On July 13, 2026, the Department of Defense made a move that sent ripples through the defense contracting community: the Pentagon officially suspended plans to roll out phase two of the Cybersecurity Maturity Model Certification (CMMC) requirements. If your business in Mentor, Willoughby, Euclid, or anywhere across Northeast Ohio works with DoD contracts, this is a big deal — but it doesn't mean you can stop caring about cybersecurity.
What Actually Happened
DoD Chief Information Officer Kirsten Davies signed a memo on July 13 announcing that the Pentagon is suspending all pending and future CMMC milestones "until further notice." Phase two — which would have required third-party cybersecurity assessments across all DoD contracts involving sensitive but unclassified information starting November 10, 2026 — is now on hold.
The DoD also launched a 60-day "CMMC Reform Task Force" to conduct a top-to-bottom review of the entire certification program. In her memo, Davies described the current CMMC framework as a "compliance checklist" that "imposes significant and often prohibitive burdens on the Defense Industrial Base, particularly the small and non-traditional businesses that are the engine of American innovation."
What Stays in Effect
Phase one of CMMC — which requires self-assessments for applicable contracts — remains in force. The DoD began requiring self-assessments last November, and that requirement hasn't changed. If your contracts currently include CMMC self-assessment requirements, you still need to comply with those.
What's suspended is the escalation to third-party assessments by C3PAOs (CMMC Third-Party Assessment Organizations). Some DoD program offices had already started requiring these audits in advance of the November deadline. Those are now paused.
Why the Pentagon Hit the Brakes
The suspension aligns with Defense Secretary Pete Hegseth's Acquisition Transformation System initiative, which focuses on eliminating bureaucracy and enabling innovation in defense contracting. Davies noted that "the combination of prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines is actively forcing innovative new entrants and small businesses to opt out of DoD contracts."
The Small Business Administration has been raising concerns since 2024 about CMMC compliance costs pushing small businesses out of the defense industrial base. SBA Administrator Kelly Loeffler applauded the DoD's decision, saying small businesses are "the backbone of national security."
The DoD estimates roughly 80,000 companies would eventually have been subject to third-party assessment requirements under CMMC 2.0.
What This Means for Northeast Ohio Contractors
For defense contractors in Lake County and across Northeast Ohio, this is a temporary reprieve — not a permanent elimination. Here's what you should do:
-
Keep your self-assessments current. Phase one requirements are still active. If your contracts require self-attestation, you must still meet those obligations.
-
Maintain your cybersecurity posture. The DoD's shift toward "tangible cyber hygiene rather than third-party certifications" means they still expect you to be secure — they just want to reduce the bureaucratic burden of proving it.
-
Don't abandon your compliance investments. The 60-day review could result in a restructured program, not a eliminated one. Companies that have already invested in NIST SP 800-171 controls and security improvements are in a stronger position regardless of what the new framework looks like.
-
Stay informed. The CMMC Reform Task Force will provide recommendations after its 60-day review. New guidance could come as early as September 2026.
The Bigger Picture
This isn't the first time CMMC has been paused. The Biden administration paused the program in 2021 for a similar review, which resulted in the streamlined "CMMC 2.0" framework. The final rules went into effect in November 2025 after years of rulemaking. The fact that the program is being restructured again underscores how difficult it is to balance rigorous cybersecurity standards with the practical realities facing small defense contractors.
For businesses in Mentor, Willoughby, Euclid, Kirtland, and Willoughby Hills, the takeaway is clear: cybersecurity compliance for small businesses in Ohio isn't going away — but the way the government verifies it is changing. If you work with DoD contracts, now is the time to strengthen your security posture on your own terms, before the next framework arrives.
How Prosen Consulting Can Help
Whether you're navigating CMMC self-assessment requirements, implementing NIST SP 800-171 controls, or just want to make sure your business is prepared for whatever comes next, Prosen Consulting provides hands-on, local IT and cybersecurity support across Lake County. We help small businesses build real, practical security — not just check boxes.
Check out our free Cybersecurity FAQ at prosenconsulting.com/cybersecurity-faq for straight answers to common compliance questions, or call us at (216) 867-0692 to schedule a free consultation.
Serving Mentor, Willoughby, Euclid, Kirtland, Willoughby Hills, and throughout Lake County, Ohio.
