The Pentagon is suspending CMMC phase two requirements that were set to take effect in November, pending a review of the entire program.

Top Pentagon officials said as currently executed, CMMC is too prohibitive and burdensome on the Defense Industrial Base.

The Defense Department will keep cybersecurity self-assessments, but will not require third-party certifications as planned.