Speaking Engagements
Healthcare Securities Class Actions, SEC Enforcement & Emerging Capital Markets Risks
September 2, 2026
On July 13, 2026, the U.S. Department of Defense/War (DoD/W) announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements — scheduled to take effect on November 10, 2026 — pending a top-to-bottom review by a newly established CMMC Reform Task Force. The announcement, formally titled “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of Cybersecurity Maturity Model Certification Requirements,” came as a surprise reversal after years of rulemaking activity stretching back to 2019. In addition to the announcement, DoD/W published an implementation memo outlining the procedural rollout of the CMMC suspension. For defense contractors and their compliance teams, the suspension raises immediate practical questions about what changes, what remains, and what comes next.
The suspension reflects mounting pressure from small business stakeholders, the Small Business Administration (SBA), and the Defense Industrial Base (DIB) at large. DoD/W’s announcement cited “prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines” as structural incompatibilities with its goal to rapidly expand the defense industrial base. The SBA, which issued its own commendation of the suspension, estimates that CMMC compliance costs can reach approximately $593,800 per certification for small firms requiring third-party assessment, and approximately $388,600 for firms eligible for self-assessment — burdens the SBA states have caused many small contractors to exit or consider exiting defense work entirely.
DoD/W’s chief information officer is immediately establishing a CMMC Reform Task Force charged with conducting a 60-day comprehensive review of the certification program. Its mandate: recommend a reformed cybersecurity framework that accelerates capability, reduces barriers for small and nontraditional businesses, and replaces costly third-party compliance models with scalable security measures.
This article is intended for general informational purposes only and does not constitute legal advice. Receipt of this article does not establish an attorney-client relationship. Defense contractors should consult with qualified legal counsel regarding their specific CMMC and DFARS compliance obligations. For more information, please contact the authors.
© 2026 Troutman Pepper Locke LLP. All rights reserved.
This just in
Speaking Engagements
Healthcare Securities Class Actions, SEC Enforcement & Emerging Capital Markets Risks
September 2, 2026
Speaking Engagements
PFAS for Decision Makers: Managing PFAS Risk in Today’s Deals – While Preparing for What’s Next
August 27, 2026 | 12:00 PM – 1:00 PM CT
Webinar
Firm Events
Cocktails and Networking During MEDevice Boston
August 26, 2026 | 6:00 PM – 8:00 PM ET
Lifted Restaurant
450 Summer St, Boston, MA 02210
Speaking Engagements
The 2026 Multifamily Maturity Cliff: Reading the $162 Billion Refinancing Wave and the Engagements It Will Generate
August 26, 2026 | 1:00 PM – 3:10 PM ET
Webinar