Originally published on CyberNetSec.
Executive Summary
The U.S. Department of War (DOW) has announced an immediate suspension of the planned rollout of Phase II of its Cybersecurity Maturity Model Certification (CMMC) program. The decision, detailed in memoranda from July 2026, pauses a significant and costly requirement that was set to take effect on November 10, 2026. Phase II would have mandated that defense contractors handling Controlled Unclassified Information (CUI) undergo and pass a cybersecurity assessment from an independent CMMC Third Party Assessor Organization (C3PAO). The DOW has now formed a CMMC Reform Task Force to re-evaluate the program's structure and impact, particularly on small businesses, and is actively seeking industry feedback.
Regulatory Details
The CMMC program was designed to enforce cybersecurity standards across the Defense Industrial Base (DIB).
- Phase I (Remains in Effect): Requires all defense contractors to conduct annual self-assessments of their cybersecurity posture based on NIST SP 800-171 standards and report their scores to the DOW.
- Phase II (Suspended): Was intended to be the next major step, requiring contractors that handle the more sensitive CUI to validate their self-assessment scores through a formal, independent audit by a C3PAO. Passing this audit would have become a prerequisite for winning or maintaining contracts.
The suspension of Phase II signals a significant strategic pivot by the DOW, acknowledging widespread concerns from the industry about the cost, complexity, and availability of C3PAO assessors.
Affected Organizations
The suspension directly impacts several key groups:
- Defense Contractors: Thousands of companies in the defense supply chain, especially small and medium-sized businesses, are granted a temporary reprieve from the financial and logistical burden of preparing for and undergoing mandatory third-party audits.
- CMMC Third Party Assessor Organizations (C3PAOs): The ecosystem of accredited assessors now faces uncertainty regarding the demand for their services and the future timeline for mandatory audits.
- Department of War (DOW): The department is undertaking a significant review that could lead to substantial changes in how it enforces cybersecurity compliance within its supply chain.
Compliance Requirements
With the suspension of Phase II, the current compliance landscape is as follows:
- Phase I requirements are still in full effect. All contractors must continue to perform annual self-assessments against NIST SP 800-171 and report their scores.
- The mandatory C3PAO audits for CUI are on hold indefinitely.
- Contracting officers have been issued guidance on amending active solicitations and existing contracts that may have included language about the upcoming Phase II requirements.
Implementation Timeline
- Suspension Date: The suspension was made effective immediately upon the release of the DOW memoranda in mid-July 2026.
- RFI Deadline: The CMMC Reform Task Force has issued a Request for Information (RFI) to solicit industry feedback. Responses are due by August 14, 2026.
The timeline for any potential new version of the CMMC program is currently unknown and will depend on the findings of the task force.
Impact Assessment
This suspension has several key implications:
- Financial Relief: It provides immediate financial relief for contractors who were facing significant costs associated with audit preparation and execution.
- Reduced Barriers: It temporarily lowers the barrier to entry for small and non-traditional businesses that may have been unable to afford the CMMC certification process.
- Program Uncertainty: It creates significant uncertainty about the future of the CMMC program. The DOW's review could lead to a complete overhaul, a more streamlined version, or a different approach to cybersecurity validation altogether.
- Potential Security Gaps: While providing relief, the delay in mandatory verification could also mean that security gaps within the DIB may persist for longer than originally planned.
Enforcement & Penalties
The immediate threat of losing contract eligibility for failing a C3PAO audit is now removed. However, contractors are still required to comply with Phase I and other existing cybersecurity clauses in their contracts (e.g., DFARS 252.204-7012). Failure to do so can still result in contractual penalties or negative performance reviews.
Compliance Guidance
Defense contractors should take the following actions in light of the suspension:
- Continue NIST 800-171 Implementation: Do not halt cybersecurity improvement efforts. The underlying requirement to protect CUI and implement the 110 controls in NIST SP 800-171 has not changed.
- Participate in the RFI: Companies in the DIB should consider providing feedback to the DOW's CMMC Reform Task Force via the RFI. This is a critical opportunity to shape the future of the program.
- Monitor for Updates: Stay informed about announcements from the DOW regarding the CMMC program. The suspension is temporary, and a new or revised set of requirements will eventually emerge.
- Focus on Foundational Security: Use this time to mature cybersecurity practices without the immediate pressure of a third-party audit. Focus on areas like access control, incident response, and vulnerability management.
Top comments (0)