Phase 2 of CMMC delayed. Again.
Is this how Vladimir Putin feels? Expected a 3-day operation, but 5 years later you keep getting bombed?
CMMC Stage 2 has been effectively canceled until further notice, and CMMC AB is on the verge of irrelevance, if not complete collapse.
Fireside chats and refinery bombings will continue until morale improves…

I have been personally (and to some degree financially) invested in the success of CMMC since 2022. I believe that, like FedRAMP, CMMC is necessary in an environment where information security is still often an afterthought. It covers a critical segment that has received less attention over the past decade as the cloud became the preferred platform for deploying new resources and infrastructure.
Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements
From the above:
While the current CMMC program was designed to enhance DIB cybersecurity, instead it has created prohibitive compliance costs and bureaucratic burdens. Recent data, including reports from the Small Business Administration (SBA), confirmed that CMMC compliance is forcing innovative companies out of the Defense Industrial Base (DIB) which will delay the delivery of critical capabilities to the warfighters.
This is unfortunately absolutely true, as this niche space is filled with innumerable grifters trying to sell you “Policy Documentation”, worthless “Gap Assessments” and near-infinite security theater.
A complete, carefully crafted documentation package used to cost around $500 in 2020 and came with full support. In 2026, said package is around $5k. ChatGPT 5.5 Sol will spit out a perfect template for about .20c.
Prices of Risk Assessments are astronomical, and they are usually conducted by unqualified idiots. Boilerplate SSPs that will make an auditor question their life choices.
The initial model was overly ambitious:
Five, FIVE!, maturity levels. Because 3 was not enough and four didn’t rhyme with five.
DoD-created practices beyond NIST SP 800-171. Because we know best.
Mandatory third-party certification. Because grift.
Compliance expected before contract award. This is what would have enabled the rampant grift.
Because wishful thinking is still thinking
After approximately 750 public comments exposed cost, complexity and implementation concerns, DoD initiated an internal review in March 2021 and effectively rebuilt the program as CMMC 2.0. That redesign was necessary because DoD’s first design was not operationally viable.
GAO has repeatedly identified management failures rather than merely unavoidable bureaucracy.
In 2021, GAO found that DoD:
Did not provide sufficiently timely implementation information to industry.
Had not properly designed how it would evaluate the CMMC pilot.
Had not established outcome-based measures showing whether CMMC actually reduced cybersecurity risk.
Then, in March 2026, GAO found that DoD still had not systematically assessed major external risks to implementation—including whether enough private-sector assessors would exist to perform the required assessments. GAO specifically warned that relying on waivers would not resolve the underlying capacity problem and could undermine the program.
Now what
Now we wait.
Those vendors that require SPRS will still need to be NIST SP 800-171 Rev. 2 (not 3) compliant, and charlatans will keep charging for more “Gap Assessments”. CMMC AB will have another fireside chat to try and calm the soldiers, but as their membership and dues dwindle, they will become less and less relevant.
NIST already being on Rev. 3, while DoD contracts and CMMC are still largely anchored to Rev. 2, is an ever-growing problem. Rev. 3 is not a little change, and going by the current four-year cadence, we are going to see Rev. 4 around 2028.
I am hearing a lot of upstream vendors now requiring Rev. 3 because they can contractually enforce it on their own and are starting to take matters into their own hands. This is good but can backfire as lazy CISOs go with the widest scope, again making compliance not economically viable.
I know there is a lesson here. Somewhere… But damned if I know what it is.
Note about orgs reliant on MSPs
This is a respite but I would highly not recommend taking this as a signal to do nothing. The self-attestation of at least 171 is still there.