The $3 Trillion Defense Market Behind the CMMC Debate

When the Pentagon suspended CMMC Phase II on July 13, 2026, the immediate story was about compliance requirements and assessment deadlines. But the decision didn't happen in a vacuum. It happened against the backdrop of one of the largest and most complex procurement markets in the federal government.
HigherGov award data helps illustrate the scale and diversity of the market affected by defense cybersecurity policy. The following figures provide context on the broader Department of War contracting market; they do not indicate that every award or contractor included in the analysis was subject to CMMC.
For the compliance guidance itself (what changed, what remains required, and what contractors should do now) see our companion article, “CMMC Phase II Is Suspended: What Defense Contractors Need to Know and Do Now”.
DoW awards totaled approximately $3 trillion over five years
$3 trillion in DoW awards over five years
Across the five-year HigherGov view, the Department of War accounted for approximately:

$3 trillion: total DoW contracts, subcontracts, grants, and subgrants over five years. Source: HigherGov analysis of federal award data.
The 2026 figures shown in the HigherGov analysis represent a partial year and should not be compared directly with completed fiscal years.
The scale of the market helps explain why changes to contractor cybersecurity requirements can have broad consequences. Even when requirements apply only to companies handling specific types of government information, they can influence teaming, technology selection, subcontractor management, pricing, and market-entry decisions.
Navy, Army, and Air Force accounted for $434.3 billion in prior-year awards

Prior-year DoW awards by component
The Navy, Army, and Air Force together accounted for approximately $434.3 billion, or about 77% of the $560.9 billion shown in the prior-year HigherGov analysis.
This breadth demonstrates why CMMC cannot be viewed solely as a requirement for cybersecurity companies or IT contractors. Defense information moves through organizations buying aircraft, ships, weapons systems, engineering, logistics, healthcare, research, software, and professional services.
More than $219 billion flowed through DoW small-business set-asides
Across the three-year HigherGov view, the Department of War obligated approximately $219.3 billion through small-business and socioeconomic set-aside categories.

$219.3 billion: DoW obligations through small-business and socioeconomic set-asides over three years. Source: HigherGov analysis of federal award data.
These figures represent overall DoW set-aside obligations, not spending specifically subject to a CMMC requirement.
They do, however, show why the cost and accessibility of CMMC became an industrial-base concern. A certification expense that may be manageable for a large prime contractor can become a substantial barrier for a small manufacturer, startup, engineering business, or first-time defense contractor.
The debate was not whether small defense contractors should protect sensitive information. The debate was whether the certification model was affordable and scalable across a market where more than $219 billion flowed through small-business set-asides over three years.
The CMMC debate extends far beyond IT contractors

Industries receiving the most DoW contract obligations
HigherGov's three-year analysis covers approximately $1.6 trillion in DoW contract obligations across industry categories.
Companies potentially affected by defense cybersecurity requirements include:
- Aircraft and aerospace manufacturers
- Engineering firms
- Research organizations
- Shipbuilders
- Component manufacturers
- Construction contractors
- Logistics providers
- Healthcare organizations
- Technology providers
- Professional services companies
CMMC was never exclusively an IT-sector issue. Sensitive information can move through almost every level of the defense supply chain.
Major contract vehicles connect thousands of businesses to DoW spending

HigherGov identified approximately $326.9 billion in obligations across major contract vehicles during the analyzed three-year period.
The presence of vehicles such as OASIS Small Business and SEWP V illustrates how cybersecurity policy can affect contractors competing through major governmentwide and defense-specific vehicles, not only companies pursuing standalone DoW procurements.
Why this matters for the CMMC debate
None of this data proves a CMMC requirement applied to any specific award. What it shows is scale: a market this large, spanning this many industries and contract types, is exactly why a compliance model's cost and accessibility became a flashpoint rather than a footnote. A certification requirement that looks manageable on paper can still reshape teaming decisions, technology selection, and market entry across a defense industrial base this broad.
Explore DoW spending and market trends in HigherGov
See the agencies, industries, contractors, set-asides, and vehicles shaping the defense market.
Explore HigherGov DoW Market Data.
Disclaimer
This article is intended for informational purposes and does not constitute legal, cybersecurity, or contracting advice. Contractors should review their specific solicitations, contracts, systems, and information-handling practices with qualified legal and compliance professionals.
Click here to schedule a demo to get the full scoop on how our product actually works and discover how AI can transform your approach to government contracting.


.png)