CMMC Phase II is Suspended - What This Means for Your Business

Written by Leslie Faircloth | Jul 28, 2026, 4:05:16 PM

 

The Department of War has officially announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II transition, along with all pending implementation milestones previously scheduled for November 10, 2026. This suspension directly aligns with Secretary of War Pete Hegseth's Acquisition Transformation System (ATS) directives, prioritizing "speed to capability" and lowering barriers for small, medium, and non-traditional defense contractors.

According to recent Small Business Administration (SBA) data cited by the Department, the previous CMMC trajectory created prohibitive compliance costs that were forcing innovative companies out of the Defense Industrial Base (DIB), threatening to delay critical capabilities for the warfighter. To chart a new path, DoW Chief Information Officer Kirsten A. Davies has established a CMMC Reform Task Force to conduct a 60-day top-to-bottom review of the program, synthesizing industry feedback to replace heavy bureaucratic hurdles with scalable, resilient security measures.

However, defense contractors must not mistake this pause in third-party certification for a cancellation of their cybersecurity obligations. The Hon. Michael Duffey, Under Secretary of War for Acquisition and Sustainment, made it clear that while the Department is removing "paralyzing costs" to keep competition growing, they are simultaneously maintaining a strict security baseline.

To support this, the DoW CIO has launched the "Brilliant at the Basics" campaign, which is designed to help DIB partners focus on tangible cyber hygiene rather than administrative overhead. This initiative guides defense contractors to fortify their enterprises by implementing high-impact, practical defense measures—such as phishing-resistant Multi-Factor Authentication (MFA), risk-based vulnerability management, strict network segmentation, and validated asset inventories across both IT and Operational Technology (OT) environments.

While the certification timeline has shifted, your contractual responsibilities have not. As emphasized by the Office of the Under Secretary of War for Acquisition & Sustainment and the Project Spectrum Team, the suspension does not eliminate the overarching requirement to protect federal data.

All Phase I requirements—including Level 1 and Level 2 self-assessments—remain firmly in place. If your organization processes, stores, or transmits Controlled Unclassified Information (CUI), you are still contractually obligated to safeguard it in accordance with DFARS clause 252.204-7012 and the security controls outlined in NIST SP 800-171 Revision 2.

STRATEGIC ACTION PLAN FOR YOUR BUSINESS

Periods of regulatory change often create market confusion, but your operational response must remain focused. I advise taking the following steps immediately to ensure your readiness is not compromised:

  • Maintain and Improve Your SPRS Score: Your Supplier Performance Risk System (SPRS) score still matters. SPRS remains the Department's system for documenting NIST SP 800-171 self-assessments, and contracting officials will continue using this information for acquisition and supplier risk management. Keep your self-assessments and required affirmations current.
  • Prepare for Prime Contractor Scrutiny: Prime contractors remain responsible for managing cybersecurity risk throughout their supply chains and have not paused their own expectations. Subcontractors should expect primes to continue asking about NIST SP 800-171 implementation, system security plans, and overall cybersecurity readiness. Waiting for additional government guidance may not align with the immediate expectations of your customers.
  • Leverage Free Cyber Resources: If you lack a dedicated compliance team, consider utilizing Project Spectrum. Project Spectrum is explicitly postured by the Office of Industrial Base Growth to support these changes, offering no-cost cybersecurity education, self-assessments, policy documentation tools, templates, and advisory resources specifically designed for defense contractors.

Credits & Further Reading: This update incorporates official announcements from the Department of War and OSD Acquisition & Sustainment, alongside expert compliance analysis from The Project Spectrum Team and the DoW CIO.