DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on • Originally published at cyber.netsecops.io

DoD Suspends CMMC Phase II Requirements

Originally published on CyberNetSec.

Executive Summary

In a surprising move, the U.S. Department of Defense (DoD) has suspended the implementation of Phase II of its Cybersecurity Maturity Model Certification (CMMC) program. The transition, which would have mandated more stringent cybersecurity requirements and third-party assessments for many defense contractors, was set to begin on November 10, 2026. The DoD has launched a 60-day study to reassess the program's path forward. It is critical for defense contractors to understand that this is not a reprieve from all cybersecurity obligations; existing requirements under DFARS clause 252.204-7012 and CMMC Phase I remain fully in effect.

Regulatory Details

The CMMC program is designed to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) within the Defense Industrial Base (DIB). CMMC Phase II was set to significantly raise the bar by requiring many contractors to undergo third-party assessments by accredited CMMC Third-Party Assessor Organizations (C3PAOs) to verify their cybersecurity posture.

The suspension puts this escalation on hold. However, the DoD has been clear that the foundational requirements are unchanged:

  • DFARS Clause 252.204-7012: This clause, present in most DoD contracts, requires contractors to provide 'adequate security' for covered defense information, which is defined as implementing the security controls in NIST SP 800-171.
  • CMMC Phase I: This initial phase requires all DIB members to conduct a self-assessment of their NIST SP 800-171 implementation and report their score to the DoD's Supplier Performance Risk System (SPRS).

Affected Organizations

This policy change directly affects the entire Defense Industrial Base (DIB), which comprises tens of thousands of companies, from large prime contractors to small businesses, that are part of the DoD supply chain. Companies that have invested significant time and resources in preparing for CMMC Phase II third-party assessments now face a period of uncertainty.

Compliance Requirements

Despite the suspension of Phase II, the following compliance requirements remain mandatory for defense contractors handling CUI:

  1. Implement NIST SP 800-171: Contractors must implement the 110 security controls outlined in NIST Special Publication 800-171.
  2. System Security Plan (SSP): Maintain a detailed SSP that describes how the NIST SP 800-171 controls are implemented.
  3. Plan of Action & Milestones (POA&M): For any controls not yet implemented, a POA&M must be created to document the plan and timeline for remediation.
  4. SPRS Score Submission: Conduct a self-assessment against the NIST SP 800-171 framework and submit the resulting score to the DoD's Supplier Performance Risk System (SPRS).

Implementation Timeline

  • Original CMMC Phase II Start Date: November 10, 2026 (Now Suspended)
  • New Timeline: A 60-day study has been initiated to determine the future of the CMMC program. The outcome of this study will dictate any new timelines or changes to the program structure.

Impact Assessment

The suspension introduces significant strategic and financial uncertainty for the DIB. Many companies have made substantial investments in consulting services, new technologies, and personnel to prepare for the anticipated CMMC Level 2 or Level 3 assessments. This pause may cause them to re-evaluate their cybersecurity budgets and project timelines. While the long-term goal of securing the DIB remains, the specific mechanism for verifying compliance is now under review. This could lead to a revised, potentially more streamlined program, or a complete overhaul.

Enforcement & Penalties

While CMMC Phase II assessments are on hold, the DoD can still enforce compliance through other means. The Defense Contract Management Agency (DCMA) has the authority to audit contractors' compliance with DFARS 252.204-7012. Failure to have an accurate SPRS score or a credible SSP and POA&M could result in contract termination, negative past performance reviews, or liability under the False Claims Act.

Compliance Guidance

DIB contractors should not interpret this suspension as a signal to halt their cybersecurity efforts. The most prudent course of action is to:

  1. Stay the Course on NIST SP 800-171: Continue to focus on fully implementing all 110 controls from NIST SP 800-171. This remains the foundational requirement and will be central to any future iteration of CMMC.
  2. Maintain Documentation: Ensure the System Security Plan (SSP) is accurate, detailed, and up-to-date. Keep the Plan of Action & Milestones (POA&M) current with realistic remediation dates.
  3. Verify SPRS Score: Re-validate the self-assessment score submitted to SPRS to ensure it accurately reflects the current security posture.
  4. Monitor for Updates: Closely follow announcements from the DoD regarding the outcome of the 60-day study to be prepared for the future direction of the CMMC program.

Top comments (0)