Congress moves to kill Pentagon's defense contractor cybersecurity mandate
H.J.Res. 40 — Providing for congressional disapproval under chapter 8 of title 5, United States Code, of the rule submitted by the Department of Defense relating to "Cybersecurity Maturity Model Certification (CMMC) Program". · Filed by Andrew Clyde (R-GA) · Introduced Feb 12, 2025 · Referred to committee
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This resolution disapproves a Department of Defense rule establishing the Cybersecurity Maturity Model Certification (CMMC) Program, which requires defense contractors to meet specific cybersecurity standards. If passed, the rule would be nullified and have no legal effect, eliminating the certification requirement for contractors seeking to work with the Pentagon.
Why we flagged it
The resolution removes a cybersecurity compliance mandate from defense contractors, reducing regulatory burden on private firms in the defense industrial base at the expense of national security standards.
What the text implies
- Elimination of CMMC removes a tiered certification system designed to protect classified and controlled unclassified information (CUI) flowing through the defense supply chain; contractors will have no standardized security baseline.
- Small and mid-sized defense contractors may have already invested in CMMC compliance; disapproval could strand those compliance costs while benefiting non-compliant competitors.
The full analysis lists 4 implications of this text.
Who stands to gain
defense contractors (reduced compliance costs); smaller defense suppliers (lower barriers to Pentagon contracts)