The Department of War has officially announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II transition, along with all pending implementation milestones previously scheduled for November 10, 2026. This suspension directly aligns with Secretary of War Pete Hegseth's Acquisition Transformation System (ATS) directives, prioritizing "speed to capability" and lowering barriers for small, medium, and non-traditional defense contractors.
According to recent Small Business Administration (SBA) data cited by the Department, the previous CMMC trajectory created prohibitive compliance costs that were forcing innovative companies out of the Defense Industrial Base (DIB), threatening to delay critical capabilities for the warfighter. To chart a new path, DoW Chief Information Officer Kirsten A. Davies has established a CMMC Reform Task Force to conduct a 60-day top-to-bottom review of the program, synthesizing industry feedback to replace heavy bureaucratic hurdles with scalable, resilient security measures.
However, defense contractors must not mistake this pause in third-party certification for a cancellation of their cybersecurity obligations. The Hon. Michael Duffey, Under Secretary of War for Acquisition and Sustainment, made it clear that while the Department is removing "paralyzing costs" to keep competition growing, they are simultaneously maintaining a strict security baseline.
To support this, the DoW CIO has launched the "Brilliant at the Basics" campaign, which is designed to help DIB partners focus on tangible cyber hygiene rather than administrative overhead. This initiative guides defense contractors to fortify their enterprises by implementing high-impact, practical defense measures—such as phishing-resistant Multi-Factor Authentication (MFA), risk-based vulnerability management, strict network segmentation, and validated asset inventories across both IT and Operational Technology (OT) environments.
While the certification timeline has shifted, your contractual responsibilities have not. As emphasized by the Office of the Under Secretary of War for Acquisition & Sustainment and the Project Spectrum Team, the suspension does not eliminate the overarching requirement to protect federal data.
All Phase I requirements—including Level 1 and Level 2 self-assessments—remain firmly in place. If your organization processes, stores, or transmits Controlled Unclassified Information (CUI), you are still contractually obligated to safeguard it in accordance with DFARS clause 252.204-7012 and the security controls outlined in NIST SP 800-171 Revision 2.
Periods of regulatory change often create market confusion, but your operational response must remain focused. I advise taking the following steps immediately to ensure your readiness is not compromised:
Credits & Further Reading: This update incorporates official announcements from the Department of War and OSD Acquisition & Sustainment, alongside expert compliance analysis from The Project Spectrum Team and the DoW CIO.