Citing prohibitive costs for small and mid-size contractors, the Defense Department will keep Phase I self-assessments in place while a new task force studies the cyber and supply chain security program's future.

Top Pentagon officials said as currently executed, CMMC is too prohibitive and burdensome on the Defense Industrial Base.

The Defense Department will keep cybersecurity self-assessments, but will not require third-party certifications as planned.