- Potential benefitReduces immediate compliance costs for contractors who would have needed CMMC certification.
- Potential benefitLowers contracting administrative burden and paperwork associated with certification verification.
- Potential benefitMay benefit small and mid-size suppliers by avoiding certification-related barriers to bidding.
Disapprove the Department of Defense Cybersecurity Maturity Model Certification…
Referred to the House Committee on Armed Services.
This joint resolution invokes the Congressional Review Act to disapprove and nullify the Department of Defense rule on the Cybersecurity Maturity Model Certification (CMMC) Program (89 Fed. Reg. 83092, Oct 15, 2024).
Liberal emphasizes national-security benefits of CMMC; conservatives emphasize regulatory burden
Narrow administrative action improves prospects in chamber where rule disapprovals are frequent, but defense and contractor interests could split votes.
This joint resolution invokes the Congressional Review Act to disapprove and nullify the Department of Defense rule on the Cybersecurity Maturity Model Certification (CMMC) Program (89 Fed.
Reg. 83092, Oct 15, 2024).
If enacted, the rule would have no force or effect.
Very narrow administrative target helps, but stakeholder opposition and typical upper‑chamber barriers reduce odds; outcome sensitive to timing and executive response.
How solid the drafting looks.
Liberal emphasizes national-security benefits of CMMC; conservatives emphasize regulatory burden
Who stands to gain, and who may push back.
These are examples from the analysis, not a ranked list of the most-affected groups.
- Potential burdenIncreases risk that inconsistent cybersecurity practices persist across the defense industrial base.
- Potential burdenRaises the likelihood of data breaches affecting controlled unclassified information handled by contractors.
- Potential burdenReduces DOD's standardized enforcement mechanism for baseline cybersecurity across suppliers.
Why the argument around this bill splits.
Liberal emphasizes national-security benefits of CMMC; conservatives emphasize regulatory burden
This persona would likely oppose the resolution.
They view the CMMC rule as a necessary baseline to protect controlled unclassified information and the defense supply chain, and see nullification as weakening cybersecurity protections.
This persona would be cautious and mixed.
They see legitimate goals in CMMC but worry about process, costs, and small-business burdens; they would prefer fixing implementation rather than outright nullification.
This persona would likely support the resolution.
They view the CMMC rule as federal overreach that imposes costly, prescriptive requirements on private contractors and stifles competition and flexibility.
The path through Congress.
Reached or meaningfully advanced
Reached or meaningfully advanced
Still ahead
Still ahead
Still ahead
Very narrow administrative target helps, but stakeholder opposition and typical upper‑chamber barriers reduce odds; outcome sensitive to timing and executive response.
- Absent cost/benefit analysis in bill text
- Executive-branch position on nullification
Recent votes on the bill.
No vote history yet
The bill has not accumulated any surfaced votes yet.
Go deeper than the headline read.
Liberal emphasizes national-security benefits of CMMC; conservatives emphasize regulatory burden
Very narrow administrative target helps, but stakeholder opposition and typical upper‑chamber barriers reduce odds; outcome sensitive to ti…
Pro readers get the full perspective split, passage barriers, legislative design review, stakeholder impact map, and lens-based policy tradeoff analysis for Disapprove the Department of Defense Cybersecurity Maturity Mo…
Go beyond the headline summary with full stakeholder mapping, legislative design analysis, passage barriers, and lens-by-lens tradeoff breakdowns.