SBA backs DoW suspension of CMMC Phase II set for Nov. 10, 2026

The agency said compliance costs could reach about $593,800 for some small contractors and affect more than 120,000 Defense Industrial Base businesses.

Summary

The U.S. Small Business Administration said the U.S. Department of War has suspended Phase II of the Cybersecurity Maturity Model Certification program, which had been scheduled to take effect on November 10, 2026, after months of discussions with small business stakeholders. SBA said the current CMMC framework had become a costly compliance burden for contractors in the Defense Industrial Base, or DIB, with some firms leaving or considering leaving defense work. SBA Administrator Kelly Loeffler said more than 100,000 small businesses were affected and that compliance costs were approaching as much as $600,000. The agency said the Department of War is now conducting a comprehensive review aimed at keeping strong cybersecurity protections while removing regulatory barriers that slow the Acquisition Transformation System and broader defense supply chain expansion. SBA said CMMC, created under a 2024 final rule during the Biden Administration, uses three certification tiers to protect Controlled Unclassified Information and Federal Contract Information. Under the current rule, Phase II requires many small contractors to complete either a self-assessment or a third-party assessment, depending on the contract. SBA analysis estimated compliance costs of about $593,800 per certification for small firms needing third-party assessment and about $388,600 for firms eligible for self-assessment. It also said that, if launched as planned, Phase II would have pushed more than 120,000 DIB small businesses into a system supported by only about 100 approved assessors, raising costs, delaying certification and excluding otherwise qualified suppliers.

Terms & Concepts