Is CMMC Going Away?
The suspension of CMMC Phase II has created confusion across the Defense Industrial Base. Some contractors believe CMMC has been cancelled. Others assume every assessment and cybersecurity requirement remains unchanged. The reality is more nuanced.
The Direct Answer: No, CMMC Is Not Going Away
The Department has suspended the transition to Phase II and launched a 60-day review of the program. Phase I self-assessments and the underlying cybersecurity requirements remain in place.
No, CMMC Is Not Being Eliminated
The Department has paused the next phase of implementation, not cancelled the entire cybersecurity program.
On July 13, 2026, the Department announced the immediate suspension of the transition to CMMC Phase II. That phase had been scheduled to begin on November 10, 2026 and would have expanded the use of Level 2 C3PAO certification assessments in applicable contracts.
The Department also created a reform task force and began a 60-day review of the CMMC program. The purpose of the review is to evaluate compliance cost, bureaucracy, barriers to small-business participation and whether cybersecurity verification can be made more scalable.
Phase I requirements remain in place. Contractors should therefore view the announcement as a delay and potential restructuring of the rollout, not as permission to stop protecting Federal Contract Information or Controlled Unclassified Information.
CMMC is not going away, but the way it is implemented, assessed and enforced may change after the 60-day review.
What Did the Department Actually Announce?
The Department announced three major actions.
First, the transition to Phase II was suspended. Second, pending and future CMMC implementation milestones were paused while the Department conducts its review. Third, the Department established a task force with 60 days to evaluate the program and recommend reforms.
The Department said the review is intended to preserve a strong cybersecurity baseline while reducing compliance costs and bureaucratic barriers that can prevent smaller and non-traditional companies from joining or remaining in the defense supply chain.
The announcement did not state that contractors no longer need cybersecurity controls. It specifically said Phase I self-assessment requirements remain firmly in place.
CMMC Has Been Cancelled
The Phase II rollout has been suspended, but the CMMC framework, Phase I self-assessments and underlying security obligations remain active.
CMMC Is Under Review
The Department is reviewing how CMMC should work, who should need outside certification and how the burden can be reduced without abandoning cybersecurity.
What Was CMMC Phase II Supposed to Do?
CMMC was being introduced through a multi-phase rollout. Phase I began on November 10, 2025 and focused primarily on self-assessment requirements.
Phase II was scheduled to begin on November 10, 2026. It would have expanded the use of Level 2 certification assessments performed by authorized CMMC Third-Party Assessment Organizations, commonly called C3PAOs.
That planned transition is now suspended. Contractors should no longer assume that the previous November 2026 deadline or the original four-phase timeline will remain unchanged after the review.
Still Active
Self-Assessment Requirements
Applicable Level 1 and Level 2 self-assessment paths remain active, including required entries and affirmations in SPRS.
Suspended
Broader C3PAO Certification Requirements
The scheduled November 10, 2026 transition toward expanded third-party Level 2 assessments has been paused.
Under Review
Revised Program Structure
The Department may change implementation dates, certification triggers, assessment methods, reciprocity or other program requirements.
What CMMC Phase I Still Requires
Phase I remains the current implementation stage. That means applicable contractors may still need to complete CMMC self-assessments and affirm their compliance.
Which Cybersecurity Requirements Still Apply?
CMMC did not create every underlying cybersecurity obligation. It was designed largely to verify requirements that defense contractors were already expected to follow.
Contractors handling covered defense information may still be required to comply with DFARS 252.204-7012, implement NIST SP 800-171 Revision 2, report qualifying cyber incidents, use appropriate external cloud services and flow requirements down to subcontractors.
Contractors may also need a current NIST SP 800-171 DoD Assessment score in SPRS before contract award, option exercise or period-of-performance extension.
! CMMC Was the Verification Layer, Not the Only Source of the Requirement
Even if the assessment model changes, DFARS and NIST requirements can continue to apply through contracts, government assessments and cybersecurity enforcement.
Do Not Let the Pause Create a Compliance Gap
Emgage helps contractors determine what remains required, maintain an accurate self-assessment, protect CUI, organize evidence and avoid unnecessary C3PAO or technology costs while the program is reviewed.
Review Your Current CMMC RequirementsWhy Is the Department Reviewing CMMC?
The Department said the current and planned CMMC requirements were creating prohibitive costs and unacceptable bureaucratic burdens, particularly for small businesses.
Smaller manufacturers and specialty subcontractors often have limited cybersecurity staff, small operating margins and older production environments. The cost of secure technology, consultants, documentation, managed services and outside assessments can become a barrier to competing for defense contracts.
The review is intended to determine whether the program can maintain strong cybersecurity while reducing paperwork, duplicated assessments and expenses that do not directly improve security.
That makes the review important for the entire Defense Industrial Base. A program that is too expensive may drive capable suppliers away, but a program with weak verification may leave sensitive defense information exposed.
What Could Change After the 60-Day Review?
The Department has not announced final reforms. However, several parts of the program could be reconsidered.
Different C3PAO Triggers
Third-party certification may be limited to higher-risk contracts, more sensitive CUI environments or specific categories of systems.
More Reciprocity
The Department may consider greater reuse of comparable assessments or certifications to reduce duplicate reviews.
Simplified Requirements for SMBs
Smaller or lower-risk suppliers may receive more scalable implementation, evidence or assessment options.
More Government-Led Verification
The Department may rely more heavily on targeted government assessments instead of requiring every contractor to purchase certification.
Updated Implementation Timelines
The previous four-phase rollout may be extended, replaced or redesigned after the review.
More Technical Validation
The program could reduce narrative paperwork while increasing direct validation of configurations, evidence and security outcomes.
Contractors should wait for official Department guidance before making major architecture, assessment or contract decisions based on speculation.
What Is Not Yet Known?
The 60-day review creates uncertainty because several important decisions have not yet been published.
What Defense Contractors Should Do Right Now
Continue Protecting FCI and CUI
Do not suspend controls, monitoring, incident response, access management, patching, backups or other safeguards required by active contracts.
Review Active Contracts and Solicitations
Identify the specific CMMC level, assessment type, DFARS clauses, SPRS requirements and written customer expectations that currently apply.
Maintain the SSP and Evidence
Keep system boundaries, diagrams, inventories, narratives, policies, configurations, tickets, reviews and training evidence current.
Validate Your Self-Assessment
Make sure the reported score and affirmation are supported by real implementation rather than assumptions or incomplete documentation.
Reevaluate C3PAO Timing
Review whether an outside assessment remains contractually necessary, competitively valuable or financially reasonable during the suspension.
Avoid Unnecessary Compliance Spending
Continue investments that protect CUI, but reconsider rushed purchases or assessment services driven only by the suspended November deadline.
Monitor Official Guidance
Follow Department CIO updates, acquisition guidance, solicitations, contracting-officer instructions and the task force’s reform recommendations.
Does the Suspension Mean You Should Cancel a C3PAO Assessment?
Not automatically. The right decision depends on why the assessment was scheduled.
A contractor may still decide to proceed if a prime contractor or customer requires independent verification, if the company is already fully prepared or if certification creates a meaningful competitive advantage.
A contractor may consider delaying when the assessment was scheduled solely to meet the former November 2026 Phase II date, major readiness gaps remain or assessment costs would strain the business.
Certification Has Business Value
Continue when a customer requires it, readiness is strong or independent verification supports important contract opportunities.
The Deadline Was the Only Reason
Delay may be reasonable when the assessment was driven only by the suspended rollout and no current contract requires it.
Deposits, cancellation provisions, scheduling commitments and work already completed may affect the financial decision.
The Risks of Assuming CMMC Is Going Away
Contractors that interpret the suspension as a complete cancellation may create new contractual and business risks.
! The Requirement May Become Less Bureaucratic, Not Less Serious
The Department may reduce paperwork while increasing direct technical validation, government assessments or enforcement of actual NIST SP 800-171 implementation.
What Happens During the 60-Day Review?
During the review period, the reform task force is expected to examine program cost, acquisition barriers, industry feedback, assessment burden and whether CMMC can be aligned more closely with measurable cybersecurity outcomes.
Contractors should watch for requests for information, implementation memoranda, revised solicitation instructions, acquisition deviations, updated frequently asked questions and the task force’s final recommendations.
The task force report may recommend changes, but those recommendations may still require additional policy, acquisition or regulatory action before becoming permanent.
Phase II Is Suspended
Contractors should review assessment plans, contract requirements and unnecessary deadline-driven expenses.
The Department Studies Reform Options
Industry feedback, small-business impacts and potential alternatives will be evaluated.
Revised Guidance May Follow
The Department may publish a new rollout, altered assessment triggers or other implementation changes.
Frequently Asked Questions
Is CMMC officially going away?
No. The Department suspended Phase II and began a 60-day review. Phase I self-assessment requirements remain in place.
Was CMMC Phase II cancelled?
The transition to Phase II was suspended. Whether it returns in the same form, a revised form or a replacement model is not yet known.
Do Level 1 self-assessments still apply?
Yes. Applicable Level 1 self-assessment and annual affirmation requirements remain part of Phase I.
Do Level 2 self-assessments still apply?
Yes, when specified by the applicable solicitation or contract. Level 2 self-assessments remain part of the current Phase I model.
Do contractors still need NIST SP 800-171?
Yes, when required by DFARS 252.204-7012 and the applicable contract. The Department has said it will continue enforcing NIST SP 800-171 through self-assessments and selected government-led assessments.
Should contractors stop spending on compliance?
No. Continue funding security controls and contractual requirements. Reevaluate optional costs driven only by the suspended Phase II deadline.
Will C3PAO assessments still be required later?
Possibly. The future assessment structure is under review, and the Department has not yet published final reform decisions.
Could the review make CMMC easier for small businesses?
That is one of the stated goals, but the specific cost reductions, exemptions, assessment changes or implementation alternatives are not yet finalized.
The Bottom Line
CMMC is not going away. The Department has paused Phase II and launched a 60-day review of how the program should work.
That review may create meaningful changes for small and medium-sized contractors, including lower costs, narrower C3PAO triggers, greater reciprocity or a more scalable assessment model.
What has not changed is the responsibility to protect FCI and CUI. Phase I self-assessments remain active, NIST SP 800-171 continues to matter, DFARS obligations remain and government-led assessments may continue.
Contractors should use the pause to reduce unnecessary spending, strengthen actual cybersecurity, validate their self-assessments and prepare for a revised program rather than assuming the requirement has disappeared.
Official Sources
Stay Compliant Without Overspending During the Pause
Emgage helps defense contractors understand current requirements, validate self-assessments, maintain SSP and evidence records, reduce unnecessary costs and prepare for the outcome of the 60-day CMMC review.
Review Your CMMC Compliance Path
