On July 13, 2026, the Department of War suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program.
The third-party assessments that were set to start appearing in defense contracts from November 10 are on hold. So are the later milestones lined up behind them.
A newly formed CMMC Reform Task Force now has 60 days to review the whole program, gather industry feedback through a public request for information (RFI), and report back with recommendations.
Department leadership pointed squarely at cost.
By their own figures, compliance was running as high as $600,000 per company and pushing more than 100,000 small businesses toward the exit from the defense supply chain.
The Department also cited the need to cut red tape, pointing to Secretary of War Pete Hegseth’s directive to reduce compliance barriers for small and medium-sized businesses.
Asked what comes next, officials would not rule out scrapping CMMC altogether once the review is done.
If you’ve spent the past year racing toward a Certified Third-Party Assessor Organization (C3PAO) audit, this reads like a reprieve. It’s narrower than it looks.
The Department is halting third-party assessments. Program managers have been told to strip Phase II language out of active solicitations and modify existing defense contracts that already carry it. If your bid or your contract named a C3PAO certification, expect that requirement to come out.
Nothing else moved. CMMC Phase I requirements remain firmly in place. Everything the audit was built to verify still stands.
Phase I stays exactly where it was. Level 1 and Level 2 self-assessments are still required, and you still post your score to the Supplier Performance Risk System (SPRS).
DFARS 252.204-7012 is still in your contracts, so you’re still obligated to implement the security requirements in NIST SP 800-171, protect controlled unclassified information, and report incidents to DIBNet within 72 hours.
Through the review period, the Department will keep enforcing the 800-171 standard using those self-assessments and select government-led checks.
The annual affirmation is still a legal certification. A senior official still signs it, under penalty of law, affirming that what you claim is genuinely in place. And the Department of Justice is still running its Civil Cyber-Fraud Initiative, using the False Claims Act to pursue contractors who misrepresent their security.
That last point gets sharper under the suspension. Third-party audits were going to catch an inflated score before it did any harm. Take the auditor out of the process and your self-assessment becomes the main thing standing between you and a false-claims case.
An inaccurate SPRS number now sits quietly on file until a breach or a whistleblower brings it into the light.
The cases are already on the books. One contractor paid $4.6 million after reporting a positive SPRS score when the true figure was negative 142. Penalties run to triple the government’s damages plus a charge on every false claim, and whistleblowers keep a share of whatever gets recovered.
What defense manufacturers need to do
Keep going. Anyone treating this as permission to stand down has misread it.
Real resilience is about being prepared for the unexpected, and this announcement proves that.
A new recommendation is coming in 60 days, and every signal from the Department this week points to 800-171 staying at the center of it.
Our read: the standard outlasts the wrapper around it. Build to the standard, not to the acronym.
Firms with mature controls will absorb whatever replaces Phase II inside a quarter. The ones that treat the pause as a reason to stop will find themselves starting from behind, with less runway than they had last week.
CMMC put a deadline on something that was always worth doing. The deadline is gone for now. The reason behind it is not.
Adversaries are still targeting the defense supply chain, and a breach still costs contracts, customers, and sometimes the whole business.
Regulations move and deadlines slip. Being ready for the ones you didn’t schedule is the whole point, and it’s what we’ve told clients for years.
A program built specifically for a November date and the audit requirement is being re-planned this week, but if you built to protect the business instead, this change should barely register.
The need for a defensible program remains, and it’s more consequential now that your self-assessment is the only thing between you and a false-claims case.
That work is still worth doing well, and it’s the work we do: build a program that holds up, or validate the one you’ve already built, and stand behind the score you file. A date on a calendar was never what made it worth the investment.
If you want a straight read on whether your program and your score would survive scrutiny, talk it through with us.
Get the latest cyber and AI insights to help your organization stay compliant, resilient and ready for ever-evolving threats and challenges.
Because while risk is constant, ready is a choice.
It's 2 a.m. Ransomware reaches the controllers that run your production line. By first shift, nothing turns on:...
Read more
On July 13, 2026, the Department of War suspended Phase II of the Cybersecurity Maturity Model Certification...
Read more
The DoD's own rulemaking estimates that getting through a Level 2 certification assessment costs a mid-sized...
Read moreLet’s help Plan, Build and Run your cyber and AI programs to keep your business capable, compliant, and resilient. Because while risk is constant, ready is a choice.