Major CMMC Program Update

CMMC Phase II Suspended: What Defense Contractors Need to Do Right Now

The Department of War has immediately suspended the transition to CMMC Phase II and launched a 60-day review focused on reducing compliance costs and bureaucratic barriers for small, medium, and non-traditional defense businesses. The pause changes the rollout timeline, but it does not eliminate existing cybersecurity obligations.

CMMC Phase II 60-Day Review NIST SP 800-171 Defense Contractors

What the Department Announced

Phase II is suspended The transition to Phase II requirements originally scheduled for November 10, 2026 has been stopped.
A 60-day study is underway A CMMC Reform Task Force will review the program and recommend more realistic and scalable security measures.
Phase I remains in effect Current Level 1 and applicable Level 2 self-assessment requirements and affirmations remain active.
Cybersecurity duties remain Defense contractors must still protect covered defense information and comply with DFARS 252.204-7012.
The announcement explained

What Happened to CMMC Phase II?

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements and pending or future CMMC implementation milestones across Department solicitations and contracts.

Phase II had been scheduled to begin on November 10, 2026. Under the original rollout, Phase II would have increased the use of CMMC Level 2 third-party certification assessments in applicable contract awards.

Instead, the Department has established a CMMC Reform Task Force and initiated a 60-day review of the program. The review will evaluate industry feedback, program costs, acquisition barriers, and ways to create cybersecurity requirements that are more scalable for small and non-traditional businesses.

The suspension is significant because it interrupts the planned escalation toward broader third-party certification requirements. However, it should not be interpreted as the cancellation of cybersecurity requirements or permission to stop protecting FCI and CUI.

This is a suspension and reform review, not a declaration that CMMC is permanently eliminated.

The final program structure, future assessment model, implementation dates, reciprocity options, and cost-reduction measures will depend on the task force’s recommendations and later Department guidance.

The cost and competition problem

Why Did the Department Pause CMMC Phase II?

According to the Department’s announcement, the current CMMC program created prohibitive compliance costs and bureaucratic burdens that were discouraging innovative companies from participating in the Defense Industrial Base.

Small manufacturers, subcontractors, engineering firms, technology companies, and specialized suppliers frequently operate with limited cybersecurity staff and narrow government-contract margins. For these organizations, the combined costs of consultants, managed services, secure cloud licensing, documentation, remediation, evidence collection, and third-party assessment can become difficult to absorb.

The Department stated that the review will focus on lowering barriers, increasing competition, supporting speed to capability, and replacing unnecessary administrative overhead with scalable and resilient cybersecurity measures.

The underlying problem is not that cybersecurity is unimportant. The challenge is creating a verification system that protects federal data without forcing smaller suppliers to spend more on the assessment process than on meaningful security improvements.

Changed vs unchanged

What Changed and What Did Not Change?

What changed

Phase II Implementation Is Paused

The November 10, 2026 transition to Phase II is suspended, along with pending and future implementation milestones. Contractors should no longer assume the previously published rollout schedule will continue unchanged.

What remains

Existing Security Requirements Still Apply

Phase I self-assessments remain in place. Contractors must continue protecting FCI and CUI, implementing applicable NIST SP 800-171 requirements, maintaining current documentation, and complying with existing contract clauses.

Do not stop compliance work

The Suspension Does Not Remove DFARS or NIST Requirements

CMMC was designed as an assessment and verification mechanism for cybersecurity requirements that already existed. The Phase II suspension does not erase those underlying obligations.

Contractors handling covered defense information remain contractually obligated to provide adequate security under DFARS 252.204-7012. For most CUI environments, that means implementing the applicable requirements from NIST SP 800-171 Revision 2.

Contractors may also remain subject to SPRS scoring, Basic or Medium NIST SP 800-171 DoD Assessments, cyber-incident reporting, cloud-provider requirements, subcontractor flowdowns, and customer-specific security terms.

! A CMMC Pause Is Not a Cybersecurity Pause

Companies that stop remediation, allow evidence to expire, or abandon NIST SP 800-171 implementation may remain noncompliant with existing contracts even if a C3PAO certificate is not immediately required.

Current requirements

What Does CMMC Phase I Still Require?

The Department has stated that Phase I self-assessment requirements remain firmly in place. Its current CMMC guidance describes the program during the pause as allowing self-assessments at Level 1 and Level 2.

1
Level 1 self-assessments Organizations handling FCI may need to assess the 15 basic safeguarding requirements from FAR 52.204-21 and submit the required affirmation.
2
Level 2 self-assessments Organizations subject to applicable Level 2 self-assessment requirements should continue evaluating the 110 NIST SP 800-171 Revision 2 requirements.
3
SPRS submissions Applicable self-assessment results and current affirmations should continue to be entered and maintained in SPRS.
4
Selected government-led assessments The Department has stated that it will continue enforcing NIST SP 800-171 through self-assessments and selected government-led assessments.
5
Annual affirmations Organizations should not assume affirmation obligations have disappeared merely because Phase II third-party certification requirements are suspended.
Immediate action plan

What Defense Contractors Need to Do Right Now

1

Do Not Cancel Your Cybersecurity Program

Continue implementing NIST SP 800-171, addressing high-risk weaknesses, protecting CUI, and maintaining required safeguards. The underlying DFARS obligations remain active.

2

Review Every Active Contract and Solicitation

Identify current CMMC, DFARS, SPRS, assessment, cloud, incident-reporting, and subcontractor requirements. Do not assume a public announcement automatically modifies an existing contract.

3

Maintain Your SSP, Evidence, and SPRS Records

Keep the SSP current, preserve implementation evidence, update responsibility assignments, maintain accurate scoping, and ensure required self-assessments and affirmations do not lapse.

4

Reevaluate C3PAO Timing Before Spending More

Companies planning an assessment solely to meet the former November Phase II timeline should reassess scheduling, cancellation terms, readiness gaps, customer demands, and the business value of completing certification voluntarily.

5

Separate Required Security From Optional Spending

Continue spending that directly protects CUI or satisfies existing contracts. Delay nonessential purchases driven only by assumptions about the old rollout until the future program structure becomes clearer.

6

Monitor Official Guidance, Not Rumors

Follow the Department’s CMMC website, reform task force publications, RFI activity, contract modifications, acquisition guidance, and official FAQs during the 60-day review.

7

Document Business Impact and Submit Feedback

Small businesses should document real costs, duplicative requirements, assessor challenges, cloud expenses, staffing burdens, contract losses, and practical alternatives that could inform the reform effort.

Use the Pause to Reduce Cost Without Losing Readiness

Emgage helps contractors identify what remains contractually required, pause unnecessary spending, preserve readiness, maintain SSP and evidence records, and choose the lowest-cost practical path while the CMMC program is reviewed.

Review Your CMMC Plan
Certification decisions

Should You Still Complete a C3PAO Assessment?

There is no single answer for every contractor. The best decision depends on active contract language, customer expectations, assessment deposits, readiness maturity, competitive goals, and the likelihood that certification will still provide business value.

Consider continuing

A Customer Still Requires It

A prime contractor, program office, teaming partner, or existing contract may still expect independent verification even while government-wide Phase II implementation is suspended.

Consider continuing

You Are Already Assessment-Ready

A company that has completed implementation and evidence preparation may decide that finishing the assessment preserves momentum and creates a competitive differentiator.

Consider delaying

The Assessment Was Driven Only by November

If the sole reason for rushing was the November 10, 2026 transition, delaying may prevent unnecessary assessment or consulting costs before reform decisions are announced.

Consider delaying

Major Readiness Gaps Remain

Companies with unresolved scope, weak evidence, incomplete technical controls, or uncertain cloud architecture may benefit from using the review period for focused remediation instead of a rushed assessment.

Do not make the decision based only on headlines.

Review your specific contracts, solicitations, assessment agreement, customer communications, and financial exposure before cancelling or rescheduling a C3PAO engagement.

Contract-by-contract review

Check Existing Solicitations and Contracts Carefully

The Department announced that pending and future CMMC implementation milestones are suspended, but contractors should still verify how that policy is reflected in individual acquisitions.

Contracting officers may issue amendments, modifications, updated instructions, or revised solicitation language. Prime contractors may also have their own supplier-security requirements that are separate from the government rollout schedule.

Review current CMMC clauses Identify the required level, assessment type, UID, affirmation, flowdown, and award conditions written into the contract.
Look for amendments Monitor SAM.gov, contracting-officer notices, solicitation amendments, prime communications, and formal contract modifications.
Confirm prime-contractor expectations A prime may continue requiring security attestations, independent assessments, minimum SPRS scores, or additional evidence from suppliers.
Document written guidance Keep records of contracting-officer instructions and customer decisions rather than relying on informal conversations.
Cost control during uncertainty

How Contractors Should Handle CMMC Spending During the Pause

The suspension creates an opportunity to separate real cybersecurity needs from spending driven primarily by deadlines, fear, or overly broad compliance recommendations.

Contractors should continue investments that reduce actual risk or satisfy existing contractual obligations. Examples include MFA, endpoint protection, secure identity management, backups, vulnerability remediation, logging, access controls, incident response, secure cloud services, and CUI scoping.

Spending that may deserve reevaluation includes rushed assessment scheduling, oversized managed-service packages, unnecessary replacement of systems outside the CUI scope, duplicate compliance tools, and expensive architecture changes based on assumptions about requirements that may be revised.

Keep funding

Security That Protects CUI

Continue funding controls, remediation, documentation, evidence maintenance, incident preparedness, and contractually required self-assessments.

Reevaluate

Deadline-Driven Extras

Review assessment deposits, accelerated consulting, unnecessary software replacement, duplicated evidence projects, and purchases driven only by the suspended Phase II date.

Potential reform outcomes

What Could the Review Mean for Small and Medium Businesses?

The Department has not yet announced the final reform recommendations. However, the review could examine ways to reduce assessment duplication, increase reciprocity, simplify evidence requirements, improve scoping guidance, adjust certification triggers, expand government-led verification, or create more scalable approaches for lower-risk suppliers.

The task force may also evaluate how costs are distributed across primes and subcontractors, whether assessment requirements align with actual information risk, and how to prevent compliance expenses from excluding specialized suppliers.

These possibilities should be treated as potential directions rather than confirmed policy. Contractors should avoid redesigning their entire security program based on speculation.

! Do Not Assume the Final Program Will Be Easier in Every Area

The Department may reduce administrative burden while strengthening direct technical validation, government-led assessments, automated evidence, incident reporting, or enforcement of NIST SP 800-171.

The review period

What to Watch During the Next 60 Days

Immediately

Phase II Transition Stops

Contractors should review planned assessments, solicitations, implementation projects, and spending decisions in light of the suspension.

During Review

Industry Feedback Is Collected

The reform task force will synthesize industry feedback and evaluate cost, complexity, scalability, competition, and cybersecurity outcomes.

Within 60 Days

Task Force Report Is Due

The task force is expected to deliver recommendations to the Department CIO. Publication timing and implementation actions may follow separately.

After Review

New Guidance May Reshape the Rollout

The Department may issue revised milestones, acquisition instructions, assessment expectations, policy memoranda, regulatory actions, or updated FAQs.

Avoid these reactions

Common Mistakes Contractors Should Avoid

1

Stopping All CMMC and NIST Work

This can create DFARS noncompliance, weaken security, reduce SPRS accuracy, and leave the company unprepared for government-led assessments.

2

Assuming CMMC Is Permanently Cancelled

The Department announced a suspension and reform study. It did not promise that certification or assessment requirements will never return.

3

Continuing Every Expense Without Review

Contractors should reevaluate accelerated services, assessment timing, consulting scope, technology purchases, and architecture projects against current business needs.

4

Letting Evidence and Affirmations Expire

Phase I requirements remain active. Self-assessments, SPRS information, affirmations, SSP records, and evidence should remain current where applicable.

5

Ignoring Prime and Customer Requirements

Commercial relationships may still require independent verification or security evidence even if the Department’s Phase II schedule is suspended.

Common questions

Frequently Asked Questions

Is CMMC Phase II officially suspended?

Yes. The Department of War announced the immediate suspension on July 13, 2026. Phase II had previously been scheduled to begin November 10, 2026.

How long is the CMMC review?

The Department announced a 60-day study and instructed the CMMC Reform Task Force to deliver its final report to the Department CIO within that period.

Is CMMC completely cancelled?

No. Phase II implementation is suspended. Phase I self-assessment requirements remain in place, and the Department is reviewing the future structure of the program.

Do contractors still have to follow NIST SP 800-171?

Yes, when required by applicable contracts and DFARS clauses. The Department specifically stated that NIST SP 800-171 Revision 2 will continue to be enforced through self-assessments and selected government-led assessments.

Do Level 1 self-assessments still apply?

Yes. The Department stated that all Phase I self-assessment requirements remain firmly in place.

Should we cancel our C3PAO assessment?

Not automatically. Review your contracts, prime requirements, assessment agreement, readiness level, deposits, competitive goals, and potential cancellation costs before making a decision.

Can contractors stop spending on CMMC?

Contractors should continue funding required cybersecurity and contract compliance. They should reevaluate optional or accelerated spending driven only by the suspended Phase II deadline.

What happens after the 60-day review?

The task force will recommend reforms. The Department may then issue updated implementation timelines, acquisition guidance, assessment requirements, or other policy changes.

The Bottom Line

The suspension of CMMC Phase II is meaningful relief for defense contractors that were facing a rapidly approaching November 2026 certification deadline.

It gives the Department an opportunity to reduce unnecessary cost and bureaucracy while reconsidering how cybersecurity compliance should be verified across small businesses, manufacturers, subcontractors, and non-traditional suppliers.

However, the pause does not eliminate the responsibility to protect FCI and CUI. Phase I self-assessments remain, NIST SP 800-171 continues to be enforced, DFARS 252.204-7012 remains active, and selected government-led assessments may continue.

The best response is not to stop. It is to slow down, reassess unnecessary spending, maintain the security work that matters, preserve documentation and evidence, review each contract, and watch official guidance closely during the 60-day review.

Official Sources

Adjust Your CMMC Plan Without Losing Readiness

Emgage helps defense contractors understand what remains required, protect CUI, maintain evidence, reduce unnecessary costs, evaluate assessment timing, and prepare for whatever follows the 60-day review.

Review Your CMMC Strategy