Home > Blog > DoW Suspends CMMC Phase II Amid Compliance Review
Compliance

DoW Suspends CMMC Phase II Amid Compliance Review

By whois-secure August 30, 2026 3 views 5 min read

Introduction

On July 13, 2026, the U.S. Department of War (DoW) announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. This decision, detailed in a memorandum signed by DoW Chief Information Officer Kirsten Davies, halts the impending implementation of mandatory third-party assessments and initiates a comprehensive 60-day review of the program. The suspension has significant implications for defense contractors and the broader Defense Industrial Base (DIB), particularly concerning compliance obligations and enforcement risks.

Background on CMMC

The CMMC framework was introduced to enhance the cybersecurity posture of organizations within the DIB by establishing a tiered model of certification levels. CMMC is designed to protect sensitive unclassified information that is shared by the Department of Defense (DoD) with its contractors and subcontractors. Phase I, implemented on November 10, 2025, required contractors to conduct self-assessments and affirmations of their cybersecurity practices. Phase II, originally scheduled to take effect on November 10, 2026, aimed to introduce mandatory third-party assessments to verify compliance with CMMC Level 2 requirements.

The introduction of CMMC was a response to growing concerns about cybersecurity threats and vulnerabilities within the defense supply chain. The framework is based on existing cybersecurity standards, such as the National Institute of Standards and Technology (NIST) Special Publication 800-171, and aims to create a unified standard for implementing cybersecurity across the DIB. The need for such a model became apparent after numerous high-profile cyber breaches, which exposed sensitive defense information and highlighted the gaps in cybersecurity practices among defense contractors.

Details of the Suspension

The suspension of Phase II was formalized through two key memoranda issued by the DoW:

  • Establishment of the CMMC Reform Task Force: This task force is tasked with conducting a 60-day review of the CMMC program to identify areas for improvement and reform. The review will focus on reducing unnecessary costs and complexities, particularly for small and medium-sized businesses within the DIB. The focus on cost reduction is crucial, as smaller contractors have often struggled with the financial burdens of compliance. Stakeholders were invited to submit input on seven key areas, with responses due by August 14, 2026. These areas include cost-effectiveness, scalability, and the impact of the current framework on innovation within the industry. Source
  • Implementation Guidance for Contracting Officers: This memorandum provided instructions on handling active solicitations and existing contracts in light of the suspension. Contracting officers are expected to amend contracts to reflect the suspension of Phase II requirements. This guidance ensures that ongoing projects are not disrupted and provides a clear pathway for resolving any contractual ambiguities that may arise due to the suspension. Source

The decision to suspend Phase II reflects an acknowledgment of the challenges faced by the industry in implementing the CMMC requirements. By pausing the rollout, the DoW aims to gather more comprehensive feedback from stakeholders and refine the program to better serve its intended purpose without imposing undue burdens on contractors.

Implications for Defense Contractors

While the suspension of Phase II delays the requirement for third-party assessments, it does not alleviate existing compliance obligations. Contractors must continue to adhere to the following requirements:

  • Self-Assessments: Organizations are required to perform self-assessments against NIST SP 800-171 Rev 2 standards and maintain accurate Supplier Performance Risk System (SPRS) scores. These self-assessments are crucial for identifying potential vulnerabilities and ensuring that cybersecurity measures are up to date. Source
  • Annual Affirmations: Contractors must submit annual affirmations of their compliance status. This process involves a thorough review of an organization’s cybersecurity practices and ensures ongoing adherence to established standards. Source
  • DFARS 252.204-7012 Compliance: Adherence to the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which includes safeguarding covered defense information and reporting cyber incidents, remains mandatory. This requirement underscores the importance of maintaining robust cybersecurity measures to protect sensitive information. Source

Failure to comply with these obligations can result in significant enforcement risks, including potential liability under the False Claims Act. Contractors must remain vigilant in their cybersecurity efforts, as non-compliance could lead to reputational damage and financial penalties.

The suspension of Phase II also raises questions about the future trajectory of the CMMC program. Contractors are left to ponder whether the eventual implementation will differ significantly from the original plan and how these changes might impact their operations. The uncertainty surrounding the program's future could lead to hesitancy in making long-term investments in cybersecurity infrastructure.

Industry Response and Recommendations

The suspension has elicited mixed reactions within the defense contracting community. While some organizations appreciate the opportunity to provide input and potentially influence the reform of the CMMC program, others express concern over the uncertainty and potential delays in achieving a standardized cybersecurity framework. Industry leaders recognize the importance of a consistent cybersecurity standard but are wary of the disruptions that repeated changes can cause.

Industry experts recommend that contractors:

  • Maintain Vigilance: Continue to implement and monitor cybersecurity practices in line with existing requirements to ensure ongoing compliance. This proactive approach will help contractors stay prepared for any eventual changes to the CMMC framework.
  • Engage in the Review Process: Provide feedback to the CMMC Reform Task Force to help shape the future direction of the program. Engaging with the task force allows contractors to voice their concerns and contribute to a more effective and practical cybersecurity framework.
  • Stay Informed: Monitor official communications from the DoW and other relevant authorities to stay updated on developments related to CMMC and other cybersecurity regulations. Keeping abreast of changes will enable contractors to adapt swiftly to new requirements.

In addition to these recommendations, experts suggest that contractors invest in cybersecurity training for their employees. Human error remains a significant vulnerability in cybersecurity, and training programs can help mitigate risks by educating staff on best practices and potential threats.

Contractors should also consider leveraging technology to enhance their cybersecurity posture. Advanced tools such as automated threat detection systems and artificial intelligence-driven analytics can provide real-time insights into potential security breaches and help organizations respond quickly to incidents.

Conclusion

The DoW's suspension of CMMC Phase II reflects a commitment to refining the program to better serve the needs of the defense industry while maintaining robust cybersecurity standards. Contractors must remain proactive in their compliance efforts and participate in the ongoing review process to ensure that the resulting framework is both effective and practical. By engaging with the CMMC Reform Task Force and staying informed about regulatory developments, contractors can help shape a cybersecurity landscape that balances security requirements with operational feasibility.

As the defense industry continues to evolve in response to emerging threats, the importance of a strong and adaptable cybersecurity framework cannot be overstated. The CMMC program represents a crucial step toward achieving this goal, and its success will depend on the collaboration and commitment of all stakeholders involved.

Tags: CMMC Department of War cybersecurity compliance defense contractors NIST SP 800-171
CyberEdge Learning
Level Up Your Cybersecurity Skills
Liked this article? Go deeper with hands-on training, certification prep, and real-world labs at CyberEdge Learning.
Start Free →