top of page

Forging the Arsenal of Freedom: What the DoW’s CMMC Phase II Suspension Means for Innovators Like Us

  • 4 days ago
  • 2 min read

On July 13, 2026, the U.S. Department of War announced a major shift in its cybersecurity compliance strategy: the immediate suspension of CMMC Phase II requirements, originally slated for November 10, 2026. The announcement, published at war.gov (source: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/), marks a decisive pivot toward reducing bureaucratic drag across the Defense Industrial Base (DIB).

For small and medium manufacturers—especially those pushing boundaries in advanced materials, additive manufacturing, and rapid prototyping—this is a consequential moment.


Defense collage: welder sparks, engineers inspect a vehicle blueprint, a fighter jet flies, and a missile launches by a soldier.

Why the Suspension Matters

The Department of War’s leadership acknowledged what many in the DIB have been saying for years: CMMC Phase II compliance was becoming a barrier to innovation, not a safeguard. Reports from the Small Business Administration reinforced that rising compliance costs were pushing high‑value, high‑agility companies out of defense work entirely.

For a company like Lothric Labs, where speed-to-capability and precision manufacturing define our competitive edge, this shift is more than policy—it’s oxygen.



A New Direction: Cybersecurity Without the Red Tape

The Department’s announcement outlines several key changes:

  • Phase II is suspended, but Phase I self-assessments remain mandatory.

  • A 60‑day top‑to‑bottom review of CMMC is underway, led by a newly formed CMMC Reform Task Force.

  • The review aligns with Secretary of War Pete Hegseth’s Acquisition Transformation System (ATS), emphasizing:

    • Lower barriers for small and non‑traditional suppliers

    • Faster delivery of capabilities

    • Resilient, scalable cybersecurity instead of administrative overhead

  • During the review period, the Department will enforce NIST SP 800‑171 Rev 2 through self-assessments and targeted government-led evaluations.

  • DFARS 252.204‑7012 obligations remain fully in effect—data protection is still non‑negotiable.


Military collage: drone, missile trucks and launcher at sunset; submarine launch at sea; soldier with rifle beside armored vehicle.

What This Means for Lothric Labs and the Broader DIB

This suspension doesn’t eliminate cybersecurity responsibilities—it reframes them. The Department is signaling that practical cyber hygiene matters more than paperwork, and that innovation is a national security asset worth protecting.

For Lothric Labs, this aligns perfectly with our operational philosophy:

  • Lean compliance that doesn’t slow production

  • High‑integrity data protection baked into our workflows

  • Rapid iteration cycles that deliver capability without compromise

The Department’s move also opens the door for more small and mid‑sized manufacturers to re-enter defense contracting—strengthening the supply chain and accelerating the “Arsenal of Freedom” initiative.


Our Perspective Moving Forward

We welcome this shift. As a company deeply invested in advanced manufacturing, materials science, and scalable production systems, we believe the future of defense innovation depends on removing friction, not adding it.

Lothric Labs will continue to:

  • Maintain strict cybersecurity standards aligned with NIST SP 800‑171

  • Monitor the CMMC reform process closely

  • Support industry peers navigating compliance transitions

  • Advocate for frameworks that protect data and empower innovation


The Department of War’s decision is a recognition that America’s industrial strength comes from its innovators—not its paperwork.

bottom of page