Understanding the 60-Day CMMC Review

Is CMMC Going Away?

The suspension of CMMC Phase II has created confusion across the Defense Industrial Base. Some contractors believe CMMC has been cancelled. Others assume every assessment and cybersecurity requirement remains unchanged. The reality is more nuanced.

CMMC Phase II 60-Day Review CMMC Suspension Defense Contractors

The Direct Answer: No, CMMC Is Not Going Away

The Department has suspended the transition to Phase II and launched a 60-day review of the program. Phase I self-assessments and the underlying cybersecurity requirements remain in place.

Phase II is paused The planned November 10, 2026 expansion toward broader C3PAO certification requirements has been suspended.
Phase I remains active Applicable Level 1 and Level 2 self-assessments and affirmations remain part of the current program.
Cybersecurity requirements remain DFARS, FAR, NIST SP 800-171, SPRS and incident-reporting obligations have not simply disappeared.
The future structure may change The Department may revise timelines, assessment triggers, costs, reciprocity or the way compliance is verified.
The answer without the noise

No, CMMC Is Not Being Eliminated

The Department has paused the next phase of implementation, not cancelled the entire cybersecurity program.

On July 13, 2026, the Department announced the immediate suspension of the transition to CMMC Phase II. That phase had been scheduled to begin on November 10, 2026 and would have expanded the use of Level 2 C3PAO certification assessments in applicable contracts.

The Department also created a reform task force and began a 60-day review of the CMMC program. The purpose of the review is to evaluate compliance cost, bureaucracy, barriers to small-business participation and whether cybersecurity verification can be made more scalable.

Phase I requirements remain in place. Contractors should therefore view the announcement as a delay and potential restructuring of the rollout, not as permission to stop protecting Federal Contract Information or Controlled Unclassified Information.

The most accurate one-sentence answer:

CMMC is not going away, but the way it is implemented, assessed and enforced may change after the 60-day review.

What the announcement says

What Did the Department Actually Announce?

The Department announced three major actions.

First, the transition to Phase II was suspended. Second, pending and future CMMC implementation milestones were paused while the Department conducts its review. Third, the Department established a task force with 60 days to evaluate the program and recommend reforms.

The Department said the review is intended to preserve a strong cybersecurity baseline while reducing compliance costs and bureaucratic barriers that can prevent smaller and non-traditional companies from joining or remaining in the defense supply chain.

The announcement did not state that contractors no longer need cybersecurity controls. It specifically said Phase I self-assessment requirements remain firmly in place.

Common myth

CMMC Has Been Cancelled

The Phase II rollout has been suspended, but the CMMC framework, Phase I self-assessments and underlying security obligations remain active.

Current reality

CMMC Is Under Review

The Department is reviewing how CMMC should work, who should need outside certification and how the burden can be reduced without abandoning cybersecurity.

The paused implementation step

What Was CMMC Phase II Supposed to Do?

CMMC was being introduced through a multi-phase rollout. Phase I began on November 10, 2025 and focused primarily on self-assessment requirements.

Phase II was scheduled to begin on November 10, 2026. It would have expanded the use of Level 2 certification assessments performed by authorized CMMC Third-Party Assessment Organizations, commonly called C3PAOs.

That planned transition is now suspended. Contractors should no longer assume that the previous November 2026 deadline or the original four-phase timeline will remain unchanged after the review.

Phase I
Still Active

Self-Assessment Requirements

Applicable Level 1 and Level 2 self-assessment paths remain active, including required entries and affirmations in SPRS.

Phase II
Suspended

Broader C3PAO Certification Requirements

The scheduled November 10, 2026 transition toward expanded third-party Level 2 assessments has been paused.

Future
Under Review

Revised Program Structure

The Department may change implementation dates, certification triggers, assessment methods, reciprocity or other program requirements.

Current program requirements

What CMMC Phase I Still Requires

Phase I remains the current implementation stage. That means applicable contractors may still need to complete CMMC self-assessments and affirm their compliance.

1
Level 1 annual self-assessments Organizations handling FCI may need to assess the 15 safeguarding requirements in FAR 52.204-21 and affirm compliance annually.
2
Level 2 self-assessments where required Organizations handling CUI may need to assess implementation of the 110 NIST SP 800-171 Revision 2 requirements.
3
SPRS records Applicable assessment results, scores, CMMC statuses and affirmations must remain current in the Supplier Performance Risk System.
4
Annual affirmations The required official must affirm continued compliance after the assessment and annually thereafter where applicable.
5
Government-led assessments The Department may continue selected NIST SP 800-171 assessments performed by government personnel.
The foundation did not disappear

Which Cybersecurity Requirements Still Apply?

CMMC did not create every underlying cybersecurity obligation. It was designed largely to verify requirements that defense contractors were already expected to follow.

Contractors handling covered defense information may still be required to comply with DFARS 252.204-7012, implement NIST SP 800-171 Revision 2, report qualifying cyber incidents, use appropriate external cloud services and flow requirements down to subcontractors.

Contractors may also need a current NIST SP 800-171 DoD Assessment score in SPRS before contract award, option exercise or period-of-performance extension.

! CMMC Was the Verification Layer, Not the Only Source of the Requirement

Even if the assessment model changes, DFARS and NIST requirements can continue to apply through contracts, government assessments and cybersecurity enforcement.

Do Not Let the Pause Create a Compliance Gap

Emgage helps contractors determine what remains required, maintain an accurate self-assessment, protect CUI, organize evidence and avoid unnecessary C3PAO or technology costs while the program is reviewed.

Review Your Current CMMC Requirements
Why reform is happening

Why Is the Department Reviewing CMMC?

The Department said the current and planned CMMC requirements were creating prohibitive costs and unacceptable bureaucratic burdens, particularly for small businesses.

Smaller manufacturers and specialty subcontractors often have limited cybersecurity staff, small operating margins and older production environments. The cost of secure technology, consultants, documentation, managed services and outside assessments can become a barrier to competing for defense contracts.

The review is intended to determine whether the program can maintain strong cybersecurity while reducing paperwork, duplicated assessments and expenses that do not directly improve security.

That makes the review important for the entire Defense Industrial Base. A program that is too expensive may drive capable suppliers away, but a program with weak verification may leave sensitive defense information exposed.

Potential reform directions

What Could Change After the 60-Day Review?

The Department has not announced final reforms. However, several parts of the program could be reconsidered.

Possible change

Different C3PAO Triggers

Third-party certification may be limited to higher-risk contracts, more sensitive CUI environments or specific categories of systems.

Possible change

More Reciprocity

The Department may consider greater reuse of comparable assessments or certifications to reduce duplicate reviews.

Possible change

Simplified Requirements for SMBs

Smaller or lower-risk suppliers may receive more scalable implementation, evidence or assessment options.

Possible change

More Government-Led Verification

The Department may rely more heavily on targeted government assessments instead of requiring every contractor to purchase certification.

Possible change

Updated Implementation Timelines

The previous four-phase rollout may be extended, replaced or redesigned after the review.

Possible change

More Technical Validation

The program could reduce narrative paperwork while increasing direct validation of configurations, evidence and security outcomes.

These are possible outcomes, not confirmed policy.

Contractors should wait for official Department guidance before making major architecture, assessment or contract decisions based on speculation.

Important unanswered questions

What Is Not Yet Known?

The 60-day review creates uncertainty because several important decisions have not yet been published.

?
Whether Phase II will return in its previous form The Department may reinstate, revise or replace the original Phase II requirements.
?
Which contracts will require C3PAO certification Future certification triggers may change based on risk, data sensitivity, contract type or supplier category.
?
Whether existing certifications receive special treatment The Department may issue transition guidance for organizations that already completed or scheduled assessments.
?
Whether assessment costs will be reduced The review is focused on burden reduction, but no specific pricing, funding or reimbursement policy has been announced.
?
When a revised rollout will begin The task force report is due within the review period, but implementation actions may follow later.
The practical response

What Defense Contractors Should Do Right Now

1

Continue Protecting FCI and CUI

Do not suspend controls, monitoring, incident response, access management, patching, backups or other safeguards required by active contracts.

2

Review Active Contracts and Solicitations

Identify the specific CMMC level, assessment type, DFARS clauses, SPRS requirements and written customer expectations that currently apply.

3

Maintain the SSP and Evidence

Keep system boundaries, diagrams, inventories, narratives, policies, configurations, tickets, reviews and training evidence current.

4

Validate Your Self-Assessment

Make sure the reported score and affirmation are supported by real implementation rather than assumptions or incomplete documentation.

5

Reevaluate C3PAO Timing

Review whether an outside assessment remains contractually necessary, competitively valuable or financially reasonable during the suspension.

6

Avoid Unnecessary Compliance Spending

Continue investments that protect CUI, but reconsider rushed purchases or assessment services driven only by the suspended November deadline.

7

Monitor Official Guidance

Follow Department CIO updates, acquisition guidance, solicitations, contracting-officer instructions and the task force’s reform recommendations.

Third-party certification decisions

Does the Suspension Mean You Should Cancel a C3PAO Assessment?

Not automatically. The right decision depends on why the assessment was scheduled.

A contractor may still decide to proceed if a prime contractor or customer requires independent verification, if the company is already fully prepared or if certification creates a meaningful competitive advantage.

A contractor may consider delaying when the assessment was scheduled solely to meet the former November 2026 Phase II date, major readiness gaps remain or assessment costs would strain the business.

Consider continuing

Certification Has Business Value

Continue when a customer requires it, readiness is strong or independent verification supports important contract opportunities.

Consider delaying

The Deadline Was the Only Reason

Delay may be reasonable when the assessment was driven only by the suspended rollout and no current contract requires it.

Review the assessment agreement before cancelling.

Deposits, cancellation provisions, scheduling commitments and work already completed may affect the financial decision.

Why stopping can backfire

The Risks of Assuming CMMC Is Going Away

Contractors that interpret the suspension as a complete cancellation may create new contractual and business risks.

!
DFARS noncompliance The contractor may still be required to implement NIST SP 800-171 and protect covered defense information.
!
Inaccurate SPRS representations An unsupported score or expired assessment may affect award eligibility and create representation risk.
!
Government assessment findings Selected government-led assessments may identify weaknesses even when a C3PAO assessment is not currently required.
!
Lost prime-contractor opportunities Primes may continue favoring suppliers that can demonstrate strong cybersecurity and current evidence.
!
Future remediation rush Companies that stop now may face higher costs and limited assessor availability when revised requirements return.

! The Requirement May Become Less Bureaucratic, Not Less Serious

The Department may reduce paperwork while increasing direct technical validation, government assessments or enforcement of actual NIST SP 800-171 implementation.

What to watch next

What Happens During the 60-Day Review?

During the review period, the reform task force is expected to examine program cost, acquisition barriers, industry feedback, assessment burden and whether CMMC can be aligned more closely with measurable cybersecurity outcomes.

Contractors should watch for requests for information, implementation memoranda, revised solicitation instructions, acquisition deviations, updated frequently asked questions and the task force’s final recommendations.

The task force report may recommend changes, but those recommendations may still require additional policy, acquisition or regulatory action before becoming permanent.

Now

Phase II Is Suspended

Contractors should review assessment plans, contract requirements and unnecessary deadline-driven expenses.

During Review

The Department Studies Reform Options

Industry feedback, small-business impacts and potential alternatives will be evaluated.

After Review

Revised Guidance May Follow

The Department may publish a new rollout, altered assessment triggers or other implementation changes.

Common contractor questions

Frequently Asked Questions

Is CMMC officially going away?

No. The Department suspended Phase II and began a 60-day review. Phase I self-assessment requirements remain in place.

Was CMMC Phase II cancelled?

The transition to Phase II was suspended. Whether it returns in the same form, a revised form or a replacement model is not yet known.

Do Level 1 self-assessments still apply?

Yes. Applicable Level 1 self-assessment and annual affirmation requirements remain part of Phase I.

Do Level 2 self-assessments still apply?

Yes, when specified by the applicable solicitation or contract. Level 2 self-assessments remain part of the current Phase I model.

Do contractors still need NIST SP 800-171?

Yes, when required by DFARS 252.204-7012 and the applicable contract. The Department has said it will continue enforcing NIST SP 800-171 through self-assessments and selected government-led assessments.

Should contractors stop spending on compliance?

No. Continue funding security controls and contractual requirements. Reevaluate optional costs driven only by the suspended Phase II deadline.

Will C3PAO assessments still be required later?

Possibly. The future assessment structure is under review, and the Department has not yet published final reform decisions.

Could the review make CMMC easier for small businesses?

That is one of the stated goals, but the specific cost reductions, exemptions, assessment changes or implementation alternatives are not yet finalized.

The Bottom Line

CMMC is not going away. The Department has paused Phase II and launched a 60-day review of how the program should work.

That review may create meaningful changes for small and medium-sized contractors, including lower costs, narrower C3PAO triggers, greater reciprocity or a more scalable assessment model.

What has not changed is the responsibility to protect FCI and CUI. Phase I self-assessments remain active, NIST SP 800-171 continues to matter, DFARS obligations remain and government-led assessments may continue.

Contractors should use the pause to reduce unnecessary spending, strengthen actual cybersecurity, validate their self-assessments and prepare for a revised program rather than assuming the requirement has disappeared.

Official Sources

Stay Compliant Without Overspending During the Pause

Emgage helps defense contractors understand current requirements, validate self-assessments, maintain SSP and evidence records, reduce unnecessary costs and prepare for the outcome of the 60-day CMMC review.

Review Your CMMC Compliance Path