CMMC Phase II Pause: What Defense Contractors Need to Know
The Department of Defense Has Announced It Is Pausing Implementation of CMMC
On July 13, 2026, the Department of Defense announced that it is pausing implementation of CMMC Phase II while it conducts a 60-day review of the program.
Watch the live announcement here: DVIDS – Video – CMMC Phase II Suspended to Boost DIB Innovation
The announcement has generated significant discussion across the Defense Industrial Base (DIB), particularly among organizations preparing for CMMC Level 2 certification and future third-party assessments.
Many contractors are now asking:
- Is CMMC being canceled?
- Does NIST SP 800-171 still apply?
- Should we continue our compliance efforts?
- What happens to planned C3PAO assessments?
- Are DFARS cybersecurity requirements still in effect?
The short answer is No, CMMC has not been canceled. The Department is reviewing the certification and assessment process, not the underlying cybersecurity requirements.
What Changed?
The Department announced that it is pausing the planned implementation of Phase II, which was scheduled to begin on November 10, 2026.
Under the existing implementation schedule, Phase II would have introduced CMMC Level 2 certification requirements for many contractors handling Controlled Unclassified Information (CUI), including assessments conducted by authorized third-party assessment organizations (C3PAOs).
The Department stated that it will use the next 60 days to review the program and evaluate the path forward.
At this time, no replacement assessment model or revised implementation schedule has been announced.
What Has Not Changed?
The most important point for contractors to understand is that the pause does not eliminate existing cybersecurity obligations.
Organizations handling CUI remain responsible for:
- Implementing NIST SP 800-171 security requirements
- Complying with applicable DFARS cybersecurity clauses
- Maintaining required SPRS assessments and scores
- Protecting Controlled Unclassified Information (CUI)
- Protecting Federal Contract Information (FCI) where applicable
The Department has paused the rollout of Phase II certification requirements not the requirement to secure sensitive information.
What About CMMC Level 1?
The announcement does not eliminate CMMC Level 1 requirements.
Organizations subject to CMMC Level 1 requirements should continue following the requirements specified in their contracts, including required self-assessments where applicable.
The pause primarily affects the planned implementation of Phase II certification requirements associated with CMMC Level 2.
What About C3PAO Assessments?
For many contractors, this is the most significant question.
The Department has paused the implementation of Phase II, which would have introduced mandatory third-party CMMC Level 2 assessments for applicable contracts.
At this time, contractors should expect additional guidance following the Department’s review.
The announcement does not state that C3PAO assessments are being eliminated permanently. Rather, the Department is evaluating the program and determining how certification requirements should be implemented going forward.
Organizations that were preparing for a future assessment should closely monitor DoD guidance before making major changes to their compliance plans.
Should Organizations Stop Their Compliance Efforts?
In short: no.
The pause does not change the fact that organizations handling CUI are expected to comply with NIST SP 800-171 and applicable DFARS requirements.
Implementation of security controls, development of documentation, identification and protection of CUI, evidence collection, and overall cybersecurity maturity efforts remain valuable regardless of how the future certification process evolves.
For organizations that have already invested in cybersecurity improvements, policy development, technical safeguards, SSP development, evidence collection, and readiness activities, that work continues to support existing contractual and regulatory obligations.
The underlying security requirements that protect defense information remain in place today.
Why This Matters
The announcement acknowledges concerns regarding the cost, complexity, and implementation challenges associated with the current certification approach, particularly for small and medium-sized businesses within the Defense Industrial Base.
The Department’s review provides an opportunity to evaluate whether adjustments to the certification process can better balance cybersecurity objectives with innovation, competition, and participation across the defense contractor community.
However, the review should not be interpreted as a reduction in cybersecurity expectations.
The Department continues to emphasize the importance of protecting sensitive information and strengthening cybersecurity across the DIB.
What Contractors Should Do Now
Organizations should continue to:
- Implement NIST SP 800-171 controls where required
- Maintain and improve SPRS scores
- Continue identifying and protecting CUI
- Develop and maintain required cybersecurity documentation
- Address known security gaps and deficiencies
- Continue evidence collection and readiness activities
- Monitor future DoD announcements and guidance
- Evaluate the impact of any future changes once additional details are released
Organizations that continue strengthening their cybersecurity programs today will be better positioned regardless of how the future assessment model evolves.
Final Thoughts
The pause of CMMC Phase II is a significant development for defense contractors, particularly those preparing for future C3PAO assessments.
However, the announcement does not eliminate CMMC, NIST SP 800-171, DFARS cybersecurity obligations, SPRS requirements, or the responsibility to protect Controlled Unclassified Information.
What has changed is the implementation timeline for Phase II certification requirements. What has not changed is the Department’s expectation that contractors handling sensitive defense information maintain appropriate cybersecurity protections.
Until additional guidance is released, organizations should view the announcement as a pause in the certification rollout not a pause in cybersecurity compliance.
Cyber Defense Advisors will continue monitoring developments and providing updates as additional guidance becomes available.


Leave feedback about this