07/13/2026
Today, the United States Department of War is taking decisive action to revitalize the DIB and dramatically reduce compliance burden on small, medium, and non-traditional businesses.
In support of Secretary Hegseth’s “Arsenal of Freedom” and the Acquisition Transformation Strategy, we are announcing the immediate suspension of CMMC Phase II requirements.
While robust cybersecurity and operational resilience remain critical, non-negotiable priorities, recent data makes it clear: the current CMMC framework creates prohibitive costs and duplicative red tape. Administrative hurdles are forcing innovative companies to choose between bureaucratic paperwork exercises and exiting the defense sector altogether. We cannot let bureaucracy impede the delivery of capabilities to our warfighters.
What stays in place:
· Phase I self-assessment requirements.
· Enforcement of NIST SP 800-171 Rev 2 (focusing on tangible cybersecurity uplift over administrative overhead).
· DFARS obligations to safeguard covered defense information.
Next steps:
DoW CIO Kirsten Davies is immediately establishing a CMMC Reform Task Force to conduct a top-to-bottom review of the program over the next 60 days. Additionally, an RFI is being issued to gather DIB feedback. We want to hear from you.
We can risk reduce our digital ecosystem while empowering American innovators. We can do both... We must do both.
Submit your RFI feedback and read the full memos here: https://dowcio.war.gov
Read the press release: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require
Learn More: https://dowcio.war.gov/brilliantbasics
Welcome to the "Brilliant at the Basics" campaign — the Department of War (DoW) Chief Information Officer (CIO) initiative dedicated to empowering our Defense Industrial Base (DIB) partners. Our mission is to help small, mid-sized, and non-traditional companies confidently secure their networks, p...