Key Takeaways
1. CMMC Phase II Is Suspended, Not the CMMC Program: DoW paused the planned November 10, 2026 expansion of CMMC certification requirements in applicable contract awards, but CMMC assessments, training, professional services, and supporting systems remain operational.
2. Existing Cybersecurity and Contractual Obligations Remain in Effect: Phase I self-assessments continue, and contractors must still protect covered defense information under applicable DFARS and NIST SP 800-171 requirements. Prime contractors may also continue requiring suppliers to hold CMMC Level 2 certification.
3. CMMC Level 2 Certification Still Provides Strategic Value: Completing an independent C3PAO assessment can improve competitiveness within defense supply chains, reduce disruption when implementation resumes, and provide documented evidence of cybersecurity due diligence.
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements. Those requirements had been scheduled to take effect on November 10, 2026.
The announcement is significant, but it does not eliminate CMMC, shut down the certification ecosystem, or release defense contractors from their existing cybersecurity obligations.
In its official press release, the DoW confirmed that all Phase I self-assessment requirements remain in place. It also emphasized that contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012.
For organizations in the Defense Industrial Base (DIB), the practical message is clear: the compliance timeline has changed, but the need to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) has not.
What Parts of CMMC Did the DoW Suspend?
The DoW suspended the start of the CMMC Program Phase II rollout and paused pending and future CMMC implementation milestones across DoW solicitations and contracts.
Under the original rollout schedule, Phase II would have expanded the use of CMMC Level 2 certification assessments conducted by an authorized CMMC Third-Party Assessment Organization (C3PAO). For applicable solicitations and contracts, an organization would have needed the required CMMC Level 2 status as a condition of contract award beginning November 10, 2026.
The suspension affects the planned implementation of that government contract-award requirement. It also pauses the planned inclusion of CMMC requirements for Level 2 C3PAO certifications and Level 3 Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessments under the applicable DFARS provisions and clauses.
DoW has established a CMMC Reform Task Force to conduct a top-to-bottom review of the program. The task force will consider industry feedback and recommend more scalable security measures, with a final report due to the DoW Chief Information Officer within 60 days of the announcement.
CMMC Remains Operational
The suspension of Phase II implementation should not be confused with the suspension of the CMMC program.
Two days after the DoW announcement, The Cyber AB confirmed that CMMC program services remain operational and available, including:
- C3PAO Level 2 certification assessments
- CAICO-sanctioned training courses
- CMMC professional examinations
- Registered Practitioner support services
- DIBCAC assessments of C3PAOs and candidate C3PAOs
DoW has not directed The Cyber AB to change the program elements under its oversight. C3PAOs can therefore continue conducting CMMC Level 2 mock assessments and certification assessments.
The Supplier Performance Risk System (SPRS) and the CMMC Enterprise Mission Assurance Support Service (eMASS) also remain available for the submission and processing of certification-assessment results.
Government Rollout Phases and CAP Assessment Phases Are Different
One possible point of confusion is understanding the different CMMC contexts in which DoW is using the term “Phase 2.”
The suspended Phase II is a stage in the government’s rollout of CMMC requirements across DoW solicitations and contracts. It is not Phase 2 of the CMMC Assessment Process (CAP) Version 2.0.
In the CAP, Phase 2 is the stage in which a C3PAO assesses an organization’s conformity with CMMC Level 2 security requirements. That assessment process remains available, and CAP Version 2.0 requirements have not been suspended by the DoW announcement.
Organizations that proceed with an assessment should therefore expect their C3PAO to follow the established CAP, including its requirements for evaluating the implementation, depth, and coverage of the applicable security controls.
Existing Cybersecurity Obligations Remain in Effect
The pause does not eliminate the contractual obligation to protect federal information.
During the review period, DoW says it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments. The Department specifically confirmed that DFARS 252.204-7012 remains applicable to defense contractors and subcontractors that handle covered defense information.
Organizations should continue reviewing the provisions and clauses in their solicitations, contracts, subcontracts, and flow-down agreements, including:
- DFARS 252.204-7012: Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019: Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020: NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7021: Contractor Compliance With CMMC Level Requirements
- DFARS 252.204-7024: Notice on the Use of the Supplier Performance Risk System
- DFARS 252.204-7025: Notice of CMMC Level Requirements
The Phase II suspension changes how DoW will implement certain requirements in upcoming awards. However, it does not automatically remove a provision or clause from an existing contract, subcontract, or other contractual instrument.
Contractors should review the language in each agreement and obtain guidance from their contracting officer, prime contractor, or legal counsel when applicability is unclear.
Prime Contractors May Still Require Level 2 Certification
The DoW suspension concerns DoW’s rollout of CMMC as a condition of award between the government and its contractors. It does not prohibit a prime contractor from requiring suppliers to obtain CMMC Level 2 certification.
Prime contractors remain responsible for managing cybersecurity risk throughout their supply chains. Depending on the information shared and the terms of the subcontract, a prime may require a supplier to demonstrate a particular CMMC status before receiving FCI or CUI.
Accordingly, subcontractors should not assume that the federal pause overrides requirements imposed by their primes. Organizations should review existing flow-down language and speak directly with their prime contractors about current and anticipated certification expectations.
Why Proceeding with CMMC Level 2 May Still Make Sense
Organizations that continue toward CMMC Level 2 certification can gain several practical advantages despite the delayed government mandate.
First, certification may preserve access to opportunities in prime contractor supply chains. A prime that must evaluate supplier risk may prefer an organization that has already completed an independent assessment over one that relies exclusively on self-attestation.
Certification can also reduce the operational disruption associated with a future restart of Phase II. Organizations that pause all readiness activity may face compressed remediation and assessment schedules once DoW announces its revised approach.
Finally, an independent assessment provides documented evidence of due diligence. The Department of Justice continues to pursue cybersecurity-related cases under its Civil Cyber-Fraud Initiative, including matters involving alleged misrepresentations of cybersecurity practices or noncompliance with contractual security requirements.
A CMMC certification is not immunity from False Claims Act liability. However, a properly conducted assessment—supported by accurate representations, maintained controls, annual affirmations, and complete documentation—can help an organization demonstrate that it took its cybersecurity obligations seriously.

What DIB Contractors Should Expect Next
DoW will use the review period to reconsider the structure and future direction of CMMC. Until the CMMC Reform Task Force completes its work, contractors should expect further guidance on implementation milestones, certification requirements, and the timing of any revised rollout.
The pause may also delay the point at which many organizations must transition from NIST SP 800-171 Revision 2 to Revision 3 under CMMC. Organizations should nevertheless monitor the developing government-wide FAR CUI rule and other acquisition updates that could introduce separate Revision 3 obligations.
IS Partners also expects government-led assessment activity to remain an important enforcement mechanism during the interim period. With DIBCAC Level 3 assessment activity paused, DIBCAC may have additional capacity for non-voluntary assessments related to DFARS 252.204-7012 and NIST SP 800-171 compliance. Contractors should treat this as a reason to maintain assessment readiness, not as a prediction that every organization will be audited.
To make the most of the additional preparation time offered by DoW’s CMMC Phase II pause, defense contractors and subcontractors should:
- Review current contracts, subcontracts, and flow-down requirements instead of relying on general summaries of the announcement.
- Confirm which systems process, store, or transmit FCI and CUI.
- Continue meeting applicable NIST SP 800-171 Revision 2 requirements.
- Verify that required assessment information and scores are accurate and current in SPRS.
- Maintain evidence supporting each implemented security requirement and any related affirmation.
- Ask prime contractors whether they will continue requiring CMMC Level 2 certification.
- Continue remediation and assessment planning based on contractual requirements and business priorities.
- Monitor announcements from DoW, The Cyber AB, and acquisition authorities during and after the 60-day review.
The Bottom Line
CMMC Phase II implementation has been suspended, but CMMC has not been canceled.
Self-assessment requirements remain in place. DFARS cybersecurity obligations remain enforceable where applicable. Prime contractors may continue requiring Level 2 certification from their suppliers. C3PAOs can continue conducting mock and certification assessments, and the systems supporting those assessments remain operational.
For many DIB organizations, maintaining momentum toward CMMC Level 2 remains the lower-risk business decision. It supports stronger cybersecurity, improves readiness for future contract requirements, and can provide a competitive advantage within defense supply chains.
IS Partners is an authorized C3PAO, helping organizations evaluate their readiness and complete independent CMMC Level 2 certification assessments. Our team makes it easy to navigate CMMC audit readiness and compliance while protecting FCI and CUI thanks to more than 20 years of compliance experience across industries.
Contact IS Partners today to discuss how the CMMC Phase II suspension affects your organization’s contracts, assessment strategy, and compliance roadmap.
What Should You Do Next?
Review Your Contracts and Flow-Down Requirements: Examine current contracts, subcontracts, and prime contractor requirements to determine which CMMC and DFARS obligations still apply. Do not assume the Phase II suspension automatically removes existing requirements.
Maintain CMMC and NIST SP 800-171 Readiness: Continue implementing and documenting applicable NIST SP 800-171 Revision 2 controls, remediating identified gaps, and keeping required SPRS scores and affirmations accurate and current.
Evaluate the Business Case for CMMC Level 2 Certification: Consult with prime contractors about their expectations and consider proceeding with a C3PAO assessment. Certification can strengthen supply-chain eligibility, prepare your organization for CMMC’s revised rollout, and demonstrate cybersecurity due diligence.







