The DoD Suspended CMMC Phase 2:What It Means for Your Business
Contributors
On July 13, 2026, the Department of War (formerly the Department of Defense) announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, originally scheduled to take effect on November 10, 2026. The move gives the Defense Industrial Base (DIB) welcome breathing room while the Department reshapes its approach to cybersecurity compliance. The mandate for third-party audits is on pause. The reasons that made CMMC worth pursuing in the first place are not.
What Changed
DoW Chief Information Officer Kirsten A. Davies announced the suspension alongside a 60-day study into the future of the CMMC program. The Department is launching a CMMC Reform Task Force to review the certification framework from the ground up, aligning it with Secretary of War Pete Hegseth's Acquisition Transformation System (ATS) priorities: speed to capability, lower barriers for small and mid-sized businesses, and scalable, resilient cybersecurity measures.
Here's what stays the same and what shifts:
- Enabling continuity: Phase I self-assessment requirements remain firmly in place.
- Simplifying the path forward: Phase II transition requirements are suspended across DoW solicitations and contracts, along with all pending and future CMMC implementation milestones.
- Strengthening the baseline: during this interim period, DoW will enforce compliance through NIST SP 800-171 Rev 2 self-assessments and select government-led assessments, with a focus on practical cyber hygiene.
- Supporting industry input: the Reform Task Force will draw on feedback from a public Request for Information (RFI) on compliance challenges, published alongside the July 13 announcement, with comments due by 12:00 PM ET on August 14, 2026. The Task Force will deliver its recommendations to the DoW CIO within 60 days.
Contractors and subcontractors still carry a contractual obligation to protect covered defense information under DFARS clause 252.204-7012, which also requires reporting cyber incidents to DoD via DIBNet within 72 hours of discovery. Every organization operating under Phase I continues submitting its self-assessment score to the Supplier Performance Risk System (SPRS) and affirming that score annually, as required under DFARS 252.204-7019 and 252.204-7020, the clauses now carrying the interim enforcement weight while third-party assessments are paused. Data protection expectations continue. The compliance pathway is what's being reimagined.
Since the suspension came through a memo rather than a rule change, it isn't automatic inside existing contracts. 32 CFR Part 170 remains on the books, and contracting officers must formally modify any award that already includes CMMC requirements. If your existing contract includes those requirements, they remain binding until your contracting officer removes them.
A note for subcontractors: if your prime contractor has already written a Level 2 C3PAO certification requirement into your subcontract, this federal pause doesn't reach that. Your obligation to your prime runs on your contract terms, not DoW policy. Confirm directly with your prime rather than assuming the suspension covers your specific situation.
Why the Journey Doesn't Stop Here
CMMC certification was never just a box to check for a contract. It's a signal, to the Department of War and to every partner in the supply chain, that an organization takes the protection of sensitive defense information seriously. The third-party audit requirement created that signal through an outside stamp of approval. Suspending Phase II removes the audit. It doesn't remove the value of being the kind of organization that earns one.
The businesses that keep building toward full CMMC readiness during this pause, rather than setting it aside, arrive at the other end of the 60-day review already proving what the certification was designed to prove. When the Reform Task Force lands on a new framework, the strongest position belongs to the organizations that never stopped advancing their security posture in the first place.
With third-party audits paused, an accurate SPRS score carries more weight than ever. That score is a formal representation to the government, and the Department of Justice continues enforcing its accuracy under the False Claims Act. In June 2026, a Huntsville, Alabama defense contractor agreed to pay over $500,000 to resolve allegations that its self-reported perfect SPRS score didn't match what a later government-led review found. Keeping a self-assessment accurate and well-documented isn't extra work right now. It's the strongest protection a business has.
Why This Matters for the DIB
DoW cited recent data, including reports from the Small Business Administration (SBA), showing that CMMC compliance costs were pushing innovative companies out of the Defense Industrial Base. Those costs were real: DoD's own estimates put the C3PAO assessment fee itself at $105,000 to $118,000 over a three-year cycle, and SBA's Office of Advocacy has put full per-company certification costs, including remediation and preparation, near $600,000. Assessment backlogs were already forming ahead of the November deadline. Nothing about this pause lowers the bar on protecting covered defense information. What it does is buy time to build a framework where a strong security program, rather than a scarce and costly third-party assessment slot, determines whether a capable small or mid-sized business gets to compete.
The 60-day review window puts contractors in the room, not on the sidelines. The public RFI, open for comment through August 14, 2026, gives every business that has felt the compliance squeeze a formal channel to describe exactly where the current model broke down and to help shape what replaces it.
For organizations across the DIB, this is a moment to prepare rather than pause. The window is the ideal time to:
- Strengthen existing NIST SP 800-171 self-assessment documentation and evidence trails.
- Advance internal cyber hygiene practices ahead of whatever framework emerges from the Reform Task Force.
- Prepare a response to the public RFI, giving your organization a direct voice in shaping the next iteration of CMMC.
- Build a security posture that protects covered defense information regardless of certification milestones.
Continue Your Journey to Security With DivIHN
The audit requirement is on hold. The reasons to pursue it are not.
DivIHN works with manufacturers and defense contractors who are navigating exactly this landscape. If you have questions about where your business stands or what you should be prioritizing during this review period, we are happy to help you think it through.
Sources:
Other Popular Articles
In the digital age, businesses must adopt an ad
GRC is the capability, or integrated collection