Pentagon Hits Pause on CMMC Phase II
The US Department of Defense has abruptly suspended the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, a move that’s sending ripples through the defense contracting world. The suspension, announced in a July 13 statement, puts the brakes on a program that was slated to take effect on November 10, 2026.
This CMMC Phase II suspension comes after the DoD decided to review the entire program. The goal? To foster more innovation within the US defense industrial base (DIB). It’s a significant pivot from the original rollout plan, which many contractors were scrambling to meet.
What CMMC Phase II Was Supposed to Do
The CMMC program was designed to shore up cyber hygiene for defense contractors and subcontractors who handle federal contract information (FCI) and controlled unclassified information (CUI). Phase I allowed companies to self-report their compliance. Phase II was a different beast entirely.
Under Phase II, contractors working with the military and handling sensitive data would have needed their cybersecurity posture verified by an external party. Specifically, they’d undergo mandatory, independent assessments led by Certified Third-Party Assessment Organizations (C3PAOs). These assessments would verify compliance with the 110 security controls outlined in NIST SP 800-171, a standard from the US National Institute of Standards and Technology (NIST).
The scale was massive. The DoD estimated that between 220,000 and 300,000 companies participate in the DIB, with roughly 80,000 expected to require CMMC Phase II compliance. Yet a CyberSheath report from October 2025 found that only 1% of defense contractors felt fully prepared for these audits.
Phase II was just the middle step. It was to be followed by Phase III (November 2027) and Phase IV (November 2028). Phase III would introduce level 3 audits led directly by the DoD for the most sensitive contracts. Phase IV would have required all DoD contractors and subcontractors to achieve full CMMC compliance.
Why the Pentagon Pulled the Plug
The DoD’s justification for the CMMC Phase II suspension is blunt. The program, they argue, has “created prohibitive compliance costs and bureaucratic burdens” rather than enhancing cybersecurity for DIB firms.
“Recent data, including reports from the Small Business Administration (SBA), confirmed that CMMC compliance is forcing innovative companies out of the DIB which will delay the delivery of critical capabilities to the warfighters,” the department stated.
To address this, the DoD will establish a ‘CMMC Reform Task Force’. This group will conduct a 60-day, top-to-bottom review of the program. The review aims to align CMMC with Secretary of War Pete Hegseth’s acquisition transformation system (ATS) strategy. That includes lowering barriers for small, medium, and non-traditional businesses and “replacing bureaucratic compliance with scalable, resilient cybersecurity measures.”
The department’s CIO, A. Davies, will lead the task force. “Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness. We believe the DIB can achieve both, while we reduce unnecessary government red tape,” Davies said.
What Happens During the Suspension
Don’t think this is a free pass. During the interim period, the DoD will still enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard. Contractors will need to rely on self-assessments and select government-led assessments. The focus, the DoD says, will be on “tangible cyber hygiene rather than administrative overhead.”
In other words, the paperwork burden might ease, but the underlying security expectations haven’t vanished.
Experts Weigh In: Don’t Let Up Now
Security compliance experts have been quick to interpret the sudden suspension. Dave Schroeder, director of National Security Initiatives at the University of Wisconsin Madison, suggested on LinkedIn that the move likely stems from too few contractors being ready to comply by November 10.
Nelina Varenas, a director and founding member of the KDM Consortium, published a LinkedIn article on July 14 with a clear warning: don’t mistake this delay for a relaxation of standards.
“First, as the DoD announcement stated, all CMMC Level 1 self-assessment requirements remain in place,” Varenas noted.
She urged organizations to keep their compliance efforts on track. The suspension, she argues, should be seen as valuable breathing room. It’s a chance to ensure cybersecurity practices are implemented correctly and thoroughly before enforcement potentially resumes. “This is not the time to step back; it’s the time to ensure compliance is done right,” she cautioned.
Practical Advice for Contractors
So, what should you do if you’re a defense contractor? First, don’t halt your NIST SP 800-171 compliance work. The underlying contractual requirements (DFARS 252.204-7012) haven’t changed. Second, use this window to audit your own systems. If you haven’t started, now is the time to get moving.
The future of CMMC is uncertain, but one thing is clear: cybersecurity isn’t going away. The DoD’s review might reshape the program, but the core expectation—that contractors protect sensitive information—remains. For more on navigating these requirements, check out our guide on NIST SP 800-171 compliance steps and how to prepare for CMMC assessments.
Stay informed, stay compliant, and don’t assume the pause means the end of the road. The Pentagon’s review could bring changes, but the direction of travel is unmistakable.