
The Pentagon suspended Phase 2 of its Cybersecurity Maturity Model Certification (CMMC) program on July 13, 2026. Phase 2 was scheduled to start November 10, 2026. It would have made a third-party CMMC Level 2 certification a condition of award for many defense contracts involving Controlled Unclassified Information (CUI), according to an analysis by the law firm WilmerHale.
The pause does not mean CMMC is gone. Contractors still have to meet the cybersecurity requirements already in their contracts, and the self-assessment phase that began in November 2025 remains in effect.
What changed
Federal News Network reported that the Pentagon cited "severe shortages in third-party assessment capacity" compared with the roughly 80,000 companies that would eventually need an assessment, along with "prohibitive compliance costs" that were pushing small businesses away from defense work. All pending and future CMMC milestones were suspended along with Phase 2.
A new CMMC Reform Task Force was given 60 days for a top-to-bottom review, and the department asked industry for input through a public request for information.
What did not change
WilmerHale notes that "All Phase I self-assessment requirements remain firmly in place." Phase 1 began on November 10, 2025, when the Defense Department's rule adding CMMC to contract clauses took effect. That rule was published in the Federal Register on September 10, 2025.
According to Covington & Burling, contractors must still:
- Self-assess against the requirements for their CMMC level, including the NIST SP 800-171 Rev. 2 controls for Level 2.
- Keep a current assessment status and affirmation in the Supplier Performance Risk System (SPRS) to be eligible for award.
- Comply with DFARS clause 252.204-7012, which covers safeguarding defense information and reporting cyber incidents.
During the pause, the department says it will enforce the standard through self-assessments and selected government-led assessments.
Where the review stands
The task force report was due to the department's chief information officer on September 11, 2026, and had not been made public as of September 21, according to Covington. The request for information drew more than 1,100 responses.
Speaking on September 9, CIO Kirsten Davies said more than half of the respondents favored the pause, DefenseScoop reported. She also said "CMMC was hitting small to medium-sized businesses really, really hard and inappropriately hard," and that the department wants to move away from point-in-time assessments toward ongoing compliance.
A quick refresher on the levels
The CMMC program rule, published October 15, 2024 and effective December 16, 2024, sets three levels:
- Level 1: the 15 basic security requirements in FAR clause 52.204-21, for companies handling Federal Contract Information. Self-assessment.
- Level 2: the 110 security requirements of NIST SP 800-171 Rev. 2, for companies handling CUI. Self-assessment or a third-party assessment, depending on the contract.
- Level 3: 24 additional requirements drawn from NIST SP 800-172, assessed by the government.
What to do now
- Keep your SPRS assessment status and affirmation current. It is still a condition of award.
- Close any remaining NIST SP 800-171 gaps and keep records that back up your self-assessment.
- Make sure you can meet the DFARS 252.204-7012 incident reporting duty, including who reports and how.
- Decide whether to keep a third-party assessment on your calendar. Covington notes that some contractors may benefit from pursuing one even while it is not required.
- Watch for the task force report, which could change both the timeline and the assessment model.
If you need help closing NIST SP 800-171 gaps, WITTCO can handle the technical side, from endpoint protection and patching to backups and Microsoft 365 security settings.
Sources
- Federal News Network, "Pentagon suspends CMMC phase two requirements, launches review of program" (July 13, 2026): https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/
- WilmerHale, "Pentagon Suspends CMMC Phase 2 Requirements and Launches Review of Cybersecurity Certification Program" (July 20, 2026): https://www.wilmerhale.com/en/insights/client-alerts/20260720-pentagon-suspends-cmmc-phase-2-requirements-and-launches-review-of-cybersecurity-certification-program
- Covington & Burling, Inside Government Contracts, "CMMC Reform Task Force Updates September 2026" (September 21, 2026): https://www.insidegovernmentcontracts.com/2026/09/cmmc-reform-task-force-updates-september-2026/
- DefenseScoop, "Pentagon pores over heaps of industry feedback on CMMC reform" (September 9, 2026): https://defensescoop.com/2026/09/09/pentagon-pores-over-heaps-of-industry-feedback-on-cmmc-reform/
- Federal Register, "Defense Federal Acquisition Regulation Supplement: Assessing Contractor Implementation of Cybersecurity Requirements (DFARS Case 2019-D041)" (September 10, 2025): https://www.govinfo.gov/content/pkg/FR-2025-09-10/html/2025-17359.htm
- Federal Register, "Cybersecurity Maturity Model Certification (CMMC) Program; Final Rule" (October 15, 2024): https://www.govinfo.gov/content/pkg/FR-2024-10-15/html/2024-22905.htm


