This joint resolution expresses congressional disapproval of the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) Program rule, effectively preventing it from taking effect.
Andrew Clyde
Representative
GA-9
This joint resolution expresses congressional disapproval of the Department of Defense’s Cybersecurity Maturity Model Certification (CMMC) Program rule. If enacted, this measure would prevent the rule from taking effect and render it without legal force.
This joint resolution is a straight-up 'delete' button for a major Department of Defense (DoD) regulation. By invoking the Congressional Review Act, lawmakers are looking to nullify the Cybersecurity Maturity Model Certification (CMMC) Program rule published at 89 Federal Register 83092. If this passes, the rule won't just be paused—it will be treated as if it never existed, and the DoD would be legally barred from issuing a 'substantially similar' rule in the future without a new act of Congress.
The CMMC program was designed to be a standardized security framework for the hundreds of thousands of companies in the defense industrial base. Think of it like a mandatory home security system for anyone building parts for a fighter jet or providing software to the Pentagon. This resolution effectively stops that security system from being installed. For a small machine shop owner in Ohio who makes specialized bolts for the military, this means they won't have to navigate the complex and often expensive process of getting third-party cybersecurity audits that the rule required. The immediate impact is a sigh of relief for contractors worried about compliance costs and the bureaucratic hurdles of proving their digital defenses are up to snuff.
While the bill cuts through the regulatory red tape that many businesses feared would eat into their margins, it also leaves a question mark over national security. The DoD's goal with the original rule was to stop 'death by a thousand cuts'—the constant theft of sensitive but unclassified data by foreign adversaries. By blocking this rule, the government keeps the status quo where cybersecurity requirements are often self-attested and inconsistent. For the average taxpayer, this is a classic trade-off: it protects the economic viability of small businesses that serve our military, but it potentially leaves the digital 'back door' to our defense supply chain less fortified than the Pentagon intended.