Home > Blog > DoW Suspends CMMC Phase II: Implications for Defense Contractors
Compliance

DoW Suspends CMMC Phase II: Implications for Defense Contractors

By whois-secure August 24, 2026 1 views 5 min read

Introduction

On July 13, 2026, the United States Department of War (DoW) announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program, which was slated to take effect on November 10, 2026. This unexpected decision has significant implications for defense contractors and the broader Defense Industrial Base (DIB). While the suspension halts mandatory third-party assessments, it does not alleviate existing cybersecurity obligations. This article delves into the details of the suspension, its impact on contractors, and the steps organizations should take in response.

Background on CMMC

The CMMC program was introduced to enhance the protection of sensitive defense information within the DIB. In recent years, cyber threats have increasingly targeted defense contractors, leading to the need for more stringent cybersecurity measures. The CMMC framework was developed with input from industry experts, cybersecurity professionals, and government officials to establish a unified standard for cybersecurity practices.

The framework consists of five maturity levels, each designed to measure a contractor's ability to protect sensitive information. Phase II was particularly focused on Level 2 and Level 3 contractors, requiring them to undergo third-party assessments to verify compliance with 110 security controls outlined in NIST SP 800-171. These controls cover a variety of security measures, including access control, incident response, and threat detection.

Details of the Suspension

The DoW's suspension of CMMC Phase II was formalized in a memorandum dated July 10, 2026, signed by DoW Chief Information Officer Kirsten Davies. The decision to suspend Phase II and initiate a comprehensive 60-day review underscores the complexity of implementing such a wide-ranging program. The memorandum pauses pending Phase III and Phase IV implementation milestones, reflecting the need to reassess the program's effectiveness.

During the review period, contracting officers have been instructed to amend active solicitations and existing contracts to remove Phase II requirements. This move is intended to reduce the administrative burden on contractors while the program is reassessed. However, Phase I self-assessment obligations remain in place, as do existing requirements under DFARS 252.204-7012, which mandate compliance with NIST SP 800-171 and cyber incident reporting.

The review aims to address concerns raised by industry stakeholders regarding the feasibility and cost of mandatory third-party assessments. It also seeks to ensure that the CMMC framework aligns with the evolving cybersecurity landscape and effectively mitigates risks to the DIB.

Implications for Defense Contractors

While the suspension of Phase II may seem like a reprieve, defense contractors must remain vigilant. The core cybersecurity obligations remain enforceable, including:

  • Self-assessing and attesting to compliance: Contractors are required to conduct regular self-assessments to ensure adherence to applicable cybersecurity controls. This process involves evaluating current security measures, identifying gaps, and implementing necessary improvements.
  • Implementing NIST SP 800-171 controls: The 110 security controls outlined in NIST SP 800-171 are critical to protecting sensitive information. These controls encompass technical measures, such as encryption and multi-factor authentication, as well as organizational practices, like security awareness training.
  • Reporting cyber incidents: Under DFARS 252.204-7012, contractors must report cyber incidents that affect covered defense information. This requirement emphasizes the need for robust incident response plans and timely communication with the DoW.

Failure to adhere to these requirements can result in enforcement actions, including potential liability under the False Claims Act. The Department of Justice has been actively pursuing cases against contractors that misrepresent their cybersecurity compliance. Recent cases highlight the legal and financial repercussions of non-compliance, reinforcing the importance of maintaining robust security practices.

Industry Response and Recommendations

The suspension has elicited mixed reactions within the defense contracting community. While some view it as an opportunity to reassess and streamline compliance efforts, others express concern over the uncertainty it introduces. Industry experts recommend the following actions for contractors:

  • Continue to implement and maintain NIST SP 800-171 controls: Despite the suspension, maintaining compliance with these controls is crucial. Contractors should regularly review and update their cybersecurity practices to address emerging threats and vulnerabilities.
  • Ensure accurate and up-to-date self-assessments: Documenting self-assessments and corrective actions taken is essential for demonstrating compliance. This documentation will be valuable in case of audits or investigations.
  • Stay informed about developments from the CMMC Reform Task Force: The ongoing review may result in changes to the CMMC framework. Contractors should monitor announcements from the DoW and be prepared to adapt to new requirements.
  • Engage with industry associations and provide feedback: Participation in public consultations and collaboration with industry groups can help contractors influence the future direction of the CMMC program. Providing constructive feedback can lead to more practical and effective compliance measures.

By proactively addressing these areas, contractors can mitigate risks and position themselves favorably for future compliance requirements. Additionally, investing in cybersecurity training and awareness programs can enhance the overall security posture of an organization.

Conclusion

The DoW's suspension of CMMC Phase II marks a significant shift in the cybersecurity compliance landscape for defense contractors. While it temporarily halts mandatory third-party assessments, the fundamental obligations to protect sensitive defense information remain unchanged. Contractors must continue to prioritize cybersecurity, ensuring they meet existing requirements and stay prepared for potential changes resulting from the ongoing review of the CMMC program.

The evolving nature of cyber threats necessitates a dynamic and adaptive approach to cybersecurity. By staying informed and engaged, defense contractors can not only ensure compliance but also enhance their resilience against cyber attacks. The future success of the CMMC program will depend on its ability to balance stringent security standards with practical implementation strategies.

For more detailed information, refer to the following sources:

Tags: CMMC Department of War cybersecurity compliance defense contractors NIST SP 800-171
CyberEdge Learning
Level Up Your Cybersecurity Skills
Liked this article? Go deeper with hands-on training, certification prep, and real-world labs at CyberEdge Learning.
Start Free →