Department of War Suspends CMMC Phase II Requirements

The U.S. Department of Defense and the Small Business Administration announced a temporary pause on Phase II of the Cybersecurity Maturity Model Certification program. The program requires defense contractors to undergo third-party assessments to verify compliance with the 110 cybersecurity requirements outlined in NIST SP 800-171 Rev 2. During the pause, the Pentagon will rely on contractor self-assessments to enforce baseline cybersecurity standards while focusing on tangible cyber hygiene over administrative overhead.

Department of War Suspends CMMC Phase II Requirements
Department of War Suspends CMMC Phase II Requirements

The U.S. Department of War has immediately suspended the planned Phase II rollout of the Cybersecurity Maturity Model Certification program, halting a highly anticipated mandate that would have forced defense contractors to undergo formal third-party audits to win military business.

The decision shifts the military’s immediate enforcement strategy back to contractor self-assessments. Department officials stated the pause is intended to focus on immediate, tangible cyber defense practices while avoiding the administrative delays, limited assessor capacity, and high overhead costs associated with mandatory third-party certification.

The Decision to Halt Phase II Audits

The suspension, announced on July 13, 2026, halts the transition to Phase II of the Cybersecurity Maturity Model Certification (CMMC) program, which was originally scheduled to take effect on November 10, 2026. Under the original timeline, Phase II would have required companies in the defense industrial base (DIB) to hire external, accredited organizations to verify their compliance with federal security guidelines.

With the pause in place, Department of War (DoW) Chief Information Officer Kirsten A. Davies is establishing a CMMC Reform Task Force to conduct a 60-day top-to-bottom review of the certification program. The review aims to align cybersecurity enforcement with Secretary of War Pete Hegseth’s Acquisition Transformation System (ATS) directives, prioritizing acquisition speed, lowering barriers for commercial innovators, and replacing bureaucratic compliance with scalable, resilient security measures.

To implement the suspension, the Department issued agency memoranda directing program managers and contracting officers to amend active solicitations and contracts.

  • Active solicitations containing CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessment requirements must be amended to remove those requirements as soon as practicable.
  • Existing contracts must be modified to remove these requirements prior to the exercise of the next option period or during the next scheduled administrative modification.

Balancing Security Standards and Compliance Costs

At the core of the CMMC program is NIST SP 800-171 Rev 2, a publication from the National Institute of Standards and Technology outlining 110 distinct security requirements. These requirements cover administrative and technical safeguards designed to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI).

To meet these guidelines, defense contractors must implement measures such as:

  • Restricting system access to authorized users
  • Multi-factor authentication across networks
  • Regular vulnerability scanning and system audits
  • Comprehensive incident response plans

While the military has long required contractors to follow these rules, CMMC was designed to transition the industry from an honor-system self-assessment model to a validated, third-party certification model. Under Phase II, contractors handling sensitive data would have been required to secure a formal certification from a Certified Third-Party Assessment Organization (C3PAO).

However, data and feedback from sources including the Small Business Administration (SBA) revealed that the high total cost of preparing for and undergoing these external reviews was creating severe bottlenecks and driving companies out of the defense market. The SBA’s regulatory analysis indicated that total compliance costs—which bundle technical remediation, security tooling, platform migration, documentation, internal labor, and the actual assessment fee—could reach up to $593,800 for a small firm requiring third-party certification. Under Secretary of War for Acquisition and Sustainment Michael Duffey noted that the decision ensures the military maintains a strict security baseline while removing “paralyzing costs” that threaten to freeze innovative small and medium-sized suppliers out of the defense supply chain.

Maintaining the Baseline Through Self-Assessments

The suspension of Phase II does not relieve defense contractors of their underlying security obligations. The Department of War clarified that Phase I of the program, which mandates self-assessments of cybersecurity practices, remains fully in effect.

Contractors must continue to self-certify that they meet the baseline standards of NIST SP 800-171 Rev 2. This process involves an internal review of the company’s network architecture, security policies, and access controls to score compliance before submitting the results to the government’s Supplier Performance Risk System (SPRS).

Federal officials emphasized that during this interim period, the government will rely on these self-assessments alongside select, targeted government-led reviews. All active defense contractors and subcontractors remain bound by DFARS clause 252.204-7012, which legally mandates the protection of covered defense information. Contracting officers may currently only include CMMC Level 1 (Self) or Level 2 (Self) assessment requirements in government contracts.

Topics
  • #Cyber Security
Krishnan

Author

Krishnan

Contributor

Enterprise Technology Explorer is a business and operations professional with over 15 years of experience across multiple industries working with Fortune 500 companies. With a solid foundation in enterprise processes, digital adoption, and technology evaluation, he excels at bridging business needs with emerging technologies to build scalable enterprise-grade applications.