DOD Suspends Implementation of CMMC Phase 2 

July 21, 2026

On July 13, 2026, the Department of Defense (formerly the Department of War, DOD) announced via press release (the Release) that it was immediately suspending the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were set to commence on November 10, 2026. The present Phase I self-assessment obligations remain in place. As a reminder, the CMMC program establishes a framework for verifying that contractors have implemented cybersecurity controls to safeguard covered defense information, including CUI, in accordance with the requirements of DFARS 252.204-7012. The Phase I approach focused on verification requirements through contractor self-assessment, while Phase II would have required many contractors to undergo a burdensome review of the controls implementation through a Third-Party Assessment Organization (C3PAO).

Per the Release, the DOD will commence a full review of the CMMC requirements in order to align with DOD’s Acquisition Transformation System (ATS) directives so that it better prioritizes speed of capability, lowers barriers to small and medium-sized companies, and reduces bureaucratic compliance with a “scalable, resilient cybersecurity” set of measures. The Release discusses that CMMC was designed to enhance cybersecurity in the Defense Industrial Base, but instead “…created prohibitive compliance costs and bureaucratic burdens.” The Release cited Small Business Administration reports that confirmed that CMMC compliance is driving small innovative companies out of the defense sector, which, in turn, delays delivery of critical capacities to warfighters. The DOD will create a CMMC Reform Task Force to perform a fulsome review of the certification program, including seeking information from the public. It is expected that this will be performed within 60 days, which we anticipate will take quite a bit longer. The Release concludes that “[i]t is critical to note that this action does not eliminate the requirement for companies to protect federal data…” and that all DOD prime and subcontractors are contractually obligated to protect covered defense information per DFARS 252.204-7012. The Release affirms that in the meantime, DOD will continue enforcement of cybersecurity compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments.

BOTTOM LINE

As we have observed in the past, while the CMMC is a necessary program, the cost and time to implement the more advanced phases of the program have proven to be challenging. The lack of available C3PAOs needed to assess compliance has wreaked havoc on the ability of contractors to meet their obligations and comply with contracts, or in many cases, obtain the certification in a timely fashion to allow them to bid on solicitations. This lack of “supply” has resulted in cost increases to get timely review and certification. Hopefully, the DOD will make changes to the CMMC to allow its needs to be met while making the program feasible and efficient. Only time will tell whether the DOD makes changes, and if so, whether those changes will be practical and “contractor friendly.”

Share on LinkedIn

Authors

Eric Leonard

Co-Chair, Government Contracts

eleonard@cozen.com

(202) 280-6536

Lawrence M. Prosen

Co-Chair, Government Contracts

lprosen@cozen.com

(202) 304-1449

Kristina Zaslavskaya

Associate

kzaslavskaya@cozen.com

(202) 280-6460

Related Practices