CMMC Phase II Suspended: A Guide For DoW Contractors During the Review
The Department of War has suspended the Cybersecurity Maturity Model Certification Phase II requirements as of July 13, 2026. The planned expansion of third-party assessment requirements had been scheduled to roll out on November 10. Learn what contractors should do during the temporary pause.
On July 13, the Department of War (DoW) released an unexpected announcement that the CMMC Phase II requirements would be suspended for 60 days, and that a new CMMC Reform Task Force would conduct a review of the program. The decision has also paused pending and future CMMC implementation milestones (phases) while the 60-day review progresses. A public Request for Information (RFI) from the DoW will act to synthesize industry feedback during the review.
This change of plans has rocked the defense industrial base because many contractors and subcontractors were already well underway in preparations for compliance with CMMC Phase II.
So, where do DoW contractors go from here?
While the announcement has suspended the rollout schedule, it does not remove the cybersecurity obligations defense contractors and subcontractors already carry under their contracts. Here are some additional tips to help you understand these changes and guide your compliance decisions during the review period.
CMMC Phase II Is Suspended For Review
The CMMC Phase I requirements took effect in November 2025 and allowed applicable contracts to include self-assessment requirements. Phase II, which was set to come into effect on November 10, 2026, would have expanded the use of third-party assessments by Certified Third-Party Assessment Organizations (C3PAOs).
The July announcement suspends that Phase II expansion. It does not erase or suspend CMMC Phase I, and neither does it eliminate the underlying security requirements for protecting Controlled Unclassified Information.
Why Did the Department of War Suspend Phase II?
The Department cited several factors, including compliance costs, limited assessment capacity, complicated timelines, and the effect those burdens were having on small and nontraditional defense businesses.
DoW Chief Information Officer Kirsten A. Davies said the Department was initiating a 60-day study while preserving “robust cybersecurity and operational resilience.”
Federal News Network reported that DoW officials believe the current program creates “significant and often prohibitive burdens” for parts of the Defense Industrial Base. The review will consider a framework that lowers entry barriers while placing greater emphasis on measurable security outcomes.
The suspension is also an opportunity to collect information and commentary from the manufacturing base itself. The Department has issued a public Request for Information seeking feedback from Defense Industrial Base organizations about compliance challenges and costs, assessment capacity, and potential reforms.
NOTE: Responses to the RFI are due August 14, 2026.
Contractors who have been working on navigating CMMC should consider submitting detailed feedback while that window remains open. It’s a democratic chance to influence the outcome.
Current Cybersecurity Obligations Remain in Force
The suspension applies to federal CMMC implementation milestones. Existing contract requirements still govern the protection of Federal Contract Information and Controlled Unclassified Information.
Depending on the contract and the information involved, those obligations may include:
● FAR 52.204-21, which establishes basic safeguarding requirements for Federal Contract Information
● DFARS 252.204-7012, which requires contractors and subcontractors to protect covered defense information
● NIST SP 800-171 Revision 2, when incorporated into the contract for systems handling CUI
● SPRS Assessments, or the required cybersecurity self-assessments and score reporting through the Supplier Performance Risk System
● Other security obligations flowed down by prime contractors to suppliers and subcontractors
The Department stated plainly in the announcement that defense contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012.
Prime contractors may also continue enforcing their own supplier cybersecurity programs. A federal pause does not require them to remove security conditions from subcontracts, vendor reviews, or purchasing requirements.
Self-Attestation Carries More Legal Weight During the Pause
The third-party assessment requirements of Phase II were meant to verify that contractors had implemented the specific controls they claimed to have in place.
During the temporary pause, however, self-assessments and selected government-led assessments will remain the primary verification methods used by the Department. Per the DoW, “All Phase I self-assessment requirements remain firmly in place.” Organizations must rely on their own documented self-assessments to demonstrate compliance, as they have since Phase I took effect on November 10, 2025.
That places greater weight on the quality and accuracy of each contractor’s compliance documentation. Three records deserve immediate attention:
● System Security Plan: The SSP should accurately describe the systems, boundaries, technologies, personnel, and procedures used to protect CUI.
● SPRS Score: Contractors should confirm that the score submitted to SPRS is current, defensible, and supported by evidence.
● Plan of Action and Milestones: A POA&M should identify unresolved security requirements, assign ownership, and provide credible completion dates. It should reflect active remediation rather than an indefinite holding list.
Executives responsible for compliance affirmations should understand the evidence supporting those representations. Self-attestation carries contractual and legal consequences.
Recommended Steps During the 60-Day CMMC Review
This pause is no release from cybersecurity concerns. The federal suspension governs Department implementation, while individual customers may maintain their own security expectations.
Contractors should treat the review period as additional preparation time and take the following actions to maintain compliance:
Continue implementing applicable NIST SP 800-171 controls.
Review the SSP against the current environment and keep it updated.
Review your SPRS score and validate the evidence behind it.
Keep moving POA&M items toward completion.
Watch for contract modifications (new clauses, modifications, solicitations, and prime contractor notices).
Stay informed during the 60-day review.
Organizations that had planned a C3PAO assessment should speak with their assessment provider before changing course. Formal assessment timing may shift, but the preparation already completed may remain valuable under the revised program.
Erudio Is Ready to Assist Defense Contractors
The CMMC Phase II suspension introduces uncertainty around the future assessment model. However, it does not lessen your organization’s obligation to protect CUI, maintain accurate records, or satisfy current contract clauses.
The audit timeline may have shifted, but contractual cybersecurity obligations remain.
Organizations that use the review period to validate controls, improve documentation, and correct weaknesses will improve their security posture and emerge better prepared for whichever structure the Department adopts next.
Erudio can help defense contractors review their current requirements and evaluate readiness during this temporary pause. Work with seasoned compliance experts to prepare accurate documentation and determine how the suspension affects your contracts and assessment plans.
Contact Erudio today to discuss your CMMC status and the steps your organization should take during the 60-day review.
FAQs
Did the Department suspend CMMC Level 2?
No. The Department suspended the Phase II implementation timeline, which would have expanded third-party assessment requirements. CMMC Level 2 and the underlying requirements for protecting CUI remain relevant where applicable.
Do subcontractors still need to comply with CMMC-related cybersecurity requirements?
Yes. Subcontractors remain responsible for applicable clauses flowed down through their contracts, including requirements related to FCI, CUI, DFARS 252.204-7012, and NIST SP 800-171.
Should we stop preparing for a C3PAO assessment?
Contractors should consult their C3PAO before canceling or postponing assessment work. The timeline may change, but the controls, documentation, and evidence prepared for an assessment can still support current compliance duties and future requirements.
Does our SPRS score still matter?
Yes. Phase I self-assessment requirements remain in effect for applicable contracts, and SPRS scores continue to document a contractor’s assessment of its NIST SP 800-171 implementation.
What happens after the 60-day review?
The CMMC Reform Task Force will provide recommendations to the Department CIO. Those recommendations could preserve, revise, or replace parts of the current assessment structure. Contractors should follow official announcements and review new contract language as it appears.
Should contractors continue working on SSP and POA&M?
Yes. The SSP should remain accurate, and POA&M items should continue moving toward completion. These documents support self-assessment scores, customer reviews, government assessments, and future certification activity.
Should we continue implementing NIST SP 800-171 controls?
Yes. Defense contractors and subcontractors should continue implementing the NIST SP 800-171 controls required by their contracts. The Phase II suspension changes the CMMC rollout schedule, but it does not remove existing obligations under DFARS 252.204-7012 or the need to protect Controlled Unclassified Information. Continued work on these controls will also support accurate self-assessments, SPRS scores, SSP updates, and future certification requirements.
Can prime contractors still require suppliers to meet cybersecurity standards?
Yes. Prime contractors may continue applying their own supplier security requirements and flowing contractual obligations down to subcontractors, even while federal Phase II implementation is paused.
How can contractors participate in the CMMC review?
The Department issued a Request for Information seeking feedback from the Defense Industrial Base. Contractors can submit information about compliance challenges, costs, assessment capacity, and proposed alternatives by the stated August 14, 2026 deadline.