CMMCDocsCMMCDocs.com

Home / Blog / CMMC Phase II Suspended: DoD Launches 60-Day Reform Review

CMMC Phase II Suspended: DoD Launches 60-Day Reform Review

On July 15, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026. Secretary Hegseth cited prohibitive compliance costs and bureaucratic burdens as the primary drivers, aligning the suspension with broader acquisition streamlining initiatives. The announcement has sent shockwaves through the defense industrial base, and the implications for contractors who have invested heavily in compliance are significant.

What Happened

The DoW's announcement suspends the Phase II mandate that would have required CMMC Level 2 third-party assessments by C3PAOs as a condition of contract award for all solicitations involving Controlled Unclassified Information. Phase II was the critical milestone that would have moved CMMC from self-assessment to independent verification across the full defense supply chain.

In place of the Phase II rollout, the DoW's Chief Information Officer is establishing a CMMC Reform Task Force. This task force will conduct a comprehensive top-to-bottom review of the certification program, synthesizing industry feedback obtained through a public Request for Information. The task force must deliver its final report by mid-September 2026.

What Remains in Force

This is the critical point that every contractor must understand: the suspension applies to Phase II requirements only. The following obligations remain fully in effect:

DFARS 252.204-7012 — the clause requiring NIST SP 800-171 implementation and 72-hour cyber incident reporting — is unchanged. This has been a contractual requirement since 2017 and is not part of the CMMC rulemaking.

CMMC Phase I self-assessments remain in place. Contractors must continue to maintain current SPRS scores and annual affirmations. The Phase I self-assessment requirements from the CMMC final rule (32 CFR Part 170) are not affected by the Phase II suspension.

Existing CMMC Level 2 certifications remain valid. Contractors who have already completed C3PAO assessments retain their certifications.

The Request for Information

The DoW has published an RFI to solicit industry input on the future of CMMC. Comments are due by 12:00 PM ET on Friday, August 14, 2026. The RFI asks for feedback on compliance cost burden, assessment methodology effectiveness, the impact on small businesses, and recommendations for streamlining the program while maintaining cybersecurity standards.

Defense contractors, industry associations, C3PAOs, and other stakeholders should consider submitting comments. This is a genuine opportunity to shape the program's future — the task force is specifically charged with synthesizing this feedback into its recommendations.

What This Does Not Mean

The suspension does not mean cybersecurity requirements are going away. CUI protection obligations under DFARS 7012 predate CMMC and will survive regardless of what happens to the certification program. The DoD's adversaries are not pausing their targeting of the defense supply chain. The underlying security problem that CMMC was created to solve — contractors misrepresenting their cybersecurity posture — has not disappeared.

It also does not mean that CMMC is dead. The 60-day review is a reform effort, not a repeal. The most likely outcomes are a revised implementation timeline, modified assessment requirements (potentially reducing costs or complexity), or a restructured phased rollout. A complete elimination of independent verification would require a separate rulemaking process and would face significant opposition from both the cybersecurity community and the DoD's own acquisition leadership.

Impact on C3PAOs and the Assessment Ecosystem

The suspension creates immediate uncertainty for C3PAOs that have invested in building assessment teams and capacity. Organizations that hired assessors, built processes, and turned down other work to prepare for Phase II assessment demand are now facing a revenue gap. Some may reduce capacity or pivot to other assessment frameworks. If CMMC Phase II is ultimately reinstated with modifications, rebuilding that capacity will take time.

What Contractors Should Do Now

Do not stop your compliance program. DFARS 7012 compliance is still required. Your SPRS score and SSP are still obligations. If you are in the middle of remediation work, continue — the underlying security requirements have not changed, and when CMMC (or its successor) resumes, you will be ahead of competitors who paused.

Do not cancel scheduled assessments without careful consideration. If you have a C3PAO assessment scheduled and are near-ready, completing it may still be advantageous. A current CMMC Level 2 certification is a competitive differentiator, and prime contractors are still asking subcontractors about their compliance posture. However, if you were planning to rush an assessment solely to meet a Phase II deadline that no longer exists, you now have time to prepare more thoroughly.

Submit comments to the RFI. If you have views on CMMC's cost, complexity, or effectiveness, this is the time to share them. The August 14 deadline is firm.

Monitor the task force output. The mid-September report will shape the program's future direction. Pay attention to official DoD channels, not industry speculation. CMMCDocs will publish analysis of the task force recommendations as soon as they are released.

The Bigger Picture

CMMC has always been a response to a real problem: defense contractors losing sensitive information because cybersecurity requirements were not being verified. The 60-day review is an opportunity to address legitimate concerns about cost and complexity without abandoning the goal of verified security across the defense supply chain. The contractors who continue building genuine security programs — not paper compliance, but real controls that protect real data — will be well-positioned regardless of what the reformed program looks like.

We will continue to track this closely and will publish updates as the reform process unfolds. In the meantime, keep building. The threat has not taken a 60-day pause.

CMMC 2.0Phase 2SuspensionReformDoD

Take the next step toward CMMC compliance

CMMCDocs has all 110 NIST SP 800-171 Rev 2 requirements built in with templates, evidence mapping, and a POA&M tracker. Spin up a free demo workspace.

Get my demo account