The Department of Defense (“DOD”) has announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were scheduled to take effect on November 10, 2026. This announcement is significant because, as we noted in our prior advisory, Phase II was expected to move CMMC toward more formal assessment requirements for many defense contractors and subcontractors. But the suspension of Phase II should not be read as a suspension of defense contractors’ underlying cybersecurity obligations. The DOD has made clear that Phase I self-assessment requirements remain in place, and that during the interim period, it will enforce compliance with NIST SP 800-171 Rev. 2 through self-assessments and selected government assessments.
The announcement marks a meaningful pause in the CMMC rollout, not a wholesale retreat from cybersecurity oversight. The DOD’s new announcement changes the near-term timing and mechanics of the CMMC compliance framework, especially for Certified Third-Party Assessor Organization (C3PAO) and Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) assessments, but other obligations to protect federal data, including Level 1, remain in place.
Key Takeaways
- Do not pause core cybersecurity compliance work. Phase I self-assessment requirements remain in place, and contractors should continue maintaining cybersecurity controls, updating self-assessments, and supporting their NIST SP 800-171 compliance posture.
- Reassess near-term CMMC certification timelines. The DOD has suspended the transition to Phase II and other pending and future CMMC implementation milestones.
- Review solicitations, contracts, and subcontract flow-downs. During the suspension period, requiring activities are only permitted to include CMMC Level 1 or 2 self-assessments in procurement request and requirements documents, and may not designate Level 2 C3PAO or Level 3 DIBCAC assessments. Contractors should therefore confirm whether existing solicitations, pending bids, and subcontractor requirements need to be updated to reflect the interim posture.
- Use the 60-day review period strategically. Contractors should use the suspension to reassess compliance strategy, budget assumptions, documentation, and opportunities to provide feedback to the DOD’s review process, because the DOD has stated that it will study the future of the program and use industry feedback to recommend realistic and scalable security measures.
What Requirements Have Been Suspended?
The DOD’s announcement suspends the transition to Phase II CMMC requirements, which had been scheduled for November 10, 2026. Under the prior implementation schedule, November 10, 2026 was the date on which the DOD could begin conditioning relevant solicitations and contracts on Level 2 C3PAO assessment requirements and Level 3 DIBCAC assessment requirements. Those Phase II requirements are now suspended while the DOD undertakes a comprehensive review of the program.
The most important suspended requirement is the scheduled expansion of third-party certification for Level 2 contractors handling CUI. Under CMMC Level 2, contractors must implement the 110 security requirements in NIST SP 800-171 Rev. 2, and program officers could determine whether assessment would be conducted through self-assessment or through a CMMC third-party assessment organization. Phase II was expected to make Level 2 C3PAO assessment requirements a condition of certain awards. The implementing memo now provides that program managers and requiring activities may not designate CMMC Level 2 C3PAO assessments during the suspension period.
The suspension also reaches Level 3 DIBCAC assessment requirements. Level 3 certification assessments are conducted by the Defense Contract Management Agency DIBCACs and must be performed every three years for systems within the Level 3 CMMC assessment scope. The implementing memo states that program managers and requiring activities may not designate Level 3 DIBCAC assessments during the suspension period.
The DOD has also suspended pending and future CMMC implementation milestones across DOD’s solicitations and contracts. That formulation is broader than a simple delay of one deadline, and contractors should review current solicitations, pending bids, and existing contract language to understand whether any CMMC clauses or assessment requirements will be amended or reinterpreted. The DOD’s public explanation emphasizes that the pause is intended to reduce compliance barriers for small, medium, and non-traditional businesses while preserving a focus on “tangible cyber hygiene.”
What Requirements Remain in Place?
Phase I self-assessment requirements remain firmly in place. The DOD stated that, during the interim period, it will enforce cybersecurity compliance with NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments.
For contractors handling CUI, Level 2 remains aligned with NIST SP 800-171 Rev. 2, which the DOD confirmed will continue to serve as the operative standard during the interim period.
Contractors also should not overlook annual affirmations, Supplier Performance Risk System (SPRS)-related obligations, and other representations that may continue to carry legal and enforcement significance. Level 2 certifications are valid for three years but require annual affirmations in the SPRS to confirm continued compliance. Defense contractors should continue to be prepared to demonstrate compliance, ensure subcontractors are compliant, and mitigate potential False Claims Act liability.
