Insights/CMMC Phase 2 Suspension
CMMC News

CMMC Phase 2 Is Suspended: What It Means for Small Defense Contractors

Updated:

On July 13, 2026, the Department of War (DoW, formerly DoD) suspended the move to CMMC Phase 2, which was due to start on November 10, 2026. Phase 2 would have made third-party (C3PAO) Level 2 certification a condition of award on many contracts. For now, new requirements may only call for Level 1 (Self) or Level 2 (Self). The cybersecurity rules themselves have not gone away. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 still apply. A CMMC Reform Task Force has been reviewing the program, and its report is expected about now. As of October 2, 2026, the DoW CIO’s CMMC page still describes Phase 2 as suspended.

What happened

Who is affected

What to do now

  1. Keep your SPRS entry current. Self-assessments and affirmations are still how the DoW checks compliance during the suspension. Confirm that your score, dates and affirming official are up to date.
  2. Keep working on NIST SP 800-171 Rev 2. DFARS 252.204-7012 is still in effect, and government-led assessments can still happen. Keep your System Security Plan and POA&M accurate.
  3. Watch your solicitations and contracts. If a bid or contract asked for Level 2 (C3PAO) or Level 3, look for an amendment or modification that removes that requirement.
  4. Don’t throw away certification prep. The work behind a C3PAO assessment (scoping, SSP, evidence) is the same work that backs a Level 2 self-assessment. Whether to certify now or wait is a business decision. Make it with your primes’ expectations in mind.
  5. Talk to your primes. Ask what they will flow down to subcontractors while the review continues, and get the answer in writing.

Key dates to watch

How Galaxy can help

Galaxy Consulting is a service-disabled veteran-owned small business and a Cyber-AB Registered Provider Organization. We help small defense contractors keep their NIST SP 800-171 work on track while the rules settle: gap assessments, SSP and POA&M documentation, and SPRS self-assessment support. When certification is required again, you’ll be ready. Read more about CMMC Level 2 and Level 1, or see our CMMC services to set up a short discovery call.

This article is general information, not legal advice. Check your own contract terms with your contracting officer or counsel.

Sources (all accessed October 2, 2026)

  1. Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” press release, July 13, 2026. https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/
  2. DoW CIO Kirsten A. Davies, memo “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of CMMC Requirements” (cleared July 13, 2026). https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf
  3. Under Secretary of War (A&S) Michael P. Duffey, memo “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to CMMC Phase 2 Requirements,” July 13, 2026, with Attachment 1. https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf
  4. DoW CIO, Cybersecurity Maturity Model Certification page. https://dodcio.defense.gov/CMMC/
  5. DoD, “Cybersecurity Maturity Model Certification (CMMC) Program,” final rule, 89 FR, October 15, 2024 (32 CFR Part 170). https://www.federalregister.gov/documents/2024/10/15/2024-22905/cybersecurity-maturity-model-certification-cmmc-program
  6. DoD, “DFARS: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041),” final rule, September 10, 2025, effective November 10, 2025. https://www.federalregister.gov/documents/2025/09/10/2025-17359/defense-federal-acquisition-regulation-supplement-assessing-contractor-implementation-of
  7. eCFR, 32 CFR 170.3, 170.15 and 170.16 (current text). https://www.ecfr.gov/current/title-32/part-170/section-170.3 · https://www.ecfr.gov/current/title-32/part-170/section-170.15 · https://www.ecfr.gov/current/title-32/part-170/section-170.16
  8. The Cyber AB, “Statement on the Department of War’s Suspension of CMMC Phase II Requirements,” July 15, 2026. https://cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements
  9. The Cyber AB, response to the DoW “Reforming CMMC and Reducing Compliance Burden” RFI, August 14, 2026. https://cyberab.org/News-Events/Press-Releases/the-cyber-abs-response-to-the-dows-reforming-cmmc-and-reducing-compliance-burden-rfi
  10. DefenseScoop, “Pentagon task force to review CMMC hits the ground running,” July 17, 2026. https://defensescoop.com/2026/07/17/pentagon-task-force-to-review-cmmc-hits-the-ground-running/
  11. DefenseScoop, “Pentagon pores over heaps of industry feedback on CMMC reform,” September 9, 2026. https://defensescoop.com/2026/09/09/pentagon-pores-over-heaps-of-industry-feedback-on-cmmc-reform/
  12. Federal News Network, “As the Pentagon rethinks CMMC, cybersecurity isn’t pausing,” September 15, 2026. https://federalnewsnetwork.com/cybersecurity/2026/09/as-the-pentagon-rethinks-cmmc-cybersecurity-isnt-pausing/