Back to news

Pentagon's CMMC Pause Leaves Space Suppliers on the Honor System

Share:
Pentagon's CMMC Pause Leaves Space Suppliers on the Honor System

The Pentagon suspended the core of its contractor cybersecurity program on July 13, 2026, and the decision reaches directly into the satellite supply chain. The Department of Defense froze Phase 2 of the Cybersecurity Maturity Model Certification, the stage that would have forced companies handling sensitive defense data to pass an independent audit before winning contracts. For the satellite manufacturers, ground-segment vendors and launch suppliers inside the defense industrial base, the obligation to prove their cybersecurity to an outside assessor is gone, at least for now.

What the Pentagon suspended

CMMC Phase 2 was set to take effect on November 10, 2026. It would have required contractors and subcontractors handling controlled unclassified information (CUI) to earn Level 2 certification from a certified third-party assessment organization, known as a C3PAO, as a condition of any contract award. In its announcement, the DoD suspended not only that phase but also the later Phases 3 and 4 and every pending implementation milestone. A newly created CMMC Reform Task Force will spend 60 days reviewing whether the program survives in any form.

Officials cast the reversal as a capacity and cost problem. Chief Information Officer Kirsten Davies pointed to a gap of more than 100,000 contractors needing an assessment against roughly 100 accredited assessors, telling reporters that “the math just simply doesn’t math”. A memo she signed with acquisition chief Michael Duffey called the current program fundamentally at odds with plans to grow the defense base, and Davies estimated the coming phases would have cost small and mid-sized firms over $7 billion a year. Self-assessment stays: Phase 1, the NIST SP 800-171 Rev 2 controls, and existing DFARS data-protection clauses remain in force.

Why this is a space story

CMMC applies to any DoD contractor that touches CUI, and space programs generate plenty of it: satellite control software, propulsion and payload designs, MILSATCOM specifications, and the technical data that moves between primes and their component suppliers. Certification was not hypothetical for the sector. Satellite operator Capella Space earned CMMC Level 2 authorizing it to store, process and transmit government CUI, with defense firm Kratos acting as its third-party assessor. The Pentagon had estimated that roughly 80,000 firms would eventually fall under the third-party requirement, a group that includes a large share of the commercial space companies now selling into defense programs.

The timing is the problem

The audit requirement is vanishing at a moment when the space sector is under unusually heavy fire. Via Satellite reported in June that cyber activity against the sector was running roughly 400% above pre-war levels after US and Israeli strikes on Iran, according to Vantor CISO Norm Laudermilch. Iranian groups have been open about the targets: the IRGC-linked actor Mobir claimed intrusions against Space42, Thuraya, Yahsat, Arabsat and the UAE Space Agency, and APT33 claimed to have taken 375 terabytes of data from Lockheed Martin.

The vector is the telling part. Security teams that defend satellite networks consistently name the ground segment, enterprise IT, and third-party supply chains as the softest points in the system, not the spacecraft in orbit. Those are exactly the areas a Level 2 audit against NIST SP 800-171 was built to harden. The reporting that documented the attack surge singled out supply-chain visibility and access control as the defenses most in need of work, which is another way of describing what CMMC assessments were checking.

Ground infrastructure has moved from back-office asset to target. SpaceNews has documented operators treating teleports and ground stations as part of the battlespace after physical strikes and intrusion attempts, and pushing toward geographic redundancy and hardening in response. Removing the outside check on how those operators secure defense data does not reduce the threat. It moves the job of verifying security back onto the contractors themselves.

That move is the crux. CMMC exists because self-attestation failed once already: inspector-general reviews found contractors certifying compliance they had not met, which is what pushed the DoD toward third-party audits in the first place. Suspending Phase 2 returns space-defense suppliers to the same honor system that produced those findings, and it does so while adversaries are actively probing the supply chain that system was meant to protect.

News first reported by Breaking Defense and DefenseScoop, with space-sector reporting from Via Satellite and SpaceNews.