Part 1: CMMC Phase II Is Paused—But the Program Is Not
The Department’s July 13, 2026 announcement that it was suspending Phase II of the Cybersecurity Maturity Model Certification (CMMC) program immediately created questions throughout the defense industrial base.
Is CMMC going away?
Should organizations stop preparing for certification?
Were the time and money already spent on CMMC readiness wasted?
The answer to each question is “no”, and certainly not based on anything the Department has announced.
The pause is significant and will likely lead to meaningful changes in how CMMC is applied throughout the supply chain. But the announcement did not cancel CMMC, weaken existing certifications, or remove the cybersecurity obligations that defense contractors already have.
The practical message is straightforward: The Department paused the next phase of implementation. It did not pause the need to protect sensitive defense information.
What Was Scheduled to Happen?
CMMC implementation began under a four-phase schedule.
Phase I began on November 10, 2025. During that phase, applicable solicitations and contracts could require a CMMC Level 1 self-assessment or a CMMC Level 2 self-assessment.
Phase II was scheduled to begin on November 10, 2026. That phase would have expanded the use of CMMC Level 2 certification assessments performed by authorized Certified Third-Party Assessment Organizations, commonly referred to as C3PAOs.
On July 13, 2026, the Department announced that the transition to Phase II was suspended. The Department also said that all Phase I self-assessment requirements would remain in place while it performed a comprehensive review of the program.
During the suspension, program managers and requiring activities have been directed to include only Level 1 self-assessment or Level 2 self-assessment requirements in procurement request and requirements documents. The previously scheduled November 2026 expansion of Level 2 certification requirements will therefore not proceed according to the original timeline.
Why Was Phase II Paused?
The Department described the review as part of a broader effort to improve acquisition speed, reduce barriers for small, medium-sized, and nontraditional suppliers, and replace overly bureaucratic compliance processes with scalable and resilient cybersecurity measures.
Those concerns are not new. Small and mid-sized defense suppliers have consistently raised questions about:
- the cost of building and maintaining a compliant environment;
- the cost and availability of formal assessments;
- inconsistent identification and marking of Controlled Unclassified Information;
- uncertainty about which systems and suppliers are in scope;
- the effect of compliance costs on companies with limited defense revenue;
- whether the same assessment model is appropriate throughout every tier of the supply chain; and
- whether the program might force capable suppliers to leave the defense marketplace.
The pause gives the Department an opportunity to revisit these issues before Level 2 certification requirements become more broadly incorporated into contracts. But that does not necessarily mean the Department believes CMMC’s underlying objectives are wrong. It may mean that the Department is reconsidering whether the current structure is the best way to achieve those objectives.
What Could Change?
A newly formed CMMC Reform Task Force is conducting a 60-day top-to-bottom review, purportedly to reduce costs and red tape for small businesses. This review process includes an industry Request for Information (RFI) with feedback due by August 14, 2026. The Department has not yet indicated any changes that will result from its review.
Potential areas of reform could include:
- which contractors require third-party certification and how certification requirements are assigned to contracts;
- responsibilities of prime contractors and how requirements are scaled for smaller suppliers;
- the frequency or timing of assessments with potential recognition of other forms of independent validation; and
- how CMMC is integrated into broader acquisition reform.
These are reasonable possibilities, but they remain possibilities. Contractors should not treat speculation as if it were a final rule or policy decision. In the end, a program review can result in modest adjustments, substantial restructuring, or something in between.
What Did Not Happen?
The CMMC program was not canceled, and the CMMC rule was not withdrawn. Phase I requirements are still in place, so obligations involving self-assessments and the implementation of NIST SP 800-171 were not changed. DFARS 252.204-7012 has not been removed from contracts and existing SPRS obligations have not been eliminated. On the bright side, existing CMMC certificates have not been invalidated. The responsibility for contractors to protect FCI and CUI remains.
These distinctions are important because the word “pause” can easily be misinterpreted to “cancellation” as it passes through organizations and supply chains.
A supplier may hear that Phase II has been paused and assume that CMMC work should stop. A manager may defer a remediation budget. An executive may conclude that an SPRS score no longer matters. A prime contractor may stop communicating expectations to subcontractors.
None of those conclusions follows from the announcement.
The CMMC Ecosystem Is Still Operating
The July 2026 Cyber AB Town Hall provided additional context regarding the current state of the program. The Cyber AB is the official, independent accreditation body for the CMMC ecosystem. It exists as a non-governmental partner of the DoD, and manages training, authorization, and oversight for third-party assessors and auditing organizations verifying defense contractor cybersecurity compliance.
At the time of the Town Hall, The Cyber AB reported:
- 1,866 final CMMC Level 2 certificates;
- 58 conditional Level 2 certificates;
- 168 Level 2 assessments in progress;
- 111 authorized or accredited C3PAOs; and
- more than 1,000 Certified CMMC Assessors.
The Town Hall also emphasized that CMMC operations were continuing and that C3PAOs could continue to perform voluntary Level 2 certification assessments. Existing certifications were not withdrawn by the Phase II announcement.
While The Cyber AB is not the Department and does not determine the final structure of the CMMC program, its observations demonstrate that the CMMC ecosystem has not shut down. NIST SP 800-171 and DFARS 252.204-7012 obligations remain in place for affected contractors. Level 2 certification continue to provide business value to subcontractors seeking to demonstrate readiness to prime contractors.
Was Prior CMMC Work Wasted?
For organizations that approached CMMC as an exercise in collecting documents and preparing for an assessment, some work may need to be adjusted after the Department completes its review.
For organizations that used CMMC readiness to improve their actual cybersecurity program, most of the work should retain value.
Examples include:
- identifying where CUI is stored and transmitted;
- limiting access to sensitive information;
- implementing multifactor authentication;
- improving logging and monitoring;
- strengthening vulnerability and patch management;
- developing an incident response capability;
- documenting the environment in a System Security Plan;
- improving relationships with managed service providers;
- reviewing privileged access;
- protecting backups; and
- building evidence that controls operate consistently.
These activities are not useful only because an assessor may ask about them, they reduce the likelihood and potential impact of an actual security event.
Should Organizations Continue Toward Certification?
There is no universal answer. An organization may have a sound reason to continue toward a voluntary Level 2 certification when:
- an important prime contractor expects it;
- a significant business opportunity is likely to require it;
- certification would distinguish the company from competitors; or
- customers are asking for independent assurance.
An organization may reasonably delay the formal C3PAO assessment when:
- the CUI scope remains uncertain;
- the environment is undergoing major change, or substantial technical remediation is incomplete;
- evidence is not sufficiently mature;
- certification is not currently required by a customer or opportunity; or
- management wants greater clarity regarding the Department’s reforms.
While delaying the formal assessment may be a reasonable decision, delaying security work is not normally advised and certainly isn’t the same thing.
The Practical Response to the Pause
Organizations should avoid the extremes.
The first extreme is to race toward certification without considering whether the timing still makes business sense.
The second is to stop all CMMC and NIST SP 800-171 activity because Phase II has been paused.
A more reasonable approach is to continue the work that supports contractual compliance, good security, accurate reporting, and customer confidence while reevaluating the timing of the formal certification assessment.
The pause provides more time. The value of that time will depend on how organizations use it.
Coming Next
The Phase II pause changes when third-party certification requirements may be introduced into additional contracts. It does not eliminate the cybersecurity clauses and assessment obligations that already apply to many defense suppliers.
In Part 2, we will examine what the pause does not change—and what prime contractors and subcontractors are still expected to do today.
This series provides general information and does not constitute legal advice. Organizations facing potential contractual, False Claims Act, disclosure, or incident-reporting concerns should consult qualified legal counsel.



