The Pentagon has suspended CMMC Phase 2 cybersecurity audits, citing prohibitive costs and a shortage of assessors driving small contractors out.

Top Pentagon officials said as currently executed, CMMC is too prohibitive and burdensome on the Defense Industrial Base.

The Defense Department will keep cybersecurity self-assessments, but will not require third-party certifications as planned.