CMMC Phase II Suspended: What Defense Contractors Need to Do Right Now
The Department of War has immediately suspended the transition to CMMC Phase II and launched a 60-day review focused on reducing compliance costs and bureaucratic barriers for small, medium, and non-traditional defense businesses. The pause changes the rollout timeline, but it does not eliminate existing cybersecurity obligations.
What the Department Announced
What Happened to CMMC Phase II?
On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II requirements and pending or future CMMC implementation milestones across Department solicitations and contracts.
Phase II had been scheduled to begin on November 10, 2026. Under the original rollout, Phase II would have increased the use of CMMC Level 2 third-party certification assessments in applicable contract awards.
Instead, the Department has established a CMMC Reform Task Force and initiated a 60-day review of the program. The review will evaluate industry feedback, program costs, acquisition barriers, and ways to create cybersecurity requirements that are more scalable for small and non-traditional businesses.
The suspension is significant because it interrupts the planned escalation toward broader third-party certification requirements. However, it should not be interpreted as the cancellation of cybersecurity requirements or permission to stop protecting FCI and CUI.
The final program structure, future assessment model, implementation dates, reciprocity options, and cost-reduction measures will depend on the task force’s recommendations and later Department guidance.
Why Did the Department Pause CMMC Phase II?
According to the Department’s announcement, the current CMMC program created prohibitive compliance costs and bureaucratic burdens that were discouraging innovative companies from participating in the Defense Industrial Base.
Small manufacturers, subcontractors, engineering firms, technology companies, and specialized suppliers frequently operate with limited cybersecurity staff and narrow government-contract margins. For these organizations, the combined costs of consultants, managed services, secure cloud licensing, documentation, remediation, evidence collection, and third-party assessment can become difficult to absorb.
The Department stated that the review will focus on lowering barriers, increasing competition, supporting speed to capability, and replacing unnecessary administrative overhead with scalable and resilient cybersecurity measures.
The underlying problem is not that cybersecurity is unimportant. The challenge is creating a verification system that protects federal data without forcing smaller suppliers to spend more on the assessment process than on meaningful security improvements.
What Changed and What Did Not Change?
Phase II Implementation Is Paused
The November 10, 2026 transition to Phase II is suspended, along with pending and future implementation milestones. Contractors should no longer assume the previously published rollout schedule will continue unchanged.
Existing Security Requirements Still Apply
Phase I self-assessments remain in place. Contractors must continue protecting FCI and CUI, implementing applicable NIST SP 800-171 requirements, maintaining current documentation, and complying with existing contract clauses.
The Suspension Does Not Remove DFARS or NIST Requirements
CMMC was designed as an assessment and verification mechanism for cybersecurity requirements that already existed. The Phase II suspension does not erase those underlying obligations.
Contractors handling covered defense information remain contractually obligated to provide adequate security under DFARS 252.204-7012. For most CUI environments, that means implementing the applicable requirements from NIST SP 800-171 Revision 2.
Contractors may also remain subject to SPRS scoring, Basic or Medium NIST SP 800-171 DoD Assessments, cyber-incident reporting, cloud-provider requirements, subcontractor flowdowns, and customer-specific security terms.
! A CMMC Pause Is Not a Cybersecurity Pause
Companies that stop remediation, allow evidence to expire, or abandon NIST SP 800-171 implementation may remain noncompliant with existing contracts even if a C3PAO certificate is not immediately required.
What Does CMMC Phase I Still Require?
The Department has stated that Phase I self-assessment requirements remain firmly in place. Its current CMMC guidance describes the program during the pause as allowing self-assessments at Level 1 and Level 2.
What Defense Contractors Need to Do Right Now
Do Not Cancel Your Cybersecurity Program
Continue implementing NIST SP 800-171, addressing high-risk weaknesses, protecting CUI, and maintaining required safeguards. The underlying DFARS obligations remain active.
Review Every Active Contract and Solicitation
Identify current CMMC, DFARS, SPRS, assessment, cloud, incident-reporting, and subcontractor requirements. Do not assume a public announcement automatically modifies an existing contract.
Maintain Your SSP, Evidence, and SPRS Records
Keep the SSP current, preserve implementation evidence, update responsibility assignments, maintain accurate scoping, and ensure required self-assessments and affirmations do not lapse.
Reevaluate C3PAO Timing Before Spending More
Companies planning an assessment solely to meet the former November Phase II timeline should reassess scheduling, cancellation terms, readiness gaps, customer demands, and the business value of completing certification voluntarily.
Separate Required Security From Optional Spending
Continue spending that directly protects CUI or satisfies existing contracts. Delay nonessential purchases driven only by assumptions about the old rollout until the future program structure becomes clearer.
Document Business Impact and Submit Feedback
Small businesses should document real costs, duplicative requirements, assessor challenges, cloud expenses, staffing burdens, contract losses, and practical alternatives that could inform the reform effort.
Use the Pause to Reduce Cost Without Losing Readiness
Emgage helps contractors identify what remains contractually required, pause unnecessary spending, preserve readiness, maintain SSP and evidence records, and choose the lowest-cost practical path while the CMMC program is reviewed.
Review Your CMMC PlanShould You Still Complete a C3PAO Assessment?
There is no single answer for every contractor. The best decision depends on active contract language, customer expectations, assessment deposits, readiness maturity, competitive goals, and the likelihood that certification will still provide business value.
A Customer Still Requires It
A prime contractor, program office, teaming partner, or existing contract may still expect independent verification even while government-wide Phase II implementation is suspended.
You Are Already Assessment-Ready
A company that has completed implementation and evidence preparation may decide that finishing the assessment preserves momentum and creates a competitive differentiator.
The Assessment Was Driven Only by November
If the sole reason for rushing was the November 10, 2026 transition, delaying may prevent unnecessary assessment or consulting costs before reform decisions are announced.
Major Readiness Gaps Remain
Companies with unresolved scope, weak evidence, incomplete technical controls, or uncertain cloud architecture may benefit from using the review period for focused remediation instead of a rushed assessment.
Review your specific contracts, solicitations, assessment agreement, customer communications, and financial exposure before cancelling or rescheduling a C3PAO engagement.
Check Existing Solicitations and Contracts Carefully
The Department announced that pending and future CMMC implementation milestones are suspended, but contractors should still verify how that policy is reflected in individual acquisitions.
Contracting officers may issue amendments, modifications, updated instructions, or revised solicitation language. Prime contractors may also have their own supplier-security requirements that are separate from the government rollout schedule.
How Contractors Should Handle CMMC Spending During the Pause
The suspension creates an opportunity to separate real cybersecurity needs from spending driven primarily by deadlines, fear, or overly broad compliance recommendations.
Contractors should continue investments that reduce actual risk or satisfy existing contractual obligations. Examples include MFA, endpoint protection, secure identity management, backups, vulnerability remediation, logging, access controls, incident response, secure cloud services, and CUI scoping.
Spending that may deserve reevaluation includes rushed assessment scheduling, oversized managed-service packages, unnecessary replacement of systems outside the CUI scope, duplicate compliance tools, and expensive architecture changes based on assumptions about requirements that may be revised.
Security That Protects CUI
Continue funding controls, remediation, documentation, evidence maintenance, incident preparedness, and contractually required self-assessments.
Deadline-Driven Extras
Review assessment deposits, accelerated consulting, unnecessary software replacement, duplicated evidence projects, and purchases driven only by the suspended Phase II date.
What Could the Review Mean for Small and Medium Businesses?
The Department has not yet announced the final reform recommendations. However, the review could examine ways to reduce assessment duplication, increase reciprocity, simplify evidence requirements, improve scoping guidance, adjust certification triggers, expand government-led verification, or create more scalable approaches for lower-risk suppliers.
The task force may also evaluate how costs are distributed across primes and subcontractors, whether assessment requirements align with actual information risk, and how to prevent compliance expenses from excluding specialized suppliers.
These possibilities should be treated as potential directions rather than confirmed policy. Contractors should avoid redesigning their entire security program based on speculation.
! Do Not Assume the Final Program Will Be Easier in Every Area
The Department may reduce administrative burden while strengthening direct technical validation, government-led assessments, automated evidence, incident reporting, or enforcement of NIST SP 800-171.
What to Watch During the Next 60 Days
Phase II Transition Stops
Contractors should review planned assessments, solicitations, implementation projects, and spending decisions in light of the suspension.
Industry Feedback Is Collected
The reform task force will synthesize industry feedback and evaluate cost, complexity, scalability, competition, and cybersecurity outcomes.
Task Force Report Is Due
The task force is expected to deliver recommendations to the Department CIO. Publication timing and implementation actions may follow separately.
New Guidance May Reshape the Rollout
The Department may issue revised milestones, acquisition instructions, assessment expectations, policy memoranda, regulatory actions, or updated FAQs.
Common Mistakes Contractors Should Avoid
Stopping All CMMC and NIST Work
This can create DFARS noncompliance, weaken security, reduce SPRS accuracy, and leave the company unprepared for government-led assessments.
Assuming CMMC Is Permanently Cancelled
The Department announced a suspension and reform study. It did not promise that certification or assessment requirements will never return.
Continuing Every Expense Without Review
Contractors should reevaluate accelerated services, assessment timing, consulting scope, technology purchases, and architecture projects against current business needs.
Letting Evidence and Affirmations Expire
Phase I requirements remain active. Self-assessments, SPRS information, affirmations, SSP records, and evidence should remain current where applicable.
Ignoring Prime and Customer Requirements
Commercial relationships may still require independent verification or security evidence even if the Department’s Phase II schedule is suspended.
Frequently Asked Questions
Is CMMC Phase II officially suspended?
Yes. The Department of War announced the immediate suspension on July 13, 2026. Phase II had previously been scheduled to begin November 10, 2026.
How long is the CMMC review?
The Department announced a 60-day study and instructed the CMMC Reform Task Force to deliver its final report to the Department CIO within that period.
Is CMMC completely cancelled?
No. Phase II implementation is suspended. Phase I self-assessment requirements remain in place, and the Department is reviewing the future structure of the program.
Do contractors still have to follow NIST SP 800-171?
Yes, when required by applicable contracts and DFARS clauses. The Department specifically stated that NIST SP 800-171 Revision 2 will continue to be enforced through self-assessments and selected government-led assessments.
Do Level 1 self-assessments still apply?
Yes. The Department stated that all Phase I self-assessment requirements remain firmly in place.
Should we cancel our C3PAO assessment?
Not automatically. Review your contracts, prime requirements, assessment agreement, readiness level, deposits, competitive goals, and potential cancellation costs before making a decision.
Can contractors stop spending on CMMC?
Contractors should continue funding required cybersecurity and contract compliance. They should reevaluate optional or accelerated spending driven only by the suspended Phase II deadline.
What happens after the 60-day review?
The task force will recommend reforms. The Department may then issue updated implementation timelines, acquisition guidance, assessment requirements, or other policy changes.
The Bottom Line
The suspension of CMMC Phase II is meaningful relief for defense contractors that were facing a rapidly approaching November 2026 certification deadline.
It gives the Department an opportunity to reduce unnecessary cost and bureaucracy while reconsidering how cybersecurity compliance should be verified across small businesses, manufacturers, subcontractors, and non-traditional suppliers.
However, the pause does not eliminate the responsibility to protect FCI and CUI. Phase I self-assessments remain, NIST SP 800-171 continues to be enforced, DFARS 252.204-7012 remains active, and selected government-led assessments may continue.
The best response is not to stop. It is to slow down, reassess unnecessary spending, maintain the security work that matters, preserve documentation and evidence, review each contract, and watch official guidance closely during the 60-day review.
Official Sources
Adjust Your CMMC Plan Without Losing Readiness
Emgage helps defense contractors understand what remains required, protect CUI, maintain evidence, reduce unnecessary costs, evaluate assessment timing, and prepare for whatever follows the 60-day review.
Review Your CMMC Strategy
