Demo

The Department of Defense (DOD) has announced a change in its cybersecurity strategy, suspending a phase of a pre-existing plan to strengthen cybersecurity compliance over concerns about the cost and bureaucracy involved in implementing it.

DOD said in a release that it was suspending phase two of the Cybersecurity Maturity Model Certification (CMMC) program due to costs for small businesses. It was originally scheduled to go into effect this November.

CMMC was first established in 2019 under the first Trump administration to ensure third-party contractors were safely holding and transmitting Pentagon data, but it has proved controversial among third parties, who have raised concerns that it is cumbersome and expensive.

Meanwhile, under his administration, President Donald Trump has prioritized streamlining government services and cutting waste and red tape to push for what he says is government efficiency.

The new plan would have forced companies to pass a cybersecurity assessment from a certified third party before receiving contract awards.

Bureaucratic Burdens

But the DOD said the plan was creating “prohibitive compliance costs and bureaucratic burdens.”

“Every dollar spent on security is a wise dollar spent, and so those who have been forward-leaning in uplifting their cyber posture, in assessing what their posture is, and doing something about it, they have contributed to national security,” Defense Department Chief Information Officer Kirsten Davies told reporters. “That is not money that is spent in vain, and so that is a huge message.”

She added that over 100,000 defense firms still needed to complete a third-party cybersecurity assessment to comply with the requirements but that just over 100 assessors were available to conduct those audits.

In a release, she added: “Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness. We believe the DIB can achieve both, while we reduce unnecessary government red tape.”

“We have a strategic imperative to reduce bureaucracy as we build the world’s strongest Arsenal of Freedom. The CIO’s decision ensures we maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain,” Under Secretary of Defense for Acquisition and Sustainment Duffey added in a statement.

A recent survey by the Small Business Administration (SBA) found data suggesting small businesses would have struggled with the bureaucratic costs of the program, the SBA said. It found that implementing it would have cost over $7 billion per annum for small to medium-sized businesses.

SBA celebrated the news. “Let there be no doubt: the small businesses that undergird our defense industrial base are committed to protecting our nation’s digital domain, but cybersecurity cannot come at the cost of bureaucracy that shuts out the very companies our warfighters depend on,” SBA Administrator Kelly Loeffler said in a statement.

Phase one of the CMMC program, which began in November 2025 and requires contractors to assure the department that their cyber defenses are adequate, will remain in place, the department said.

If it had gone into effect after phase 2, a third phase would have followed in November 2027.

Interim Measures

Other government departments have recently made cuts to cybersecurity programs. Units tracking cyber threats in the ODNI were cut in August 2025 as part of plans to cut staff at the agency by almost 50%. Among the cuts were units that track cyber threats.

The department will now conduct a review of its certification programs, it said, and will recommend new measures within 60 days.

In the interim, it will enforce cybersecurity compliance through self-assessments and government-led assessments.

Read the full article here

Share.
© 2026 Gun USA All Day. All Rights Reserved.