CMMC Phase II suspended: What contractors need to know

On July 13th, 2026, the Department of War (DOW) shocked the Defense Industrial Base (DIB) when it announced that CMMC Phase II — the second phase of the planned Cybersecurity Maturity Model Certification (CMMC) roll out that would steer most contracts involving Controlled Unclassified Information (CUI) to require third-party assessment — was suspended effective immediately. This announcement was especially unexpected as it parallels other major CMMC-related and adjacent events, such as the scheduling of an Interim Final Rule for transitioning CMMC Level 2 from NIST SP 800-171 revision 2 to revision 3. Additionally, the introduction of a proposed FAR CUI rule that would require ALL federal contractors, not just DOW, handling CUI to implement NIST SP 800-171 revision 3.

Regardless, here we are. CMMC Phase II has been suspended. Why did this happen? What exactly does this suspension mean, and what requirements, if any, remain? Is CMMC gone? In this blog, we’ll unpack the DOW’s announcement and provide our take on what defense contractors should take away.

What was CMMC Phase II, and why was it suspended?

As written into law within the CMMC Final Rule and as described in our previous post, CMMC was to be “rolled out” in four “phases” over a three-year period of three years. A new DFARS clause, 252.204-7021, was created as the “CMMC clause”, which was to be inserted into contracts and dictate which Level (1, 2, or 3) and Assessment Type (Self or third-party, aka C3PAO) was required for a particular contract. 

Phase I kicked off November 10th, 2025, and directs the government Program Managers (PM) and the tier 1 Prime Contractors to require Self-Assessments for contracts involving CUI.  C3PAO certification assessments weren’t explicitly required during Phase I.  However, both the PMs and Primes reserved the right to require C3PAO assessments, even during Phase 1.  So, it’s important to clarify what was really driving assessment requirements in contracts: the tier 1 Prime contractors. Primes know the effort it takes to acheive CMMC Level 2 certification, so many of them, anticipating Phase II C3PAO assessment requirements, started asking their supply chains to acheive Level 2 C3PAO certification even during Phase I.

During Phase II, then, which was scheduled to begin November 10th, 2026, PMs and Primes would be directed by DOW to require C3PAO assessments for most contracts involving CUI, rather than Self.  Primes are required to flow down the requisite CMMC Level and assessment type, based on the type of information flowed down to the contractor.  The DoW estimated this flowdown would have required about 80,000 contractors to undergo C3PAO assessment and achieve CMMC Level 2 certification.  However, the DoW’s announcement on 13 July suspended Phase II.

See the image below for a graphical depiction of the CMMC timeline, now with the Phase II suspension in effect:

So, the suspension of CMMC Phase II means that we will remain in Phase I. PMs and Primes will continue to be directed to require self-assessments rather than C3PAO. Is it conceivable that PMs and especially Primes, regardless of this announcement, will still choose to require C3PAO certification for a contract involving CUI? Yes, it is, and this will certainly be interesting to watch.

According to the DOW’s announcement, CMMC Phase II was suspended for the following reasons:

  • CMMC has created “prohibitive compliance costs and bureaucratic burdens”
  • Recent reports from the Small Business Administration have confirmed that CMMC is “forcing innovative companies out of the Defense Industrial Base (DIB) which will delay the delivery of critical capabilities to the warfighters”
    • Note: The SBA has also released a commendation of the DOW’s suspension of CMMC Phase II.
  • This decision “ensures we maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain”

You may agree or disagree with the DOW’s analysis. Regardless, in their announcement, the DOW references a “Brilliant at the Basics” campaign, essentially providing a “top 10” list of cybersecurity best practices. While unclear if this is going to be any form of a replacement for CMMC (and more specifically, NIST SP 800-171), the DOW believes that “these foundational core practices help you fortify your enterprise, reduce technical debt, and ensure the secure, rapid delivery of superior technology directly to the warfighter at the tactical edge.” Our opinion is that some of these are great, while others remain confusing (looking at you, #3 and #4…).

What changed?

As discussed above, since we remain in Phase I, PMs and Primes are encouraged to require self-assessments rather than C3PAO certification assessments for the time being. This and the fact that DoW has established a Reform Task Force (RTF, more on this below) to analyze and improve the CMMC model suggests that Phase I will be in effect beyond November 10th, 2026 when Phase II was supposed to begin. 

Additionally, via analysis of the latest DOW CMMC page, it appears that all resources and materials referencing CMMC Level 3 (advanced protections for larger Primes and those working on more sensitive systems) are gone, potentially indicating that Level 3 will be done away with entirely. But we shall see. 

Perhaps a more relevant discussion is what has not changed:

DFARS 252.204-7012 remains, which obligates you to protect CUI via implementation of the NIST SP 800-171 revision 2 standard, in addition to being prepared to report cybersecurity incidents to the DOW. As of now, there are no changes to the underlying NIST 800-171 standard. If you have DFARS 252.204-7012 in your contract, continue to implement NIST 800-171 rev. 2, build your System Security Plan (SSP), and continue your efforts strengthening your organization’s cybersecurity.

DFARS 252.204-7021 remains, which means you can still expect to find this clause in your contract. Since we remain in Phase I, it’s likely that this clause will require you to complete either a CMMC Level 1 or Level 2 self-assessment, rather than a Level 2 C3PAO assessment. You’ll continue to report your self-assessment results and annual affirmations via the Supplier Performance Risk System (SPRS) portal. For Level 2 assessments, you calculate your score using the CMMC Level 2 scoring methodology.

The DOW, via the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), still reserves the right to perform NIST 800-171 assessments of any contractors they choose, both virtually and on-site. So, be prepared to defend your NIST 800-171 implementation to DIBCAC should you be called upon to do so. Do not lie about your implementation by inflating your self-assessment score, as this subjects you to penalties under the False Claims Act.

The obligation and necessity to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) remains. This information is of great interest to our adversaries, and therefore we must protect it. CMMC Phase II being suspended does not negate this need.

What happens next?

The DOW states that they are initiating a 60-day study of “the future of the program”. The announcement states:

"To realign our cybersecurity posture with the principles of the Acquisition Transformation System (ATS), the Department CIO is establishing a CMMC Reform Task Force to conduct a comprehensive top-to-bottom review of the certification program. This task force will serve as the central hub for synthesizing industry feedback from our public Request for Information (RFI) regarding compliance challenges. Using these insights, the team will recommend realistic, scalable security measures that prioritize speed to capability and lower barriers for small and non-traditional businesses, delivering their final report to the DoW CIO within 60 days."

We can only speculate what the outcome of their review will be, and we don’t want to post speculation. However, you can expect news on this front in the next 60-90 days. In the meantime, the CMMC Reform Task Force is sourcing feedback via their Request for Information (RFI). We encourage anyone reading this to submit their feedback while the window remains open. The RFI includes the following questions:

  • Identify the top five most prohibitive cost drivers, administrative burdens, or operational challenges your organization has experienced, or anticipates to experience, when attempting to comply with the CMMC framework and NIST SP 800-171 Rev 2.

  • Which specific security controls has your organization found to deliver the most tangible uplift of cybersecurity and actual risk reduction?

  • Conversely, which specific regulatory requirements or security controls create the highest administrative overhead and financial burden with the least measurable improvement to your actual cybersecurity posture?

  • Describe how your organization utilizes existing commercial cybersecurity capabilities, platforms, managed services, or any other additional strategies or initiatives to safeguard data, improve operational resiliency, and reduce cybersecurity risk, and how the DoW might better recognize or accept these commercial solutions within a compliance or risk framework.

  • Regarding Phase I self-assessments, what specific administrative or technical challenges does your organization face in maintaining, verifying, and reporting compliance, and how could this process be fundamentally streamlined? Have your self-assessments led to a more dynamic cyber posture approach, or are they performed only for compliance purposes?

  • What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically reduce costs and barriers to entry for small, medium, and non-traditional businesses without degrading the protection of federal data?

  • What specific, actionable policy changes or regulatory reforms should the CMMC Reform Task Force recommend over the next 60 days to drastically improve operational resilience against cyber attacks at your organization?

Lastly, a note about current scheduled C3PAO assessments.  If you have a C3PAO assessment scheduled, you may want to reconsider.  If you scheduled the assessment because your customer directed you to acheive CMMC Level 2 certification, you may want to inquire whether or not that direction still stands after the DoW’s suspension of CMMC Phase II.  It may or may not, depending.  

Wrapping up

The decision to suspend CMMC Phase II certainly has resulted in a mix of celebration, coping, and distress. Therefore, it is critical to understand what has changed, what is unclear, and what will happen next. You are welcome to submit any questions to us at [email protected]. Or, if you’d like to ask questions to us live during our monthly Subscriber Q&A Forums, consider becoming a Totem subscriber!

— Nathan

Like this post? Share it!

Get notified when new blogs are published!