BLUF;

  • CMMC Phase II has been paused, but CMMC has not been canceled.
  • NIST SP 800-171 Rev. 2, DFARS 252.204-7012, and applicable self-assessment requirements remain in effect.
  • Organizations should continue strengthening their cybersecurity programs while the Department of War completes its 60-day review.

On July 13, the Department of War announced the immediate pause of Cybersecurity Maturity Model Certification Phase II (CMMC Phase II), delaying the planned November 10, 2026 rollout of third-party C3PAO assessments while a newly formed CMMC Reform Task Force conducts a comprehensive 60-day review of the certification program.

Read The CyberAB’s official press release. (July 15, 2026)

Although the announcement has led some to believe CMMC has been canceled, that is not the case. Phase I requirements remain in effect, meaning organizations handling Controlled Unclassified Information (CUI) must continue meeting the cybersecurity requirements of NIST SP 800-171 Rev. 2, complete required Level 2 self-assessments, and maintain affirmations where specified by contract. Contractors also remain contractually obligated to protect covered defense information under DFARS 252.204-7012.

The DoW says the review is intended to reduce compliance burdens, particularly for small and non-traditional businesses, while maintaining a strong cybersecurity baseline. The goal is to identify more scalable and resilient security measures that better align with the DoW’s broader acquisition modernization efforts.

While the DoW has paused the rollout of mandatory Level 2 certifications, they have not removed the underlying cybersecurity requirements. Our team recommends that organizations continue to work toward their CMMC L2 certification.

Defense Contractors Should Not Stop Preparing for CMMC

For defense contractors, the key takeaway is simple: don’t stop preparing. The timeline may have changed, but the need to protect sensitive information has not. Threat actors targeting the Defense Industrial Base are not waiting for regulatory updates, and strong cybersecurity practices remain essential regardless of when revised CMMC requirements emerge. Use the delay to strengthen cybersecurity posture and close known gaps.

  • For small businesses, the additional time can be used to build security processes that may have previously been constrained by budget or staffing limitations.
  • For mid-sized and large defense contractors, the delay provides an opportunity to mature existing security programs, standardize policies across business units, automate evidence collection, remediate longstanding technical gaps, and validate controls.

Organizations that have built security programs around managing risk rather than simply passing an assessment are well positioned to adapt to whatever follows the 60-day review. Compliance requirements may evolve, but a mature cybersecurity program built on sound security practices will continue to meet both contractual obligations and operational needs.

Why Third Party Assessment Still Matters

If your company is selected for a government-led assessment, completing a third-party assessment beforehand can help identify and address findings before a government team evaluates your environment.

Want to talk to an expert about what this means for your CMMC efforts? Schedule a meeting >


Key Questions This Article Answers

  • Has CMMC Phase II been canceled?
  • What does the suspension of CMMC Phase II mean for defense contractors?
  • Do organizations still need to comply with NIST SP 800-171 Rev. 2?
  • Are DFARS 252.204-7012 requirements still in effect?
SecureStrux

SecureStrux

As a cybersecurity firm with deep roots in the Department of War (DoW) cybersecurity community, we provide specialized services in the areas of compliance, vulnerability management, cybersecurity strategies, and engineering solutions. Since 2013, we’ve partnered with hundreds of organizations within and outside the DoW to understand and proactively manage their risk. Our strength within the DoW has allowed us to easily translate best practices to our clients in other industries including Energy, Manufacturing, Architecture, Education, and Aerospace.

The latest in Cybersecurity

Enter your email to get the latest news, updates,
and content on cybersecurity.

"*" indicates required fields

How Did You Hear About SecureStrux?