DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on • Originally published at cyber.netsecops.io

DOD Suspends CMMC 2.0 Phase II Implementation

Originally published on CyberNetSec.

Executive Summary

The U.S. Department of Defense (DOD) has announced a significant change to its cybersecurity compliance program, suspending the implementation of Phase II of the Cybersecurity Maturity Model Certification (CMMC) 2.0. This phase, which was set to begin on November 10, 2026, would have required defense contractors handling Controlled Unclassified Information (CUI) to undergo mandatory third-party assessments. While this pause provides temporary relief from third-party audit requirements, the DOD emphasized that all existing cybersecurity obligations for contractors remain in force. The department has also issued a Request for Information (RFI) to gather industry input for a future reformed version of the program.

Regulatory Details

The CMMC 2.0 program is structured in phases. The now-suspended Phase II would have mandated that contracts involving CUI require an assessment by a CMMC Third-Party Assessor Organization (C3PAO).

However, Phase I requirements, which are already in effect, are not impacted by this decision. This means DOD procuring activities must continue to include:

  • CMMC Level 1 (Foundational): For contractors handling Federal Contract Information (FCI).
  • CMMC Level 2 (Self-Assessment): For some contracts involving CUI.

Crucially, the suspension does not alter the fundamental requirements of the DFARS 252.204-7012 clause, which obligates contractors to safeguard CUI by implementing the 110 security controls outlined in NIST SP 800-171.

Affected Organizations

This policy change directly affects all organizations within the Defense Industrial Base (DIB), which includes hundreds of thousands of contractors and subcontractors that do business with the DOD. This ranges from large prime contractors to small businesses.

Compliance Requirements

Despite the pause on Phase II, DIB contractors must continue to:

  1. Implement the security controls in NIST SP 800-171 to protect CUI.
  2. Conduct self-assessments of their NIST SP 800-171 implementation.
  3. Report the results of their self-assessment to the DOD's Supplier Performance Risk System (SPRS).
  4. Maintain compliance with all other cybersecurity clauses in their contracts, such as incident reporting.

Implementation Timeline

  • July 13, 2026: The DOD announces the suspension of CMMC 2.0 Phase II.
  • August 14, 2026: Deadline for industry stakeholders to submit responses to the DOD's RFI for CMMC reform.
  • November 10, 2026: The original date Phase II was scheduled to take effect.

Impact Assessment

The immediate impact for the DIB is the removal of the near-term requirement and cost associated with scheduling and undergoing a C3PAO assessment. This provides breathing room, especially for small and medium-sized businesses. However, it also introduces uncertainty about the future of CMMC and what the reformed program will look like. Contractors should not interpret this pause as a relaxation of cybersecurity standards, as the underlying NIST 800-171 requirements are still contractually binding and are being mirrored in proposed government-wide regulations (FAR rule).

Enforcement & Penalties

While the specific enforcement mechanism of C3PAO audits is paused, the DOD can still enforce compliance through other means, such as contract audits, False Claims Act cases for misrepresentation of security posture, and withholding of contract awards.

Compliance Guidance

Defense contractors should:

  1. Maintain Momentum: Do not halt efforts to implement and maintain compliance with NIST SP 800-171. The requirements are not going away.
  2. Participate in the RFI: Consider providing feedback to the DOD's RFI to help shape a more practical and effective future CMMC program.
  3. Document Everything: Continue to thoroughly document your implementation of NIST 800-171 controls in a System Security Plan (SSP) and maintain a Plan of Action & Milestones (POA&M) for any gaps.
  4. Monitor for Updates: Stay informed on both the CMMC reform process and the proposed FAR rule for CUI, as it will likely impose similar requirements across all federal contracting.

Top comments (0)