The U.S. Department of War (DoW) announced on July 13, 2026, that it is suspending Phase II requirements of its Cybersecurity Maturity Model Certification (CMMC) initiative. The requirements were scheduled to take effect on November 10, 2026. The DoW also established a CMMC Reform Task Force to conduct a 60-day review of the certification program.1
The announcement changes the CMMC implementation timeline, but it does not change the cybersecurity responsibilities defense contractors and subcontractors may have under existing agreements. Organizations should review their contractual requirements and continue protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Organizations can use this time to reassess priorities, validate their current cybersecurity posture, and determine which activities should continue while the program is under review.
What the Suspension Covers
The DoW suspended the CMMC Phase II transition, as well as pending and future Phase II implementation milestones across its solicitations and contracts. It is important to note that all Phase I self-assessment requirements remain in place.2
Implementation guidance issued with the announcement states that, during the suspension, procurement requirements may call for CMMC Level 1 or Level 2 self-assessments. The DoW will enforce baseline compliance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2 through self-assessments and select government-led assessments.3
Organizations with a Certified Third-Party Assessment Organization (C3PAO) assessment scheduled or under consideration should review the latest guidance before deciding whether to adjust their plans.
Contractual Cybersecurity Requirements Remain in Effect
The suspension applies to part of the CMMC certification rollout. It does not, by itself, change the security requirements included in an organization’s contracts. Those responsibilities will depend on the applicable agreements, the information the organization handles, and the systems that process, store, or transmit that information.
Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 addresses safeguarding covered defense information and cyber incident reporting. The DoW’s implementation guidance confirms that the cybersecurity requirements in this clause remain in effect during the CMMC Phase II suspension. The related DFARS framework also includes NIST SP 800-171 assessment provisions in solicitations and contracts, subject to applicable exceptions.4
Organizations should review the requirements that apply to their specific contracts and environments.
Four Actions to Consider Now
The review period gives organizations an opportunity to firm up their cybersecurity posture with greater discipline. Priorities may include the following:
- Review current contracts and solicitations. Identify applicable DFARS clauses, assessment requirements, and information-protection responsibilities.
- Confirm the scope of the environment. Identify where FCI and CUI are processed, stored, or transmitted and which people, systems, and service providers support that environment. Take particular care with CUI scope, foreign-person access, and enclave boundaries.
- Revisit the NIST SP 800-171 self-assessment. Consider whether conclusions are supported by current evidence and accurately reflect how controls operate. Work toward a full score of 110 points and close documented gaps within the time frame reflected in your Plan of Action and Milestones (POA&M).
- Address known gaps. Continue remediation efforts that support contractual compliance and reduce risk, particularly for weaknesses documented in a System Security Plan (SSP), POA&M, or prior assessment.
Organizations also should monitor their Supplier Performance Risk System information and related representations for accuracy. A score or documented position should reflect current conditions rather than an earlier stage of the cybersecurity program.
Preparing for an Uncertain Outcome
The review period could lead to changes in certification requirements or future CMMC implementation. The DoW has not yet stated what the redesigned program will require, so contractors should avoid making assumptions about the forthcoming outcome.
Possibilities discussed during the review period will likely include a delay of Phase II beyond the initial window, a narrower definition of which organizations require third-party assessment, prioritization of specific CUI categories or contract types, and an eventual move from NIST SP 800-171 Revision 2 to Revision 3.
Organizations can, however, make informed decisions using the requirements and risks they understand today. Pausing initiatives could allow known weaknesses to remain unresolved. Continuing specific activity without reconsidering its purpose could direct time and resources toward a timeline that has changed.
The suspension provides additional time, but strong preparation remains valuable. Organizations that maintain a clear understanding of their environments and cybersecurity responsibilities will be better positioned to respond when the DoW completes its review and provides further direction.
How Forvis Mazars Can Help
IT Risk & Compliance professionals at Forvis Mazars can help organizations respond to evolving CMMC requirements. Our professionals also can assist organizations with reviewing their cybersecurity readiness, assessing SSP and POA&M documentation, and prioritizing remediation efforts. Connect with us today to ask your questions regarding CMMC.
- 1“Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” war.gov, July 13, 2026.
- 2Ibid.
- 3“ImplementingSuspensionCMMC-PhaseII.pdf,” dowcio.war.gov, July 13, 2026.
- 4“252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting,” acquisition.gov, May 7, 2026.