CMMC Phase II Is Suspended: What Defense Contractors Should Do Now

On July 13, 2026, the Department of War announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. The transition had been scheduled to begin on November 10, 2026.

The announcement may provide temporary relief for some organizations that were preparing for third-party assessments. However, it does not eliminate the cybersecurity responsibilities of defense contractors and subcontractors.

Phase I self-assessment requirements remain in effect. Contractors that handle Controlled Unclassified Information (CUI) must also continue meeting applicable requirements under NIST SP 800-171 and DFARS.

The bottom line is simple: CMMC Phase II is paused, but protecting sensitive government information is not.

What Does the CMMC Phase II Suspension Mean?

Under the original implementation schedule, Phase II would have expanded the use of CMMC Level 2 third-party assessments beginning in November 2026.

The suspension places that transition and other pending CMMC implementation milestones on hold while a newly established CMMC Reform Task Force conducts a comprehensive 60-day review of the program.

During the suspension, Department program managers and requiring activities may include only the following CMMC assessment requirements in procurement documents:

  • CMMC Level 1 self-assessments
  • CMMC Level 2 self-assessments

They may not designate CMMC Level 2 C3PAO assessments or CMMC Level 3 government assessments as procurement requirements during this period. Active solicitations containing these requirements are expected to be amended, and applicable existing contracts are to be modified according to the Department’s implementation guidance.

The review is intended to explore ways to reduce unnecessary compliance costs and barriers while maintaining meaningful cybersecurity protections throughout the defense industrial base.

Is CMMC Cancelled?

No. CMMC has not been cancelled.

The Department has suspended the move into Phase II while it reviews and potentially reforms the program. Phase I remains in place, including applicable Level 1 and Level 2 self-assessment requirements.

The Department also stated that it will continue enforcing baseline compliance with NIST SP 800-171 Revision 2 through contractor self-assessments and selected government-led assessments. Cybersecurity requirements contained in DFARS 252.204-7012 also remain in effect.

Organizations should not interpret the announcement as permission to pause all CMMC and NIST SP 800-171 preparation.

What Requirements Still Apply?

The exact requirements that apply to your organization depend on the contracts you pursue, the clauses they contain and the type of government information your systems handle.

During the suspension:

  • Contractors handling Federal Contract Information may still be required to complete an annual CMMC Level 1 self-assessment and affirmation.
  • Contractors handling Controlled Unclassified Information may still be required to complete a CMMC Level 2 self-assessment every three years, with an annual affirmation.
  • CMMC Level 2 continues to align with the 110 security requirements in NIST SP 800-171 Revision 2.
  • Applicable DFARS cybersecurity and incident-reporting clauses remain in effect.
  • Organizations must be prepared to demonstrate that their documented policies and procedures reflect their actual cybersecurity practices.
  • Contractors should continue maintaining required compliance documentation, evidence and assessment records.

A pause in third-party certification requirements does not reduce the risk of cyberattacks, contractual noncompliance or inaccurate representations about an organization’s security posture.

Should You Continue Preparing for CMMC?

For most defense contractors, yes.

The Phase II suspension gives organizations more time to close gaps, but third-party assessments may still return. Continuing preparation now can strengthen FCI and CUI protections, improve policies and the SSP, organize evidence, support contract eligibility, and reduce the cost of last-minute remediation.

Organizations should also review contracts, solicitations, and prime contractor expectations. Use this period to ensure policies, procedures, responsibilities, and supporting evidence accurately reflect how security controls operate in the actual environment.

How CKSS Can Help

The CMMC Phase II suspension gives organizations additional time to prepare, but it should not be viewed as a reason to pause compliance efforts. CKSS provides a holistic approach that includes

  • Gap Analysis
  • Remediation Support
  • Policy and Procedure Development
  • System Security Plan Updates
  • Evidence Organization
  • Technical Control Implementation
  • Ongoing Compliance Monitoring

This end-to-end support helps organizations address deficiencies, improve their cybersecurity posture, and remain prepared for self-assessments, customer inquiries, government reviews, and future certification requirements.

CKSS also supports clients during the assessment process by serving as an audit liaison, mapping evidence to CMMC requirements, preparing personnel for interviews, and coordinating with assessors. Through partnerships with select C3PAOs, CKSS helps organizations move smoothly from readiness and remediation into an independent third-party assessment when required.

Use this suspension period to strengthen your program, close remaining gaps, and prepare with confidence.

Turn the CMMC pause into preparation. Schedule a complimentary consultation with CKSS today.

Leave a Comment