What the DoW’s CMMC Phase II Announcement Means for Defense Contractors
The Department of War’s announcement pausing the planned rollout of CMMC Phase II has sparked questions across the Defense Industrial Base.
On July 13, 2026, the Department of War (DoW) announced a significant change to the implementation of the Cybersecurity Maturity Model Certification (CMMC) program.
The Department has suspended the planned transition to CMMC Phase II, which was scheduled to begin on November 10, 2026, and has opened a 60-day review of the program led by a newly established CMMC Reform Task Force, whose recommendations are expected on or around September 13. As part of that review, the Department also issued a Request for Information (RFI), inviting industry stakeholders to provide feedback on the future of CMMC.
For defense contractors across the Defense Industrial Base (DIB), the announcement raises an important question:
Does this change your cybersecurity obligations?
The short answer is no.
While the certification timeline is changing, the underlying cybersecurity requirements remain firmly in place.
What Changed?
The most significant change is that the DoW is not moving forward with the planned Phase II rollout at this time.
Under the original implementation plan, Phase II would have begun phasing CMMC Level 2 certification assessments, performed by authorized third-party assessment organizations (C3PAOs), into applicable solicitations beginning November 10, 2026.
Instead, the Department will continue accepting Level 2 self-assessments, supported by annual affirmations of continued compliance, while it reevaluates the program. This effectively delays the mandatory shift to third-party certification.
Although the Department stated that it will amend active solicitations containing a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, the broader CMMC ecosystem remains fully operational. C3PAO Level 2 certification assessments are still available, and organizations with assessments scheduled or underway can continue on that path.
The Department’s review is intended to gather industry feedback and evaluate how CMMC can continue strengthening cybersecurity while reducing unnecessary barriers for small businesses and new entrants to the defense supply chain.
What Hasn’t Changed
Although the implementation timeline is evolving, the Department’s expectations around protecting sensitive defense information have not.
Several foundational requirements remain unchanged:
- Controlled Unclassified Information (CUI) must continue to be protected. Contractors remain responsible for safeguarding CUI in accordance with DFARS 252.204-7012, which the DoW has expressly confirmed remain in effect.
- NIST SP 800-171 Rev. 2 remains the cybersecurity standard. Organizations are still expected to implement the required security controls and validate compliance through self-assessments where applicable. The Department has stated it will continue enforcing this standard through self-assessments and select government-led assessments during the review period.
- Current Phase I requirements remain in effect. For contracts including CMMC Level 2 requirements, this includes maintaining a current self-assessment score in the Supplier Performance Risk System (SPRS) and submitting annual affirmations of continued compliance, which remain signed attestations that the required security controls are in place. Organizations must continue meeting any assessment obligations specified within their contracts.
- Other contractual data protection requirements continue to apply. FAR 52-204-21 basic safeguarding for, FedRAMP Moderate (or equivalent) for CUI in the cloud, and export control obligations under ITAR and EAR are unaffected by the announcement.
In other words, while the certification timeline is being reconsidered, the security expectations are not.
Why the Department Made This Call
The DoW has been direct about its reasoning. The suspension supports Secretary Hegseth’s Acquisition Transformation Strategy directives: speed to capability, lower barriers for small and non-traditional businesses, and a commercial-first approach. The Department’s press release points to SBA data suggesting compliance was pushing companies out of the defense supply chain, and a mismatch between the number of organizations ultimately needing third-party assessment and the current number of assessors. The Department was equally clear that the pause is not a retreat from security or the requirement to implement NIST SP 800-171 to protect CUI.
That rationale deserves a fair reading, alongside some on-the-ground context from the field:
- Most of the cost of compliance is in implementing the security requirements, not certification. The bulk of the expense attributed to CMMC is implementing NIST SP 800-171 itself, an obligation under DFARS 252.204-7012 that predates CMMC and is untouched by this pause.
- The assessor capacity data may be dated. Assessor capacity has grown steadily, assessment pricing is trending down, and scheduling an assessment is rarely the constraint today.
- The real bottleneck is contractor readiness. Many organizations have not yet fully implemented the underlying requirements, a gap that will remain no matter what the Task Force recommends.
It is also fair to acknowledge the seat the Department is in: a new leadership team is executing acquisition reform priorities, revisiting trade-offs that earlier reviews and multiple rounds of rulemaking had already worked through. For contractors who deferred implementation and were running out of runway, this pause is best read as a reprieve, not a recission, and the smart use of it is to close the gap.
What This Means for Defense Contractors
First, an acknowledgment: many organizations have committed years and real budget implementing the security requirements and building a cybersecurity program that can withstand the scrutiny of a third-party assessment. Watching another administrative change occur is frustrating. That work has not lost its value. The security posture you built is durable, it protects your business today, meets your contractual obligations, and it positions you well under any verification model that emerges from the Department’s review.
Announcements like this can create uncertainty, but they should not change the direction of your cybersecurity strategy.
Pausing or unwinding security investments now would surrender momentum that is expensive to rebuild. This is an opportunity to continue building a mature cybersecurity program that aligns with long-term Department expectations.
Key priorities include:
Continue implementing NIST SP 800-171
Whether future verification involves self-assessments, third-party assessments, or a revised model, the underlying security controls remain the same. Progress made today will continue to deliver value regardless of how compliance is ultimately verified.
Stay aligned with your customers
Prime contractors and government customers set their own cybersecurity expectations, and several major primes have been requiring CMMC Level 2 from their supply chains independent of the DoW’s schedule. Nothing in the suspension changes what a prime may require before sharing CUI with a supplier. Regular communication helps ensure your organization continues meeting contractual expectations.
Participate in the RFI process
The Department has invited industry feedback through its Request for Information. Organizations with perspectives on implementation, assessment requirements, or barriers to compliance have an opportunity to help shape the future of CMMC before the August 14 submission deadline. The most useful submissions will be substantive: actual implementation costs, firsthand experience with assessor availability, and which controls delivered meaningful risk reduction versus administrative overhead.
A Strong Security Foundation Still Matters
The Department’s announcement reinforces an important point: protecting the Defense Industrial Base remains a national security priority.
Organizations that continue strengthening their cybersecurity programs today will be better positioned regardless of how future certification requirements develop.
For many contractors, the most effective strategy is to focus less on the timing of assessments and more on building a sustainable cybersecurity program that supports both compliance and operational resilience.
Looking Ahead
As the Department reviews the CMMC program over the coming months, defense contractors should continue focusing on protecting CUI, implementing NIST SP 800-171, and maintaining close communication with customers and prime contractors.
The implementation timeline may evolve, but the mission remains the same: protecting sensitive defense information and strengthening the cybersecurity of the Defense Industrial Base.
If you are unsure what this announcement means for your specific situation, our team is happy to talk it through. We are tracking the Task Force’s review closely and will share guidance as new details emerge.