Summary

On July 13, 2026, the U.S. Department of War announced the immediate suspension of Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) assessment requirements, which had been scheduled to take effect on November 10, 2026. The Department also suspended pending and future CMMC implementation milestones across its solicitations and contracts while conducting a broader review of the program.

Phase 2 would have expanded requirements for CMMC Level 2 certification assessments performed by accredited Certified Third-Party Assessment Organizations (C3PAOs) for contractors handling Controlled Unclassified Information (CUI). The suspension affects contractors and subcontractors across the defense industrial base who had been preparing for significant compliance burdens.

The Department explicitly stated that all Phase 1 self-assessment requirements remain in place and that the action “does not eliminate the requirement for companies to protect federal data.” Contractors subject to DFARS clause 252.204-7012 remain obligated to safeguard covered defense information per NIST SP 800-171 Rev. 2.

Source

WilmerHale — Pentagon Suspends CMMC Phase 2 Requirements
Department of War — Forging the Arsenal of Freedom Release

Commentary

This is a significant policy shift with real implications for the defense industrial base. Phase 2 was the phase that would have brought actual third-party oversight to the table — moving beyond self-assessment to independent verification. Its suspension means contractors now have more time, but it also signals uncertainty about the long-term regulatory trajectory.

The fact that Phase 1 (self-assessment) remains in place suggests the Pentagon isn’t retreating from cybersecurity requirements — just reconsidering the enforcement mechanism. Defense contractors should continue treating Phase 1 obligations as binding and prepare for the possibility that Phase 2 could be restructured rather than eliminated entirely.

For blue team practitioners in the defense sector, this means the baseline security requirements haven’t changed, but the compliance roadmap has. Organizations should focus on maintaining NIST SP 800-171 compliance regardless of the certification timeline.

By Allan