Pentagon Suspends CMMC Phase II Rollout
- Read time: 3 mins.
The Department of War has announced the immediate suspension of the planned Phase II rollout of CMMC while it conducts a 60-day review of the certification framework. Phase II was scheduled to begin requiring third-party (C3PAO) assessments for applicable CMMC Level 2 contracts starting November 10, 2026.
DoD Chief Information Officer Kirsten Davies said the review will evaluate the program’s implementation, cost and impact on the Defense Industrial Base, particularly small and medium-sized businesses. In her memo, Davies pointed to Small Business Administration data showing that compliance costs were pushing small and non-traditional companies out of defense contracting rather than protecting them. Under Secretary of War for Acquisition and Sustainment Michael Duffey framed the decision as an effort to maintain a strict security baseline while removing costs that were freezing innovative companies out of the supply chain.
At this time, the Department has not eliminated CMMC or the requirement to safeguard Controlled Unclassified Information (CUI). It has paused the expansion of mandatory third-party certification while it reevaluates the program.
You can read the full announcement here: Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements
What the Suspension of CMMC Phase II Means?
This announcement is significant, and it’s important to understand what has, and has not, changed.
What has changed:
- The planned rollout of mandatory Phase II C3PAO assessments has been suspended pending completion of the Department’s review.
- This was originally set to take effect November 10, 2026.
- Organizations may have additional time before mandatory third-party certification requirements are implemented.
- All pending and future CMMC milestones are paused, not just the Phase II timeline specifically.
What has not changed:
- Organizations handling CUI remain responsible for protecting that information.
- DFARS clause 252.204-7012, which has required NIST SP 800-171 implementation since 2017, remains contractually binding on every defense contractor and subcontractor.
- Phase I self-assessment requirements remain firmly in place. You’re still expected to maintain an up-to-date SPRS score and file an accurate annual affirmation.
- Existing contractual obligations remain in effect unless modified by the contracting agency or prime contractor.
- The Department will continue enforcing NIST SP 800-171 Rev 2 compliance through self-assessments and select government-led assessments during the review period.
To recap: cybersecurity expectations have not gone away. The Department is reviewing the certification process, not the importance of protecting sensitive defense information.
Looking for a CMMC Partner?
Protecting your opportunity for contracts with the DoD means understanding exactly which CMMC requirements apply to you.
How Does This Impact You?
For most, our recommendation is simple: continue implementing and maintaining NIST SP 800-171 compliance.
The work you’ve already completed to improve your cybersecurity posture remains valuable and is required regardless of how the Department ultimately revises the CMMC program. Investments in securing your environment, documenting your practices and protecting CUI continue to reduce organizational risk and prepare you for future contractual requirements.
It's also worth noting that self-attestation carries its own exposure. The Department of Justice's Civil Cyber-Fraud Initiative has pursued multi-million-dollar settlements (under the False Claims Act) against contractors who claimed compliance they didn't actually have, and those cases were built on inaccurate self-assessments, not failed third-party audits. An accurate SPRS score matters as much as ever while third-party verification is on hold.
What If You’re Already Scheduled for a Level 2 Assessment?
Organizations with upcoming C3PAO assessments should carefully evaluate whether proceeding remains the right business decision for their specific circumstances.
Factors to consider include:
- The outcome of the Department’s 60-day review.
- The expectations of your prime contractors and customers.
- Whether future contracts are likely to continue requiring third-party certification.
- Your organization’s current level of implementation and readiness.
For many, obtaining an independent Level 2 certification still provides meaningful value. A successful third-party assessment demonstrates an independently validated cybersecurity program, and will likely differentiate your organization during competitive procurements, providing additional confidence to customers and prime contractors regarding your ability to protect CUI.
Conversely, organizations that haven’t yet committed to an assessment, or that are earlier in their implementation journey, may want to pause long enough to understand the Department’s direction before making a significant financial investment.
Some prime contractors may also continue requiring third-party verification from their own supply chain, regardless of what the current DFARS timeline requires.
As additional information becomes available over the coming weeks, HBS will continue monitoring developments and providing updates.
Have questions about how this announcement affects your compliance efforts, assessment schedule or cybersecurity roadmap? Reach out to us. We’re happy to discuss your specific circumstances and help you determine the most appropriate path forward.
Questions About CMMC? We’re Ready to Help
Frequently Asked Questions
Is CMMC canceled
No. The Department has suspended the rollout of Phase II third-party assessments while it conducts a 60-day review. Phase I self-assessment requirements remain in place, and the underlying NIST SP 800-171 standard is unchanged.
Do I still need to comply with NIST SP 800-171?
Yes. DFARS clause 252.204-7012 has required NIST SP 800-171 implementation since 2017, and this announcement doesn’t touch that clause. The Department will continue enforcing compliance through self-assessments and select government-led assessments during the review period.
What happened to the November 10, 2026 deadline?
That was the date mandatory third-party (C3PAO) assessments were set to begin for applicable Level 2 contracts. That requirement, along with other pending CMMC milestones, is suspended until the Department completes its review.
Should I cancel my scheduled C3PAO assessment?
Not automatically. Talk with your assessor and consider factors like your prime contractor’s expectations, your current level of readiness and whether future contracts are likely to require third-party certification again. For many organizations, an independently verified certification still holds real value.
Does this affect my SPRS score or annual affirmation?
No. Phase I self-assessment requirements are still firmly in place, and an accurate SPRS score and affirmation remain a contractual obligation.
Will my prime contractor still require third-party certification?
Possibly. Some primes may continue requiring C3PAO verification from their supply chain regardless of the federal timeline. Check your existing contract language and flow-down requirements rather than assuming the pause applies to you automatically.
What happens after the 60-day review?
The Department’s CMMC Reform Task Force will deliver recommendations aimed at lowering costs and reducing barriers for small and non-traditional businesses. It’s not yet clear whether or how the third-party assessment requirement will return, so organizations should stay tuned for updates.
Related Content
Stuck In the Middle of CMMC? Here’s How to Get Unstuck
The most common CMMC pitfalls and how the right partner can help you close gaps, reduce risk, and cross the finish line with confidence.
CMMC
Secure your future DoD contracts with HBS’s CMMC certification guidance. Our experienced professionals help you navigate through CMMC requirements efficiently.
CMMC Compliance: An Overview for Your Business
Is your business part of the defense supply chain? Learn what CMMC compliance is, why it matters for contractors and subcontractors, and how to get certified.