The Pentagon paused the next phase of its Cybersecurity Maturity Model Certification (CMMC) program, suspending a requirement for third-party cybersecurity audits that defense contractors said was driving small suppliers out of military work, Reuters reported Monday.
The Defense Department said program offices will continue requiring only Level 1 or Level 2 self-assessments instead of the third-party audits that were scheduled to become mandatory on Nov. 10. The department also launched a 60-day review, saying "CMMC compliance is forcing innovative companies out of the Defense Industrial Base."
The move follows complaints from small and mid-sized defense suppliers that compliance costs and lengthy waits for audits were prompting some companies to reconsider defense work, according to Reuters.
Comments