On July 13, 2026, the Department of War announced that it was suspending the upcoming Phase 2 requirements of the Cybersecurity Maturity Model Certification program, commonly called CMMC.
This announcement does not eliminate CMMC. It does not eliminate cybersecurity requirements for defense contractors. It primarily pauses the expansion of mandatory third-party CMMC Level 2 certifications while the Department reviews and potentially restructures the program.
The simplest explanation is: Companies may no longer need a third-party CMMC Level 2 certification during the suspension, but companies handling Controlled Unclassified Information must still implement the required security controls and complete the applicable self-assessment.
What Exactly Was Suspended?
The Department suspended the transition to CMMC Phase 2, which had been scheduled to begin November 10, 2026. During Phase 2, an increasing number of contracts involving Controlled Unclassified Information, or CUI, were expected to require a formal CMMC Level 2 assessment performed by an authorized Certified Third-Party Assessment Organization, known as a C3PAO.
During the suspension:
- Contracting programs may not designate CMMC Level 2 C3PAO certification requirements.
- Contracting programs may not designate CMMC Level 3 DIBCAC assessment requirements.
- The permitted CMMC requirements are currently Level 1 self-assessment and Level 2 self-assessment.
- Existing solicitations containing Level 2 C3PAO or Level 3 requirements are expected to be amended.
- Existing contracts containing these requirements are expected to be modified before the next option period or scheduled administrative modification.
The Department has also paused future CMMC implementation milestones while it conducts a comprehensive review.
Does This Mean CMMC Level 2 Compliance Is No Longer Required?
No. There is an important difference between being compliant and being certified.
CMMC Level 2 compliance
Level 2 is based on the security requirements in NIST Special Publication 800-171 Revision 2. These requirements address areas such as:
- Multifactor authentication
- Access control
- Security monitoring
- Incident response
- System configuration
- Vulnerability management
- Employee security practices
- Protection of Controlled Unclassified Information
Organizations that handle CUI are still expected to protect it according to the applicable contract requirements, including DFARS 252.204-7012.
CMMC Level 2 certification
Certification means that a C3PAO examines the organization and independently verifies that the requirements have been implemented. The current suspension removes the Level 2 C3PAO assessment requirement from Department solicitations and contracts during the review period. It does not remove the underlying security obligations. The Department’s implementation instructions specifically state that DFARS 252.204-7012 remains in effect and that baseline NIST SP 800-171 compliance will continue to be enforced through Level 2 self-assessments and selected government-led assessments.
Do Companies Still Have to Self-Assess?
Yes. The Department clearly stated that all Phase 1 self-assessment requirements remain in place. During the suspension, contracts may require:
CMMC Level 1 Self-Assessment
This generally applies when a contractor handles Federal Contract Information, or FCI, but does not handle CUI. Level 1 is based on the basic safeguarding requirements in FAR 52.204-21.
CMMC Level 2 Self-Assessment
This may apply when a contractor handles CUI. Level 2 self-assessment is aligned with the 110 security requirements in NIST SP 800-171 Revision 2. The organization must assess its environment using the required assessment methodology and submit the results in the Supplier Performance Risk System, known as SPRS.
The Level 2 self-assessment rules also require:
- A defined CMMC assessment scope
- A documented assessment score
- Submission of results into SPRS
- A new assessment at least every three years
- Annual affirmation of continued compliance
- Completion of eligible Plans of Action and Milestones within 180 days
The Department also retains the authority to conduct a government assessment. If a DCMA DIBCAC assessment finds that the organization’s self-reported status is inaccurate, the government’s findings take precedence.
Is CMMC Enforcement Completely Paused?
No. The third-party certification expansion is paused. The cybersecurity baseline is not.
Contractors must still pay attention to:
- FAR 52.204-21 requirements for protecting FCI
- DFARS 252.204-7012 requirements for protecting CUI
- NIST SP 800-171 implementation
- Cyber incident reporting requirements
- SPRS assessment requirements
- Contract-specific security clauses
- Flow-down requirements for subcontractors
- Annual compliance affirmations
- Government assessments and investigations
The Department’s memorandum states that all other contractual cybersecurity clauses remain intact.
What Should Contractors Do Now?
Organizations should not stop their compliance work. A reasonable approach is to continue building and maintaining the same security foundation that would support a successful Level 2 certification.
1. Determine whether you handle FCI or CUI
Do not assume that every defense contractor has the same requirement.
Review:
- Your contracts
- Your subcontracts
- Statements of work
- Security classification guides
- Data received from prime contractors
- DFARS and FAR clauses
- Customer instructions concerning CUI
The information you receive and process determines whether Level 1 or Level 2 applies.
2. Review your current SPRS score
Organizations handling CUI should confirm that their NIST SP 800-171 assessment is current, accurate, properly scoped, and submitted in SPRS. A score entered several years ago may no longer accurately describe the environment.
3. Do not exaggerate your compliance
A self-assessment is still a formal representation to the federal government. The assessment should reflect the organization’s actual implementation, not its future plans or the security features it has merely purchased. A tool, license, policy template, or managed service does not automatically mean a security requirement has been met.
4. Maintain an accurate System Security Plan
The System Security Plan, or SSP, should explain:
- Where CUI is stored
- How CUI moves through the organization
- Which systems are included in scope
- Which security controls have been implemented
- Which external providers support the environment
- How responsibilities are divided between the organization and its providers
5. Continue addressing open security gaps
Organizations should continue working through legitimate Plans of Action and Milestones. The pause should be used as additional preparation time, not as permission to delay necessary security improvements.
6. Review subcontractors and service providers
CUI protection does not stop with the prime contractor. Review whether subcontractors, cloud providers, managed service providers, consultants, and other external organizations can access or support systems containing CUI. Cloud services used to process, store, or transmit CUI may need to meet FedRAMP Moderate authorization or equivalency requirements. External service-provider responsibilities must also be properly documented and included within the appropriate assessment scope.
7. Continue preserving evidence
Maintain evidence showing that security practices are operating effectively.
Examples may include:
- Access reviews
- Security logs
- Vulnerability remediation records
- Incident response exercises
- Employee training records
- Configuration standards
- Risk assessments
- Backup testing
- Account termination records
- Multifactor authentication reports
- Security policies and procedures
A future assessor will normally look for evidence that controls are consistently practiced, not merely documented.
Could the Department Reinstate Third-Party Certification?
Yes. The Department described the action as a suspension and announced a review of the program. It did not repeal the CMMC regulations or state that independent verification would never return. The Department established a CMMC Reform Task Force and announced a 60-day review focused on reducing cost, lowering barriers for smaller businesses, improving scalability, and maintaining cybersecurity resilience.
Several outcomes are possible:
- C3PAO certification could return largely unchanged.
- Certification could return for fewer contracts.
- Certification could be limited to higher-risk CUI.
- Requirements could be phased in more slowly.
- Small businesses could receive simplified assessment options.
- More government-led assessments could replace some third-party assessments.
- The existing program could be substantially redesigned.
At this point, no one outside the decision-making process can state with certainty which outcome will occur.
How Likely Is Certification to Return?
It is reasonable to expect that some form of independent verification will eventually return, particularly for organizations handling sensitive or high-risk CUI. That is an informed assessment, not an official prediction. The government has repeatedly expressed concern that organizations may claim compliance without fully implementing NIST SP 800-171. CMMC was created largely to add verification to requirements that contractors were already expected to follow. The current announcement criticizes the cost and structure of the program, but it also emphasizes that strong cybersecurity and operational resilience remain critical.
Our practical assessment is:
- A complete permanent elimination of cybersecurity assessments appears unlikely.
- A redesigned, narrower, or risk-based certification program appears more plausible.
- Level 2 C3PAO requirements could be reinstated after the review, but possibly with a new timetable or modified structure.
- Organizations that continue preparing will be in a much stronger position than organizations that stop their compliance work.
What Happens to Companies That Are Already CMMC Level 2 Certified?
An existing certification still provides value. It demonstrates that the organization completed an independent assessment under the current framework. It may also provide a competitive advantage when working with prime contractors or customers that continue to prefer independently validated suppliers.
However, organizations should monitor future Department guidance concerning:
- The continued recognition of existing certifications
- Expiration dates
- Annual affirmations
- Contract eligibility
- Possible transition rules
- Changes to assessment standards
The suspension announcement does not automatically invalidate previously issued certifications.
What Should Prime Contractors Be Mindful Of?
Prime contractors should not tell subcontractors that CMMC or NIST SP 800-171 no longer applies.
Prime contractors should instead:
- Review each contract’s actual clauses
- Identify where CUI is shared
- Apply appropriate cybersecurity requirements to subcontractors
- Avoid unnecessarily labeling ordinary information as CUI
- Communicate clearly whether Level 1 or Level 2 self-assessment is required
- Monitor contract modifications and solicitation amendments
- Avoid imposing outdated third-party certification requirements without confirming the contractual basis
The pause may reduce immediate assessment costs, but it does not remove responsibility for protecting government information throughout the supply chain.
The Bottom Line
The July 2026 announcement is a pause in the expansion of mandatory third-party certification, not the end of CMMC and not the end of defense-contractor cybersecurity compliance.
Organizations handling FCI or CUI should continue to:
- Follow their contractual security requirements
- Maintain their required controls
- Complete applicable CMMC self-assessments
- Submit accurate information to SPRS
- Provide required annual affirmations
- Maintain their SSP and supporting evidence
- Correct known security weaknesses
- Monitor future Department guidance
Stopping compliance work now could create contractual risk, cybersecurity risk, and a costly rush if independent certification requirements are reinstated. The safest approach is to remain compliant and assessment-ready while avoiding unnecessary spending that depends solely on the suspended November 2026 certification deadline.
Official References
- Department of War announcement suspending CMMC Phase 2 requirements.
- Department implementation procedures for the CMMC Phase 2 suspension.
- Department CIO CMMC information and reform resources.
- CMMC Level 2 self-assessment and affirmation requirements in 32 CFR 170.16.
- Final DFARS CMMC acquisition rule.
- Department Office of Small Business Programs CMMC update.
This article is provided for general educational purposes and is not legal advice. Contract requirements may vary. Contractors should review their specific contracts, solicitations, data flows, and legal obligations before making compliance decisions.



