• Events and Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
  • Events and Webinars
  • Resources
    • Blog
    • Case Studies
    • News
    • Newsletter
    • Infographics
    • Papers
    • Posters
    • Video
  • Careers
    • Careers at HBS
    • Open Positions
    • Student Opportunities
  • About HBS
    • About Us
    • Leadership
    • Locations
    • Partners
    • Green Initiatives
HBS logo
HBS Logo
  • Infrastructure
    • CLOUD

      • Cloud Solutions
      • Public Cloud
      • Hybrid Cloud
      • Infrastructure as a Service
      • Cloud Security Solutions
      • Backup, Replication and Disaster Recovery
      • HBS Cloud Hosting Services

      DATA CENTER

      • Data Center Solutions
      • Traditional Data Center
      • Hyperconverged
      • Colocation
      • Directory Services
      • Cloud Email and Calendar Solutions

      NETWORK AND ACCESS

      • Network Infrastructure
      • Enterprise Mobility
      • Wireless Solutions
      • SD-WAN
      • Structured Cabling
      • Staff Augmentation
      Data Center Solutions blue gradient background badge with white text
  • Managed Services
    • MANAGED ONE

      • Managed One Overview
      • Managed Backup and Disaster Recovery
      • Managed Email and Collaboration Security
      • Managed Firewall

       

      • Managed HaaS and SaaS
      • Managed IT Help Desk
      • Managed Network and Server Monitoring

      HBS + PARTNER SOLUTIONS

      • HBS Secure with Verkada
      • HBS Collaborate with Webex
      • Managed XDR
      HBS Managed One Megamenu Graphic
  • Modern Workplace
    • MICROSOFT

      • Microsoft Licensing Management
      • Microsoft Modern Workplace
      • Microsoft Copilot
      • Microsoft Fabric
      • Microsoft Funding Opportunities

       

      • Dynamics 365 Business Central
      • Dynamics 365
      • Dynamics GP

      COLLABORATION

      • Audio Visual
      • Unified Communication Solutions
      • HBS Collaborate with Webex
      HBS Collaborate with Webex blue gradient background badge
  • Professional Services
    • ADVISORY

      • Virtual CISO
      • Virtual CIO
      • Project Management
      • IT Business Consulting

      ENGINEERING SERVICES

      • Staff Augmentation

      AI & ANALYTICS

      • Artificial Intelligence
      • AI Advance
      • AI Predict
      • AI Assist
      • Data Management and Analytics
      • Microsoft Copilot
      • Microsoft Fabric

      APPLICATION INNOVATION

      • Website Development
      • Application Development

      DOCUMENT MANAGEMENT

      • Document Management Services
      • Document and Check Scanners
      Discover your AI Readiness blue gradient background with white text. Bottom right photo of young man in glasses smiling while looking at laptop. Red to green temperature gauge png
  • Security
    • CYBERSECURITY

      • Managed XDR
      • Penetration Testing
      • Vulnerability Scanning
      • Email Security Services
      • Digital Forensics and Incident Response
      • Backup, Replication and Disaster Recovery
      • Firewalls
      • Cloud Security Solutions

       

      • Virtual CISO
      • Virtual Security Team
      • Virtual Security Engineer
      • Cybersecurity Risk Assessment
      • Governance and Compliance
      • SOC 2
      • CMMC
      • Managed Security Awareness Training

      PHYSICAL SECURITY

      • Security Solutions
      • HBS Secure with Verkada
      Cybersecurity Risk Assessment Megamenu Graphic
  • Search
Contact Us
Blog

Pentagon Suspends CMMC Phase II Rollout

  • July 15, 2026
  • Read time: 3 mins.
Soldiers in camouflage uniforms typing on laptops at a desk, close-up of hands on keyboard.

The Department of War has announced the immediate suspension of the planned Phase II rollout of CMMC while it conducts a 60-day review of the certification framework. Phase II was scheduled to begin requiring third-party (C3PAO) assessments for applicable CMMC Level 2 contracts starting November 10, 2026.

DoD Chief Information Officer Kirsten Davies said the review will evaluate the program’s implementation, cost and impact on the Defense Industrial Base, particularly small and medium-sized businesses. In her memo, Davies pointed to Small Business Administration data showing that compliance costs were pushing small and non-traditional companies out of defense contracting rather than protecting them. Under Secretary of War for Acquisition and Sustainment Michael Duffey framed the decision as an effort to maintain a strict security baseline while removing costs that were freezing innovative companies out of the supply chain.

At this time, the Department has not eliminated CMMC or the requirement to safeguard Controlled Unclassified Information (CUI). It has paused the expansion of mandatory third-party certification while it reevaluates the program.

You can read the full announcement here: Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements

What the Suspension of CMMC Phase II Means?

This announcement is significant, and it’s important to understand what has, and has not, changed.

What has changed:

  • The planned rollout of mandatory Phase II C3PAO assessments has been suspended pending completion of the Department’s review.
  • This was originally set to take effect November 10, 2026.
  • Organizations may have additional time before mandatory third-party certification requirements are implemented.
  • All pending and future CMMC milestones are paused, not just the Phase II timeline specifically.

What has not changed:

  • Organizations handling CUI remain responsible for protecting that information.
  • DFARS clause 252.204-7012, which has required NIST SP 800-171 implementation since 2017, remains contractually binding on every defense contractor and subcontractor.
  • Phase I self-assessment requirements remain firmly in place. You’re still expected to maintain an up-to-date SPRS score and file an accurate annual affirmation.
  • Existing contractual obligations remain in effect unless modified by the contracting agency or prime contractor.
  • The Department will continue enforcing NIST SP 800-171 Rev 2 compliance through self-assessments and select government-led assessments during the review period.

To recap: cybersecurity expectations have not gone away. The Department is reviewing the certification process, not the importance of protecting sensitive defense information.

Looking for a CMMC Partner?

Protecting your opportunity for contracts with the DoD means understanding exactly which CMMC requirements apply to you.

CMMC Certification
Read More »

How Does This Impact You?

For most, our recommendation is simple: continue implementing and maintaining NIST SP 800-171 compliance.

The work you’ve already completed to improve your cybersecurity posture remains valuable and is required regardless of how the Department ultimately revises the CMMC program. Investments in securing your environment, documenting your practices and protecting CUI continue to reduce organizational risk and prepare you for future contractual requirements.

It's also worth noting that self-attestation carries its own exposure. The Department of Justice's Civil Cyber-Fraud Initiative has pursued multi-million-dollar settlements (under the False Claims Act) against contractors who claimed compliance they didn't actually have, and those cases were built on inaccurate self-assessments, not failed third-party audits. An accurate SPRS score matters as much as ever while third-party verification is on hold.

What If You’re Already Scheduled for a Level 2 Assessment?

Organizations with upcoming C3PAO assessments should carefully evaluate whether proceeding remains the right business decision for their specific circumstances.

Factors to consider include:

  • The outcome of the Department’s 60-day review.
  • The expectations of your prime contractors and customers.
  • Whether future contracts are likely to continue requiring third-party certification.
  • Your organization’s current level of implementation and readiness.

For many, obtaining an independent Level 2 certification still provides meaningful value. A successful third-party assessment demonstrates an independently validated cybersecurity program, and will likely differentiate your organization during competitive procurements, providing additional confidence to customers and prime contractors regarding your ability to protect CUI.

Conversely, organizations that haven’t yet committed to an assessment, or that are earlier in their implementation journey, may want to pause long enough to understand the Department’s direction before making a significant financial investment.

Some prime contractors may also continue requiring third-party verification from their own supply chain, regardless of what the current DFARS timeline requires.

As additional information becomes available over the coming weeks, HBS will continue monitoring developments and providing updates.

Have questions about how this announcement affects your compliance efforts, assessment schedule or cybersecurity roadmap? Reach out to us. We’re happy to discuss your specific circumstances and help you determine the most appropriate path forward.

Questions About CMMC? We’re Ready to Help

Frequently Asked Questions

Is CMMC canceled

No. The Department has suspended the rollout of Phase II third-party assessments while it conducts a 60-day review. Phase I self-assessment requirements remain in place, and the underlying NIST SP 800-171 standard is unchanged.

Do I still need to comply with NIST SP 800-171?

Yes. DFARS clause 252.204-7012 has required NIST SP 800-171 implementation since 2017, and this announcement doesn’t touch that clause. The Department will continue enforcing compliance through self-assessments and select government-led assessments during the review period.

What happened to the November 10, 2026 deadline?

That was the date mandatory third-party (C3PAO) assessments were set to begin for applicable Level 2 contracts. That requirement, along with other pending CMMC milestones, is suspended until the Department completes its review.

Should I cancel my scheduled C3PAO assessment?

Not automatically. Talk with your assessor and consider factors like your prime contractor’s expectations, your current level of readiness and whether future contracts are likely to require third-party certification again. For many organizations, an independently verified certification still holds real value.

Does this affect my SPRS score or annual affirmation?

No. Phase I self-assessment requirements are still firmly in place, and an accurate SPRS score and affirmation remain a contractual obligation.

Will my prime contractor still require third-party certification?

Possibly. Some primes may continue requiring C3PAO verification from their supply chain regardless of the federal timeline. Check your existing contract language and flow-down requirements rather than assuming the pause applies to you automatically.

What happens after the 60-day review?

The Department’s CMMC Reform Task Force will deliver recommendations aimed at lowering costs and reducing barriers for small and non-traditional businesses. It’s not yet clear whether or how the third-party assessment requirement will return, so organizations should stay tuned for updates.

Related Content

CMMC get unstuck

Stuck In the Middle of CMMC? Here’s How to Get Unstuck

The most common CMMC pitfalls and how the right partner can help you close gaps, reduce risk, and cross the finish line with confidence.

Learn More »
CMMC Certification

CMMC

Secure your future DoD contracts with HBS’s CMMC certification guidance. Our experienced professionals help you navigate through CMMC requirements efficiently.

Explore More »
CMMC Compliance How to Get Started

CMMC Compliance: An Overview for Your Business

Is your business part of the defense supply chain? Learn what CMMC compliance is, why it matters for contractors and subcontractors, and how to get certified.

Start Here »
  • CMMC, Compliance, Cybersecurity, Policies
Blog

Connect:

[email protected]  |  800.236.7914

HBS logo

HQ | 1700 Stephen Street
Little Chute, WI 54140
Locations

HBS Remote Support | Service & Technical Support | E-Bill Portal
Standard Terms & Conditions | Cookie Policy | Privacy Policy | Onboarding Form | End User Agreements | E-Bill FAQ | Site Map
Any purchase is governed by the HBS Standard Terms and Conditions.
©2026 Heartland Business Systems. All rights reserved.

Halo from HBS
This chat may be recorded as described in our Privacy Policy.