The DoD Suspended CMMC Phase 2:What It Means for Your Business

Contributors

Shantanoo Govilkar
Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions
Image
CMMC-Phase-2-Suspended

On July 13, 2026, the Department of War (formerly the Department of Defense) announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, originally scheduled to take effect on November 10, 2026. The move gives the Defense Industrial Base (DIB) welcome breathing room while the Department reshapes its approach to cybersecurity compliance. The mandate for third-party audits is on pause. The reasons that made CMMC worth pursuing in the first place are not.

What Changed

DoW Chief Information Officer Kirsten A. Davies announced the suspension alongside a 60-day study into the future of the CMMC program. The Department is launching a CMMC Reform Task Force to review the certification framework from the ground up, aligning it with Secretary of War Pete Hegseth's Acquisition Transformation System (ATS) priorities: speed to capability, lower barriers for small and mid-sized businesses, and scalable, resilient cybersecurity measures.

Here's what stays the same and what shifts:

  • Enabling continuity: Phase I self-assessment requirements remain firmly in place.
  • Simplifying the path forward: Phase II transition requirements are suspended across DoW solicitations and contracts, along with all pending and future CMMC implementation milestones.
  • Strengthening the baseline: during this interim period, DoW will enforce compliance through NIST SP 800-171 Rev 2 self-assessments and select government-led assessments, with a focus on practical cyber hygiene.
  • Supporting industry input: the Reform Task Force will draw on feedback from a public Request for Information (RFI) on compliance challenges, published alongside the July 13 announcement, with comments due by 12:00 PM ET on August 14, 2026. The Task Force will deliver its recommendations to the DoW CIO within 60 days.

Contractors and subcontractors still carry a contractual obligation to protect covered defense information under DFARS clause 252.204-7012, which also requires reporting cyber incidents to DoD via DIBNet within 72 hours of discovery. Every organization operating under Phase I continues submitting its self-assessment score to the Supplier Performance Risk System (SPRS) and affirming that score annually, as required under DFARS 252.204-7019 and 252.204-7020, the clauses now carrying the interim enforcement weight while third-party assessments are paused. Data protection expectations continue. The compliance pathway is what's being reimagined.

Since the suspension came through a memo rather than a rule change, it isn't automatic inside existing contracts. 32 CFR Part 170 remains on the books, and contracting officers must formally modify any award that already includes CMMC requirements. If your existing contract includes those requirements, they remain binding until your contracting officer removes them.

A note for subcontractors: if your prime contractor has already written a Level 2 C3PAO certification requirement into your subcontract, this federal pause doesn't reach that. Your obligation to your prime runs on your contract terms, not DoW policy. Confirm directly with your prime rather than assuming the suspension covers your specific situation.

Why the Journey Doesn't Stop Here

CMMC certification was never just a box to check for a contract. It's a signal, to the Department of War and to every partner in the supply chain, that an organization takes the protection of sensitive defense information seriously. The third-party audit requirement created that signal through an outside stamp of approval. Suspending Phase II removes the audit. It doesn't remove the value of being the kind of organization that earns one.

The businesses that keep building toward full CMMC readiness during this pause, rather than setting it aside, arrive at the other end of the 60-day review already proving what the certification was designed to prove. When the Reform Task Force lands on a new framework, the strongest position belongs to the organizations that never stopped advancing their security posture in the first place.

With third-party audits paused, an accurate SPRS score carries more weight than ever. That score is a formal representation to the government, and the Department of Justice continues enforcing its accuracy under the False Claims Act. In June 2026, a Huntsville, Alabama defense contractor agreed to pay over $500,000 to resolve allegations that its self-reported perfect SPRS score didn't match what a later government-led review found. Keeping a self-assessment accurate and well-documented isn't extra work right now. It's the strongest protection a business has.

Why This Matters for the DIB

DoW cited recent data, including reports from the Small Business Administration (SBA), showing that CMMC compliance costs were pushing innovative companies out of the Defense Industrial Base. Those costs were real: DoD's own estimates put the C3PAO assessment fee itself at $105,000 to $118,000 over a three-year cycle, and SBA's Office of Advocacy has put full per-company certification costs, including remediation and preparation, near $600,000. Assessment backlogs were already forming ahead of the November deadline. Nothing about this pause lowers the bar on protecting covered defense information. What it does is buy time to build a framework where a strong security program, rather than a scarce and costly third-party assessment slot, determines whether a capable small or mid-sized business gets to compete.

The 60-day review window puts contractors in the room, not on the sidelines. The public RFI, open for comment through August 14, 2026, gives every business that has felt the compliance squeeze a formal channel to describe exactly where the current model broke down and to help shape what replaces it.

For organizations across the DIB, this is a moment to prepare rather than pause. The window is the ideal time to:

  • Strengthen existing NIST SP 800-171 self-assessment documentation and evidence trails.
  • Advance internal cyber hygiene practices ahead of whatever framework emerges from the Reform Task Force.
  • Prepare a response to the public RFI, giving your organization a direct voice in shaping the next iteration of CMMC.
  • Build a security posture that protects covered defense information regardless of certification milestones.

Continue Your Journey to Security With DivIHN

The audit requirement is on hold. The reasons to pursue it are not. 

DivIHN works with manufacturers and defense contractors who are navigating exactly this landscape. If you have questions about where your business stands or what you should be prioritizing during this review period, we are happy to help you think it through.

Sources:

Get the latest insights straight from our desk to your inbox.

Other Featured Articles

Explore More
CMMC-Phase-2-Suspended

The DoD Suspended CMMC Phase 2: What It Means for Your Business

CMMC Phase II suspended: DoW halts third-party audit mandate to ease compliance costs for small and mid-sized defense contractors. What's paused, what isn't, and how to prepare.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
what-is-cmmc-do-you-need-it

What Is CMMC and Do You Need It?

Learn what CMMC is, who needs it, and how to determine if your business requires Level 1 compliance for DoD contracts.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
mmc-level-selection-guide

CMMC Level 1 vs Level 2, Which Applies to You?

Learn the key differences between CMMC Level 1 and Level 2, understand FCI vs. CUI, and determine which CMMC level your DoD contract requires to avoid unnecessary costs or compliance risks.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
cmmc-dod-subcontractors

What CMMC Means for DoD Subcontractors

Understand what CMMC means for DoD subcontractors, how compliance requirements flow down from prime contractors, who must comply, and the steps to determine your CMMC obligations.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
cmmc-level-1-self-assessment-guide

How to Complete Your CMMC Level 1 Self Assessment

Complete CMMC Level 1 self-assessment guide: define scope, work through 15 practices, fix common gaps, and submit your SPRS affirmation.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
cmmc-october-2026-deadline

The October 2026 CMMC Deadline: What Happens If You Miss It 

Prepare for the October 2026 CMMC deadline. Learn how compliance affects DoD contract eligibility, SPRS affirmations, renewals, and subcontractors.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
IT-OT-Boundary-Ransomware-Entry-Point

Operational Technology (OT) Penetration Testing Guide for Ransomware Defense

Ransomware doesn't need to breach your control room it needs to get close enough that you can't trust it hasn't.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
FDA-510K-and-PMA-Cybersecurity-Testing

A Medical Device Maker's Guide to FDA Cybersecurity Testing for 510(k) & PMA

The FDA doesn't publish a pen testing checklist, but its guidance, 524B requirements, and reviewer expectations add up to one.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Pharma-Pen-Testing-FDA-Complianc

Pharma Pen Testing: Why FDA and IP Risk Need Different Scoping

Standard pen test scoping frameworks weren't built for pharma.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
FDA-524B-Medical-Device-Cybersecurity-Testing

FDA 524B Is Here: What Medical Device Makers Must Test Now

Section 524B made medical device cybersecurity a legal requirement, not a guideline.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
CMMC-2-0-Pen-Testing-Requirements

Why CHIPS Act Manufacturers Can't Rely on CMMC Pen Testing Alone

Semiconductor manufacturers face dual compliance obligations under CMMC 2.0 and the CHIPS Act and a standard pen test satisfies neither fully.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
C3PAO-Audit-Evidence-Mapping

Why Pen Test Evidence Fails C3PAO Assessments (and How to Fix It)

Completing a pen test isn't enough for CMMC.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
PTaaS-vs-Annual-Pen-Testing

PTaaS vs. Annual Pen Testing: Why Manufacturers Are Switching

Annual penetration testing produces documentation, not security.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Map-OT-Attack-Surface

Map Your OT Attack Surface Before the Next Audit

Don't wait for an auditor to tell you what you missed.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Scope-IT-OT-Penetration-Testing

How to Scope IT-OT Penetration Testing Safely

Learn how to safely scope IT-OT penetration testing engagements.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Manufacturing-Penetration-Testing-Frequency

How Often Should Manufacturers Run OT Penetration Testing?

Annual pen testing fits a budget cycle but it doesn't reflect how fast manufacturing environments actually change.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
21-CFR-Part-11-and-cGMP-Requirements

Pharmaceutical Pen Testing: What 21 CFR Part 11 and cGMP Require

21 CFR Part 11 and cGMP don't mention penetration testing but the controls they require depend on it.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
RD-and-Regulated-Systems-Penetration-Testing-Scopes

Pharmaceutical Pen Testing: Why R&D and GxP Need Different Scopes

R&D and GxP regulated environments have different risk profiles, compliance requirements, and testing constraints.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Nation-State-Cyber-Threats-in-Pharma

Why Pharmaceutical Pen Testing Must Address Nation-State Threats

Nation-state actors treat pharma like critical infrastructure targeting formulation data, synthesis routes, and clinical IP with patience and precision.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
IT-OT-Boundary-Ransomware-Risk

How Ransomware Crosses the IT-OT Boundary (And How to Stop It)

Ransomware operators target the IT-OT boundary deliberately and they know manufacturing economics well.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
Where-Industry-4-0-Exposed-OT

Where Industry 4.0 Left Your OT Attack Surface Wide Open

Industry 4.0 connected OT environments were never built for. Learn why traditional IT security tools fall short and what OT penetration testing reveals that audits miss.

Shantanoo Govilkar
SVP Strategic Solutions Risk & Cybersecurity Solutions view
What-AS4-Actually-Solves-Banner-Image

What AS4 Actually Solves: Real Outcomes Companies See After Migration

Discover what AS4 actually solves for modern businesses. Learn the real outcomes companies achieve after migration, from stronger security to better B2B integration performance.

 

EDI Solutions Group
Marketing Group view
AS4-migration-pitfalls-Banner-image

7 Migration Pitfalls That Derail AS4 Upgrades (and How to Avoid Them)

Avoid costly AS4 upgrade mistakes. Discover 7 migration pitfalls that delay projects, create risk, and disrupt B2B messaging, plus practical ways to avoid them.

EDI Solutions Group
Marketing Group view
pen-testing-in-cloud-enviroment-banner-image

How to Perform Penetration Testing in Cloud Environments (AWS, Azure, and GCP) - 2026 Edition

A practical guide to cloud penetration testing across AWS, Azure, and GCP. Learn methods, tools, and best practices to identify vulnerabilities and improve security.

Cybersecurity Solutions Group
Marketing Group view
when-to-switch-legacy-edi-to-as4

5 Signs It's Time to Move Legacy EDI Environment to AS4 Protocol

Partner onboarding delays, compliance gaps, and rising maintenance costs are signals your EDI infrastructure is reaching its limits. Learn the five signs it is time to evaluate a move to AS4.

EDI Solutions Group
Marketing Group view
How-to-Design-Custom-Chatbots-Banner-Image

How to Design Custom Chatbots That Cannot “Make Stuff Up”

Confident AI answers without traceable sources create institutional risk. Learn how Grounded RAG architecture retrieves real documents first and attaches verifiable citations to every response.

Data and AI Solutions Group
Marketing Group view
Conversational-AI-blog-banner

How Citation-Backed Conversational AI Improves Public Access and Internal Decision-Making

AI without source citations creates real liability. Learn how citation-backed AI brings traceable sources, version awareness, and audit-ready outputs to every institutional decision.

Data and AI Solutions Group
Marketing Group view
Network-penetration-testion-blog-banner

How to Perform a Successful Network Penetration Test: Comprehensive Guide for 2025

Learn how to perform a successful network penetration test to identify vulnerabilities, simulate real cyberattacks, and strengthen your organization’s network security.

Cybersecurity Solutions Group
Marketing Group view
Penetration-testing-banner-image

What Is Penetration Testing? A 2026 Expert Guide

A 2026 expert guide to penetration testing for security leaders and IT teams seeking proactive defense, compliance, and stakeholder trust.

Cybersecurity Solutions Group
Marketing Group view
ot-ransomware-prevention-banner-image

OT Ransomware Prevention: Practical Best Practices for Industrial Cybersecurity

Explore enterprise grade OT ransomware prevention strategies, including segmentation, identity control, threat informed detection, and resilient recovery design to protect industrial operations fro

Cybersecurity Solutions Group
Marketing Group view
OT-Ransomware-Risks-and-Response-Banner

10 Myths About OT/ICS Security That Put Your Business at Risk

Think your OT network is secure? Learn the 10 most dangerous myths about OT and ICS cybersecurity that leave industrial operations exposed to attacks.

Cybersecurity Solutions Group
Marketing Group view
OT-ransomeware-risk-and-responses-banner-image

OT Ransomware Risks and Response for Industrial Systems

Learn why OT environments face higher ransomware risk, how attackers gain access, and how effective detection and response reduce operational impact.

Cybersecurity Solutions Group
Marketing Group view
AI-Risk-Assessment-Best-Practices-Banner

AI Risk Assessment: Risk Types, Best Practices & More

Explore AI risk types, essential assessment frameworks, and proven best practices to mitigate threats in AI deployment. Learn actionable strategies for secure AI systems today.

Cybersecurity Solutions Group
Marketing Group view
AI Risk Assessment Banner Image

AI Risk Assessment: Everything You Need to Know

Learn essential processes, methodologies, risk types, regulatory requirements, and practical implementation strategies for safe AI deployment.

Cybersecurity Solutions Group
Marketing Group view
Whitepaper: Ransomware Threat Management

Whitepaper: Ransomware Threat Management

Ransomware continues to be a real threat to business operations across all industries, no organization is safe from this threat.

Laszlo S. Gonc
CISSP, First Senior Fellow, DivIHN Cybersecurity Center of Excellence view
Cybersecurity Incident Response Preparedness

Cybersecurity Incident Response Preparedness

An incident response framework provides a structure to support incident response operations. A framework typically provides guidance on what needs to be done, but not on how it is done.

Laszlo S. Gonc
CISSP, First Senior Fellow, DivIHN Cybersecurity Center of Excellence view
Internet of Things

IoT Medical Device Cybersecurity

Healthcare data and medical devices would be aggressively targeted by ransomware attacks since early 2017 has proven to be true

Laszlo S. Gonc
CISSP, First Senior Fellow, DivIHN Cybersecurity Center of Excellence view
Back
to Top