Forging the Arsenal of Freedom: What the DoW’s CMMC Phase II Suspension Means for Innovators Like Us
- 4 days ago
- 2 min read
On July 13, 2026, the U.S. Department of War announced a major shift in its cybersecurity compliance strategy: the immediate suspension of CMMC Phase II requirements, originally slated for November 10, 2026. The announcement, published at war.gov (source: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/), marks a decisive pivot toward reducing bureaucratic drag across the Defense Industrial Base (DIB).
For small and medium manufacturers—especially those pushing boundaries in advanced materials, additive manufacturing, and rapid prototyping—this is a consequential moment.

Why the Suspension Matters
The Department of War’s leadership acknowledged what many in the DIB have been saying for years: CMMC Phase II compliance was becoming a barrier to innovation, not a safeguard. Reports from the Small Business Administration reinforced that rising compliance costs were pushing high‑value, high‑agility companies out of defense work entirely.
For a company like Lothric Labs, where speed-to-capability and precision manufacturing define our competitive edge, this shift is more than policy—it’s oxygen.
A New Direction: Cybersecurity Without the Red Tape
The Department’s announcement outlines several key changes:
Phase II is suspended, but Phase I self-assessments remain mandatory.
A 60‑day top‑to‑bottom review of CMMC is underway, led by a newly formed CMMC Reform Task Force.
The review aligns with Secretary of War Pete Hegseth’s Acquisition Transformation System (ATS), emphasizing:
Lower barriers for small and non‑traditional suppliers
Faster delivery of capabilities
Resilient, scalable cybersecurity instead of administrative overhead
During the review period, the Department will enforce NIST SP 800‑171 Rev 2 through self-assessments and targeted government-led evaluations.
DFARS 252.204‑7012 obligations remain fully in effect—data protection is still non‑negotiable.

What This Means for Lothric Labs and the Broader DIB
This suspension doesn’t eliminate cybersecurity responsibilities—it reframes them. The Department is signaling that practical cyber hygiene matters more than paperwork, and that innovation is a national security asset worth protecting.
For Lothric Labs, this aligns perfectly with our operational philosophy:
Lean compliance that doesn’t slow production
High‑integrity data protection baked into our workflows
Rapid iteration cycles that deliver capability without compromise
The Department’s move also opens the door for more small and mid‑sized manufacturers to re-enter defense contracting—strengthening the supply chain and accelerating the “Arsenal of Freedom” initiative.
Our Perspective Moving Forward
We welcome this shift. As a company deeply invested in advanced manufacturing, materials science, and scalable production systems, we believe the future of defense innovation depends on removing friction, not adding it.
Lothric Labs will continue to:
Maintain strict cybersecurity standards aligned with NIST SP 800‑171
Monitor the CMMC reform process closely
Support industry peers navigating compliance transitions
Advocate for frameworks that protect data and empower innovation
The Department of War’s decision is a recognition that America’s industrial strength comes from its innovators—not its paperwork.




