Skip to Main Content

Keeping you informed

Defense Department Pauses Third-Party CMMC Assessments, But Contractor Cybersecurity Obligations Remain

    Client Alerts
  • July 22, 2026

On July 13, 2026, the Department of Defense announced the immediate suspension of the planned transition to Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program and the launch of a 60-day review of the program's future. The announcement pauses implementation of certain higher-level CMMC assessment requirements and creates uncertainty regarding the future structure of the CMMC assessment and certification framework.

Under the current phased implementation plan, Phase 2 was set to take effect on November 10, 2026, and would have introduced third-party assessments and certifications for many contractors handling controlled unclassified information (CUI). The DOD has now suspended the implementation of those requirements, as well as future implementation milestones associated with later phases of the program, pending further review.

Importantly, the suspension does not eliminate existing cybersecurity obligations. Contractors subject to current CMMC Phase 1 requirements must continue to perform required self-assessments and comply with applicable cybersecurity requirements, including FAR 52.204-21, DFARS 252.204-7012, and other applicable DFARS cybersecurity clauses. The DOD has also indicated that it will continue selected government-led cybersecurity assessments during the review period.

What Has Changed?

Prior to the announcement, Phase 2 would have required many contractors to obtain assessments from accredited CMMC Third-Party Assessment Organizations (C3PAOs). The DOD has now directed that, during the review period, requiring activities may specify only CMMC Level 1 or Level 2 self-assessments and may not require Level 2 C3PAO assessments or Level 3 defense industrial base cybersecurity assessment center (DIBCAC) assessments.

The DOD has also directed contracting officers to amend active solicitations to remove Level 2 C3PAO and Level 3 DIBCAC assessment requirements and to remove those requirements from existing contracts before the next option exercise or scheduled administrative modification. The suspension is currently being implemented through acquisition guidance, and the DOD has not yet amended the underlying CMMC regulations in 32 C.F.R. Part 170.

Why the Change?

According to the DOD, the current CMMC framework has imposed significant compliance costs and administrative burdens, particularly on small, medium-sized, and non-traditional defense contractors. The agency cited industry feedback and reports from the Small Business Administration suggesting that compliance costs, limited assessment capacity, and regulatory complexity were discouraging participation in the defense industrial base.

CMMC Reform Task Force

The DOD has established a CMMC Reform Task Force to conduct what it describes as a "top-to-bottom" review of the program and collect industry feedback over the next 60 days. To aid in this review, the DOD published a request for information (RFI) entitled "Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB)" on July 13, 2026, seeking direct feedback from DIB companies on practical strategies to inform the newly established CMMC Reform Task Force during its review. Comments on this RFI are due on August 14, 2026.

The task force is expected to evaluate whether the current assessment and certification framework should be modified and what cybersecurity requirements should apply to defense contractors going forward. At this stage, the DOD has not announced whether independent and government-led assessment requirements will ultimately be reinstated, revised, or replaced with an alternative compliance framework.

Key Takeaways for Contractors

While the suspension postpones the immediate need for many contractors to obtain third-party CMMC certifications, the announcement creates uncertainty regarding the future structure of contractor cybersecurity assessment and certification requirements. The department has not indicated whether it will ultimately reinstate the current framework, adopt a modified certification model, or pursue an alternative approach.

In the meantime, defense contractors should:

  • Continue complying with existing cybersecurity obligations and self-assessment requirements.
     
  • Continue implementing applicable NIST SP 800-171 Rev. 2 requirements and documenting compliance, including through required self-assessments and affirmations.
     
  • Monitor the ongoing DOD review and any guidance emerging from the CMMC Reform Task Force and associated RFI process.
     
  • Carefully evaluate how future solicitations address cybersecurity requirements while the review remains ongoing.

Final Takeaway

The suspension of Phase 2 raises important questions about the future of the DOD's approach to contractor cybersecurity oversight. While the department appears committed to maintaining cybersecurity standards, it is reevaluating whether the current CMMC certification structure is the appropriate mechanism for achieving that objective. Contractors should closely monitor developments over the coming months, as the outcome of the review could significantly reshape cybersecurity compliance obligations.

For more information, please contact us or your regular Parker Poe contact. Click here to subscribe to our latest alerts and insights.