Capstone believes demand for cybersecurity advisory firms will continue to grow despite the US Department of Defense’s (DOD) suspension of the third-party audit mandate for defense contractors, given pressures to comply with underlying security standards. While demand for auditors will slow until the mandate is eventually implemented, prime contractor flow-through to subcontractors will sustain some baseline demand.
- The DOD implemented the Cybersecurity Maturity Model Certification (CMMC) in 2019 and announced Phase II in 2021. However, on July 13th, it suspended the Phase II third-party certification requirements, originally due to fully take effect on November 10, 2026.
- We believe cybersecurity advisory services will continue to witness demand growth as prime contractors expect subcontractors to comply with underlying cybersecurity requirements.
- By contrast, the suspension will slow down demand for certified third-party assessment organizations (C3PAOs). We believe a revised rule will be implemented under a future administration, buoying demand for independent audits. However, the upside will be limited, as the implementation is likely to have a narrower scope, covering fewer contractors.
Background
The CMMC framework, designed to better safeguard controlled unclassified information (CUI), has roots in the early 2010s. The US DOD formally established the program in 2019 to move away from a self-attestation model for covered organizations. To make this shift, it adopted a phased approach that requires entities within the Defense Industrial Base (DIB) to receive independent certification of compliance with the National Institute of Standards and Technology (NIST) Special Publications (SP) 800-171 cybersecurity requirements.
Under CMMC 2.0, announced in 2021, DIB entities must self-assess during Phase I of implementation that started in November 2025. DIB entities required to meet “Level 2 – advanced” were then expected to meet 110 security controls of NIST SP 800-171 and pass third-party auditing every three years during Phase II. These requirements would have come into effect on November 10, 2026, while the rest of the program was expected to phase in through November 2028.
However, on July 13th, the DOD suspended these CMMC 2.0 provisions along with the implementation milestones over the next two years, as part of its efforts to “forge the arsenal of freedom.” We had also heard in our outreach conversations that C3PAOs were unlikely to meet demand before the original Phase II deadline. The Small Business Administration has supported the suspension. In the interim, regulators have maintained that the original self-attestation measures still apply. The full implementation is still slated for November 2028, absent any formal changes.
Investment Implications
The DOD’s move was unexpected and inconsistent with Capstone’s base case that the November 2026 deadline would be met and Phase II would be implemented. We believe the impacts are greatest for C3PAOs, which were poised to benefit significantly from the number of DIB contractors requiring independent assessment. However, the durability of the underlying cybersecurity requirements and the continued flow-down from prime contractors will balance some of that demand slowdown. We also expect cybersecurity advisory firms to continue seeing tailwinds given broader pressures on DIB contractors to adopt stronger cybersecurity practices. The DOD had previously estimated roughly 80,000 DIB contractors would have to comply with Level 2 requirements of independent assessment of cybersecurity practices.
In Capstone’s conversations since the suspension, stakeholders have maintained that DIB contractors need to continue working toward NIST SP 800-171 compliance. Many smaller entities will still outsource implementation to advisory firms, including managed service providers. Furthermore, requirements for self-attestation remain unchanged.
Even without the federal government mandate for independent verification, prime contractors are still likely to require their subcontractors to undertake the verification. In the event of a cybersecurity incident at a subcontractor, the prime’s attestation would be considered a “false claim” under the False Claims Act (FCA), entitling the government to treble damages. Companies have historically agreed to large settlements to avoid going to trial, and the Trump administration has continued enforcement activity. For instance, as recently as June 2026, the administration brought a case alleging FCA violations against a defense contractor.
Potential Rule Changes
We expect most of the 80,000 DIB contractors to remain subject to independent auditing requirements, even if the administration modifies the CMMC program and reduces the scope of third-party audits. Industry comments have consistently called out how CUI is defined, suggesting that perceived pain point may have partially driven the DOD’s agenda.
While the Trump administration has sufficient latitude to tinker with timing given the certification mandate originated in DOD rulemaking, CMMC is underpinned by statutory requirements and bipartisan support. In fact, these ongoing cybersecurity efforts stem from initiatives put in place during President Trump’s first term. The DOD could relatively quickly promulgate a further delay of the eventual November 2028 deadline for full implementation. Additional changes to the program’s substance would likely require more formal rulemaking, including a notice-and-comment period.
The new task force of the Small Business Administration’s Office of Advocacy recently submitted a comment letter that captures perspectives shared at a July 30th roundtable held by the agency and is consistent with our views. In summary, the office recommended that “CMMC reform should not mean weaker cybersecurity; it should mean clearer requirements, a more defined scope….” In addition, the letter affirms weaknesses in Phase I self-assessments and pushes for a “graduated path to Level 2 CMMC compliance.” Consistent with other commenters, the office also suggested limiting cybersecurity flow-down requirements to actual CUI handled by a contractor, rather than “all facets of the supply chain.”
What’s Next
The DOD’s Request for Information closed on August 14th, and the CMMC Reform Task Force is expected to issue recommendations around mid-September. Any final rule is increasingly likely to rest with a future administration, but it will depend on when the DOD acts on any findings the task force proposes. NIST has adopted the third version of SP 800-171.
Read more from Capstone’s TMT team:
Regulatory Tailwinds Build a Case for Identity Verification Vendors
AI-Resistant Moats for Established Software Providers
Which Subscription-Reliant Firms Will Face Risks Under Potential FTC Rule





























