samsearch
    Platform
    01InfluenceShape the requirement before it's on your competitor's radar.
    Signal
    Recompete window opens in 42 days
    Facilities maintenance IDIQ$8.4M
    Forecast
    Agency spend up 18% next FY
    DoD facilitiesQ3 window
    02CaptureFind and qualify the work across every market.
    Federal91%
    Network engineering support — GSA MAS
    GSA541512
    SLED88%
    Custodial services — Fairfax County Public Schools
    K-12561720
    DIBBS79%
    Aircraft hydraulic fitting — DLA Aviation
    DLANSN 5330
    03AnalyzeExtract requirements and build the compliance matrix.
    Compliance matrix
    L.2.1Technical approachVol I
    L.3.4Staffing planVol I
    M.1Past performanceEvaluated
    SOW breakdown
    Requirements extracted38
    Mapped to Section L/M38
    Every extractionCited
    Ask Sammy
    “Do we meet the small business set-aside?”
    04ManageRun the pursuit through to award.
    Pipeline
    QualifyFacilities support · USACE
    CaptureComms upgrade · DLA
    ProposalShipyard dredging · NAVSEA
    PriyaAlex
    This week
    Submit past performance refsThu
    Confirm subK teamingFri
    Upload SF 33Mon
    05RespondDraft and submit your response.
    Drafting · Volume I
    247 words
    RFI response
    CompanyAcme Robotics LLC
    UEIJK4M8…
    Capability narrativeDrafted
    06FinanceGet paid faster on what you win.
    Capital available
    $2.4M against your award
    Facilities maintenance IDIQAwarded
    Partner matched
    LenderFederal Capital Partners
    Draw available$2.4M
    UnderwritingCleared
    The platform
    Influence
    Capture
    Analyze
    Manage
    Respond
    Finance
    One pipeline, six stages, start to award.
    See the whole platform
    Solutions
    By industry
    Tech & softwareSoftware and SaaS companies entering GovCon.Defense contractorsPrimes and subs in the defense industrial base.ConstructionBuilders bidding federal, state, and local work.CybersecuritySecurity vendors pursuing federal mandates.
    By team
    Capture managers & BDPipeline, qualification, and win strategy.Proposal teamsCompliance matrices and proposal drafting.Subcontractors & primesTeaming, subcontracting, and partner fit.
    By company size
    Small businessesSet-aside and small business contractors.EnterpriseLarge contractors running multiple pursuits.ConsultantsAdvisors and capture consultants.
    Browse all industries
    CustomersPricing
    ResourcesNew
    Learn
    AcademyCourses, guides, and playbooks.WebinarsLive sessions and recordings.DocsProduct documentation and setup guides.Implementation planOperational rollout guidance.
    Tools & data
    Free GovCon toolsCalculators, lookups, and more.Gov ExploreContracts, agencies, and NAICS codes.GovCon eventsConferences, training, and set-aside events.
    Latest blogIntroducing the New SamSearch: The Operating System for Government ContractingSamSearch has a new brand, a new site, and a new way of explaining what the platform actually does — the operating system for government contracting, organized around six stages instead of a single search box. Here's what changed and why.Read the post →
    All resources and tools
    Sign inRequest a demo
    Home/News/Department of War Halts CMMC Phase II Requirements Amid Compliance Concerns
    federal_newspolicy

    Department of War Halts CMMC Phase II Requirements Amid Compliance Concerns

    The Department of War has suspended CMMC Level 2 requirements while initiating a 60-day review. This decision is significant for small defense contractors, as it aims to alleviate compliance burdens that challenge their ability to compete for contracts.

    July 14, 2026Department of War, U.S. Small Business Administration, National Institute of Standards and Technology, Department of Defense

    Key Signals

    • DoW suspends CMMC Level 2 requirements amidst compliance concerns for small contractors
    • 60-day comprehensive review to evaluate future of CMMC program
    • Compliance cost estimates for small contractors reached up to $593,800 per certification

    "In support of Secretary Pete Hegseth's directive to reduce compliance barriers for small and medium-sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program."

    — Kirsten Davies, Chief Information Officer

    The recent suspension of the Cybersecurity Maturity Model Certification (CMMC) Level 2 requirements by the Department of War (DoW) marks a pivotal moment for small defense contractors across the United States. This decision comes amidst growing concerns regarding the compliance costs that could restrict smaller businesses from participating in federal procurement opportunities. Originally slated for implementation in November 2026, the suspension initiates a 60-day comprehensive review of the CMMC program, in alignment with the directives from DoW’s Chief Information Officer, Kirsten Davies.

    The CMMC framework was introduced with the intention of ensuring that contractors adequately protect sensitive unclassified federal data. However, the evolving landscape of defense contracting revealed that the financial and operational burdens placed upon smaller companies could hinder their competitiveness. SBA Administrator Kelly Loeffler underscored this sentiment, citing that the financial strain imposed by compliance could have forced mission-critical small businesses out of the defense sector altogether.

    The looming requirement for CMMC Phase II was particularly concerning, as it involved extensive third-party assessments—with costs associated with certification reaching as high as $593,800 for those requiring outside evaluations. Further complicating matters, only about 100 approved assessors were available to handle the volume of certifications required, exacerbating delays in contract awards and potentially locking capable suppliers out of the defense contracting process entirely. As a result, many defense contractors had already invested significant resources in preparation for compliance, leading to further frustration.

    Despite this pause, the urgency of maintaining cybersecurity standards remains. The DoW confirmed that while CMMC Phase II audits are suspended, compliance with essential NIST standards remains mandatory. This means that companies must continue to adhere to NIST SP 800-171 requirements for safeguarding covered defense information, regardless of the status of CMMC certification efforts. Furthermore, self-assessments from Phase I of the CMMC remain in effect, highlighting that regulatory compliance continues to be critical even as the specific audit requirements are revisited.

    The decision to pause the CMMC Phase II requirements reflects a balancing act between the need for rigorous cybersecurity measures and the practical realities faced by small businesses. As the federal government conducts its review, procurement professionals can expect adjustments in future regulatory frameworks concerning cybersecurity compliance. For contractors and vendors, this opens an opportunity to reassess strategies to remain compliant and competitive, while potentially benefitting from new guidance that may arise from the review process.

    This development underscores the DoW's recognition of the vital role that small and medium-sized businesses play in the defense industrial base. As stated by Davies, the temporary halt aims to alleviate unnecessary barriers for these businesses, enabling them to continue contributing to national security without facing overwhelming compliance costs. Given that over 120,000 small defense contractors are affected, the implications of this decision are far-reaching within the defense contracting space.

    Agencies

    • Department of War
    • U.S. Small Business Administration
    • National Institute of Standards and Technology
    • Department of Defense

    Sources

    • DoD/Dow CIO pulled all info on CMMC?reddit-fedemployees · Jul 13
    • US Department of War suspends costly CMMC Phase... | PluangPluang · Jul 13
    • War Department Changes Cybersecurity Maturity Model Certification Requirements > U.S. Department of War > Defense Department News | U.S. Department of WarU.S. Department of War (.gov) · Jul 13
    • Pentagon CMMC Pause Explained and Why Thousands of Small Business Owners Just Dodged a Six-Figure Bill | IBTimes UKInternational Business Times UK · Jul 14
    CybersecurityDefense & MilitaryRegulationsProcurementSmall Business
    ← Back to News
    samsearch

    The Complete AI Platform for Government Contracting

    Platform
    • Product
    • Pricing
    • ROI calculator
    • Integrations
    • Changelog
    Solutions
    • Solutions
    • Customers
    • Comparisons
    • Market watch
    Resources
    • Blog
    • Free GovCon tools
    • Glossary
    • Docs
    Company
    • API & partnerships
    • Careers
    • Support
    • Compliance
    • Trust centre
    • Contact
    Recognised & verified
    SOC 2 Type II Compliant, SamSearchAWS Partner - Advanced, SamSearch on AWS MarketplaceGartner Peer Insights Customer First, SamSearch
    Ask AI about samsearch
    Ask ChatGPTAsk ClaudeAsk Perplexity
    Follow

    © 2026 samsearch. All rights reserved.

    Terms of usePrivacy policy