The Department of War Suspends CMMC Phase II
In its July 13, 2026, release, the Department of War (DoW) suspended the implementation of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements effective immediately. Phase II, expected to have taken effect on November 10, 2026, entailed the requirement for third-party assessments. Pending and future CMMC implementation milestones throughout DoW solicitations and contracts are similarly suspended. An accompanying memo instructs that for any solicitation package or contract requiring CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments, program managers and contracting officers are to remove the requirements via solicitation amendment as soon as practicable or through a contract modification “prior to the exercise of the next option period or during the next scheduled administrative modification.”
Citing recent data that supports small businesses and non-traditional contractors are electing not to contract with the DoW, the department is concerned that the current CMMC framework is incompatible with its desire to expand the Defense Industrial Base (DIB). And so, the DoW is establishing a CMMC Reform Task Force “to conduct a comprehensive top-to-bottom review of the certification program” over the next 60 days. The Task Force is expected to recommend a revised security framework that will remove barriers to defense contracting.
Despite the suspension of Phase II requirements, the DoW is clear that all “All [CMMC] Phase I self-assessment requirements remain firmly in place.” Phase 1 requires self-assessments and attestations as to the appropriate protection of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). To avoid any doubt within the DIB, the DoW reiterated “all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012.” Accordingly, contractors should not view this as an invitation to reduce their cybersecurity posture.
If you have any questions regarding the suspension of CMMC Phase II or any other aspect of the CMMC program, cybersecurity requirements or any other matters related to contracting with the federal government, please reach out to your Cohen Seglias contact or contact any member of the Government Contracting Group.