Third-party risk management in the defense sector has spent the last three years building toward a single inflection point: the moment cybersecurity self-attestation gives way to independently verified certification. On 13 July 2026, that moment was postponed. The US Department of War suspended the transition to Phase Two of the Cybersecurity Maturity Model Certification programme - originally scheduled for 10 November 2026 - and established a CMMC Reform Task Force to review the programme, while Phase One self-assessment obligations under NIST SP 800-171 Revision 2 remain fully in force.
The suspension does not remove the underlying obligation; it removes the enforcement mechanism that was meant to verify it is being met. Roughly 300,000 companies in the US Defense Industrial Base are subject to Controlled Unclassified Information handling requirements, yet independent tracking as of February 2026 found only around 8 percent (yes, you read that right – 8%) of defense contractors had obtained CMMC Level 2 certification - a gap that a mandatory third-party assessment regime was designed to close, and that a suspended regime now leaves substantially unaddressed. Phase Two would have required Certified Third-Party Assessment Organisation verification of all 110 NIST 800-171 controls for contracts handling CUI; that requirement is now paused pending a 60-day programme review, with self-assessment - and the honour-system risk it carries - remaining the operative standard in the interim.
The UK has been moving in the opposite direction, tightening rather than pausing. The Defence Cyber Protection Partnership, the joint MoD-industry initiative established to protect the defence supply chain from cyber threat, has been formally absorbed into a new IASME-delivered Defence Cyber Certification scheme. MoD Defence Digital has stated that industry partners should be working toward Level 0 DCC certification by 31 December 2026, tiering supply chain security requirements by risk level in a way that is structurally similar to CMMC's level system, but without the pause.
The lesson for third-party risk functions on both sides of the Atlantic is the same, even though the two regimes are moving at different speeds: certification frameworks are not static compliance checkboxes but live policy instruments subject to political and administrative revision. And organisations that treat a certification deadline as the finish line for their assurance programme - rather than one input into a continuously maintained evidence base - will find themselves exposed each time a framework pauses, tightens, or is reformed.
A defense TPRM programme built around passing a single assessment event is inherently more fragile than one built around continuously demonstrable control evidence, because the former is only as strong as its regulator's next policy announcement.