-Style Tiered Alternative |
|
Compliance Requirement |
Same 110 NIST SP 800-171 controls for all Level 2 CUI handlers |
Requirements scale based on actual depth and method of CUI interaction |
|
Assessment Pathway |
Full C3PAO assessment for all Level 2 contractors handling CUI |
Short self-assessment for minimal-access contractors; full assessment for active CUI environments |
|
Security Architecture Responsibility |
Each contractor builds and maintains its own CUI environment independently |
Contractors rely on pre-validated enclave solutions, reducing duplicative engineering |
|
Path for Read-Only / Portal-Based Access |
No reduced-burden pathway available |
VDI/portal access enables outsourced CUI handling and significantly reduced compliance scope |
|
Cost Driver |
Uniform regardless of CUI footprint |
Scales with actual CUI footprint; smaller footprint, proportionally lower compliance cost |
|
Established Precedent |
Unique model with no equivalent in commercial compliance frameworks |
Mirrors PCI DSS via SAQ-A pathway, P2PE validation, and External Service Provider reliance model |
PCI DSS solved an equivalent problem for small merchants, and it didn’t do it by lowering the security bar.
A decade ago, small businesses across retail and hospitality were technically in scope for the full PCI standard because they processed payment cards. Applying the same certification burden to a 10-person coffee shop as to a major card processor made no practical sense. The card’s industry response was structural.
As Schellman’s PCI practice leader documented following the Phase II suspension, PCI DSS allows merchants who completely outsource payment processing (i.e., never store or transmit cardholder data themselves) to qualify for SAQ-A: a short self-assessment rather than a full audit. The payment processor builds and maintains the secure environment; the merchant’s job is to confirm they’re using it correctly. Technologies like point-to-point encryption (P2PE) and tokenization extended the same logic to merchants who do remain in the transaction flow, using validated solutions to remove sensitive data from their environment entirely.
The CMMC Reform Task Force has a 60-day window to deliver recommendations to the DoD CIO, with a report due in mid-September 2026.
The DoD has been explicit about what this is and isn’t. It is not a rollback of security requirements; DFARS 252.204-7012 remains in force. Phase I self-assessments continue. The obligation to protect federal information didn’t change on July 13. The suspension paused the certification mechanism, not the baseline. (If your immediate question is what to do with your compliance program during the review period, our CMMC pause breakdown covers that.)
What should change is how the framework accounts for CUI interaction. Two specific pathways would give the reform structural weight.
A subcontractor whose only CUI exposure is read-only access through a prime's secure portal never stores or processes CUI locally. That mirrors the PCI SAQ-A merchant: no data touches their environment, so the compliance footprint reflects that reality. This group should qualify for a dramatically simplified certification pathway: a short self-assessment with focused controls, not the full 110-control C3PAO audit.
For contractors who do need CUI in their environment, a pre-validated, turnkey enclave — built on FedRAMP-authorized infrastructure from providers like Microsoft, Amazon, or Google — should serve as a reusable compliance foundation. What CMMC currently calls External Service Providers (ESPs) need a formal reliance mechanism. Right now, each contractor must re-prove the configuration of the environment even when the underlying infrastructure has been validated. PCI DSS solved this for merchants through its processor validation model. CMMC needs an equivalent at the enclave layer.
What doesn’t serve the DIB or national security: a Reform Task Force that returns in September with the same architecture and a later deadline. If the framework comes back without structural differentiation, the same math problem will resurface and small manufacturers and suppliers that anchor the defense supply chain will continue to exit.
Navigating CMMC compliance decisions before the Reform Task Force releases its recommendations? Our team has worked with defense contractors across the DIB on exactly this. Schedule a conversation →
According to a 2026 SBA analysis, total compliance costs for small firms requiring C3PAO third-party assessment reach approximately $593,800.
CMMC compliance costs vary by level and organizational starting point. For Level 1, costs typically run $10,000 to $40,000. For Level 2, expect $50,000 to $250,000 or more in year one, depending on remediation scope and baseline maturity.
It depends on contract value, CUI exposure, and the compliance pathway available. For small businesses holding DoD contracts that justify the investment, achieving CMMC certification builds a competitive advantage: satisfies enterprise security questionnaires, supports contract retention, and enables growth into new program opportunities. For contractors holding low-value CUI contracts where compliance costs approach or exceed contract revenue, the current model presents a structural problem the DoD has formally acknowledged and is actively working to address through the Reform Task Force.
A CMMC third-party assessment (C3PAO assessment) is an independent review conducted by an authorized CMMC Third-Party Assessment Organization. For Level 2 contractors, it evaluates all 110 NIST SP 800-171 security controls across the contractor's documented CUI environment and submits results to the CMMC eMASS system. The DoD's official estimate for C3PAO assessment fees runs approximately $104,670, but that figure excludes implementation and remediation costs, which typically represent the majority of total compliance spend. As of July 13, 2026, Phase II C3PAO assessment requirements are suspended pending the DoD's 60-day program review.
The July 13, 2026 suspension paused mandatory C3PAO certification as a condition of contract award for Level 2. Phase I self-assessment requirements, DFARS 252.204-7012 obligations, and NIST SP 800-171 compliance requirements all remain in force. Contractors who have begun compliance programs should continue; the underlying obligation to protect federal information didn't change. A CMMC Reform Task Force is conducting a comprehensive review with recommendations due to the DoD CIO in mid-September 2026. The outcome could reshape certification pathways, assessment timelines, or both.
Federal Contract Information (FCI) is information provided by or generated for the government under a contract that isn't intended for public release. It triggers CMMC Level 1: 15 basic controls, annual self-assessment.
Controlled Unclassified Information (CUI) is more sensitive (e.g., engineering drawings, test reports, technical data with military applications) and triggers Level 2, which currently requires 110 NIST SP 800-171 controls and, for most contractors, C3PAO assessment.
The CMMC Reform Task Force was established by DoD CIO Kirsten Davies alongside the July 13, 2026 Phase II suspension. Its mandate is to conduct a comprehensive review of the CMMC program, synthesize industry feedback through a public request for information, and deliver actionable recommendations for reform. The task force is specifically focused on reducing compliance burden while maintaining strong cybersecurity, including exploring self-attestation models, commercial cybersecurity capabilities, and streamlined requirements for small and non-traditional businesses.