CMMC 2.0 Phase II Suspended: Third-Party Certification Paused, but Cybersecurity Obligations Remain

CMMC 2.0 Phase II suspended cybersecurity update graphic with shield and lock highlighting continued NIST SP 800-171 and defense contractor compliance requirements.

On July 13, 2026, the Department of War announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (“CMMC”) program, which had been scheduled to begin on November 10, 2026. The Department also paused future CMMC implementation milestones while a task force conducts a 60-day review of the program.

Recommended Actions

  • Contractors should review their current contracts and solicitations before changing planned certification activities.
  • Confirm whether they handle FCI, CUI, or covered defense information and maintain proper markings.
  • Validate their NIST SP 800-171 implementation and SPRS score.
  • Update SSPs and POA&Ms
  • Ensure self-assessments are supported by documentation.

What Will the Government Do

During the suspension, government program offices may require only:

  • CMMC Level 1 (Self) for systems handling Federal Contract Information (“FCI”); or
  • CMMC Level 2 (Self) for systems handling Controlled Unclassified Information (“CUI”).

Program offices may not designate CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC) assessments during this period. Active solicitations containing those requirements are expected to be amended, and contracting officers have been directed to remove them from existing contracts through upcoming modifications or option exercises.

Importantly, this action is a suspension and program review—not yet a formal repeal of CMMC 2.0, 32 C.F.R. Part 170, or the applicable DFARS clauses.

What Contractors Must Still Do

The suspension does not eliminate contractors’ underlying cybersecurity obligations. Depending on the contract and the information involved, contractors and subcontractors must continue to:

  • Protect FCI using the basic safeguards in FAR 52.204-21.
  • Implement NIST SP 800-171 Revision 2 for covered contractor systems handling CUI or covered defense information under DFARS 252.204-7012.
  • Maintain an accurate System Security Plan and appropriate Plans of Action and Milestones.
  • Maintain a current NIST SP 800-171 DoD Assessment score in the Supplier Performance Risk System (“SPRS”) under DFARS 252.204-7019 and 252.204-7020.
  • Complete applicable CMMC Level 1 or Level 2 self-assessments and annual affirmations of continued compliance in SPRS.
  • Report covered cyber incidents to DoD within 72 hours, preserve relevant system images and monitoring data for at least 90 days, and cooperate with government forensic reviews.

Why Continued CMMC Readiness Matters

False Claims Act risk. The government is returning to reliance on contractor self-assessment and affirmation to confirm compliance with NIST 800-171 requirements. Contractors who submit a self-attested score also affirm that such claims are truthful. The Department of Justice pursues False Claims Act matters involving NIST 800-171 fraud.

Prime-contractor and subcontract eligibility. Prime contractors must continue flowing down applicable DFARS cybersecurity clauses and may not award a covered subcontract unless the subcontractor has completed a current Basic NIST SP 800-171 DoD Assessment.

Future requirements. The current suspension is temporary, and further guidance is expected after the Department’s review. Companies that stop implementation entirely may face significant remediation costs, lost subcontracting opportunities, or an inability to respond quickly when revised requirements are issued.

National security. Cyber risk remains a vulnerability to the national security of the U.S. Contractors who fail to adequately protect their systems may be disqualified from future contracts, affect eligible awards, trigger contractual remedies, or jeopardize continued performance. Contractors also risk losing valuable intellectual property to malicious actors.

The opinions expressed are those of the author(s) and do not necessarily reflect the views of their employer, its clients, or Portfolio Media Inc., or any of its or their respective affiliates. This article is for general information purposes and is not intended to be and should not be taken as legal advice.