NEWS

What the Suspension of CMMC Phase II Means for Government Contractors

July 17, 2026

 

The Department of War has announced that it is suspending the implementation of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had been scheduled to take effect on November 10, 2026. 

For businesses pursuing Department of War contracts, this means additional time before CMMC Phase II certification requirements are implemented while the Department reviews the program. The review is intended to identify ways to maintain strong cybersecurity while reducing barriers for small, medium-sized, and non-traditional businesses. 

What Changed? 

The Department has paused the rollout of CMMC Phase II certification requirements and launched a 60-day review of the program. According to the announcement, the review will examine how cybersecurity requirements can better protect sensitive information while making it easier for companies to compete for defense work. 

As Chief Information Officer Kirsten A. Davies stated, the Department is seeking to “reduce compliance barriers for small and medium sized businesses” while maintaining strong cybersecurity protections. 

What Hasn’t Changed? 

While the certification timeline has changed, existing cybersecurity requirements remain in effect. 

Defense contractors and subcontractors are still responsible for: 

  • Completing required CMMC Phase I self-assessments, where applicable. 
  • Meeting the security requirements outlined in NIST SP 800-171 Rev. 2 through self-assessments and, in some cases, government-led assessments. 
  • Protecting Covered Defense Information (CDI) in accordance with DFARS 252.204-7012. 

What Should Contractors Do Now? 

Businesses should view this announcement as an opportunity to strengthen their cybersecurity programs—not pause them. 

Now is a good time to: 

  • Continue implementing and documenting NIST SP 800-171 security controls. 
  • Complete required self-assessments and address any identified gaps. 
  • Keep policies, procedures, and cybersecurity documentation up to date. 
  • Stay informed as the Department releases additional guidance following its 60-day review. 

Strong cybersecurity remains essential for organizations that want to compete for federal defense contracts, regardless of when Phase II requirements are finalized. 

UCEDC’s APEX Accelerator will continue monitoring developments and sharing updates that help government contractors understand evolving requirements. If you have questions about how these changes may affect your business, our team is here to help. 

 

Source: Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” July 13, 2026 

 


Disclaimer 

This APEX Accelerator program is funded in part through a cooperative agreement with the Department of Defense and partially funded by the County of Union, New Jersey. The information provided is for educational purposes only and does not guarantee contracting opportunities or awards.