The figure that seems to have finished the programme off is not a cost. It is a ratio: more than 100,000 companies in the American defence supply chain needing an independent cybersecurity audit, against roughly 100 accredited assessors licensed to carry one out.

“So the math just simply doesn’t math,” Kirsten Davies, the Pentagon’s chief information officer, told reporters, in what may be the most quotable sentence ever produced by a federal certification review.

On Monday, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification programme, the compliance regime that would have required contractors handling sensitive but unclassified information to pass an audit by a certified third-party assessor before winning contract awards.

Those requirements were due to take effect on 10 November. They are now frozen, along with every other pending CMMC milestone, until further notice.

The 💜 of EU techThe latest rumblings from the EU tech scene, a story from our wise ol' founder Boris, and some questionable AI art. It's free, every week, in your inbox. Sign up now!A newly created CMMC Reform Task Force has 60 days to review the entire programme and report back. Davies and Michael Duffey, the under secretary for acquisition and sustainment, both declined to rule out scrapping CMMC altogether when the review concludes.