On July 13, 2026, the Department of Defense (DoD) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Level 2 third-party assessment requirements, which were originally scheduled to come into effect on November 10, 2026. The announcement clarified that all CMMC Level 1 and CMMC Level 2 self-assessment requirements, which have been in effect since November 10, 2025, will remain in place. The Pentagon intends to conduct a comprehensive review of the CMMC program, raising fresh uncertainty about the long-term direction of cybersecurity compliance obligations for defense contractors.
The principal takeaway of the suspension is that contractors seeking award of or performing on contracts that involve the handling of Controlled Unclassified Information (CUI) will not be required to schedule and complete a third-party assessment of their CMMC Level 2 compliance. However, where contractors will be required to handle CUI, they are still responsible for self-certifying that they comply with all 110 NIST SP 800-171 Rev. 2 security requirements. In other words, the technical cybersecurity requirements have stayed the same, only the need for a third-party certification has been postponed.
The announcement is also welcome news for subcontractors, who have faced a significant financial burden under the CMMC program. The November deadline would have required third-party assessments not only for prime contractors handling CUI, but also all tiers of subcontractor that process, store, or transmit CUI. This has led many primes to manage risk by flowing down third-party assessment requirements to subcontractors even before formal contract language ever appears. With the third-party assessment requirement now suspended, subcontractors can continue performing defense work after completing a less costly self-assessment, and prime contractors can engage with them at reduced risk.
What Has Changed
Phase II of the CMMC program was intended to take effect on November 10, 2026. This second phase would require contractors to complete a CMMC Level 2 assessment conducted by a Certified Third-Party Assessment Organization (C3PAO) in order to be eligible for defense contracts that involve the handling of CUI. Phase III, which was intended to take effect on November 10, 2027, would add a CMMC Level 3 requirement for contracts involving highly sensitive CUI, which would require contractors to undergo an assessment conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
The November deadline for the transition to Phase II has been indefinitely suspended. Additionally, all pending and future CMMC implementation milestones across department solicitations and contracts are indefinitely held in abeyance. This means contracting officers may not require compliance with CMMC Level 2 (C3PAO) or Level 3 as a condition of contract award or option exercise until the suspension is lifted.
If an active solicitation includes CMMC Level 2 (C3PAO) or CMMC Level 3 requirements, contracting officers must initiate an amendment explicitly removing those requirements as soon as practicable. For existing contracts that include the suspended requirements, contracting officers are directed to issue modifications removing the requirements prior to the exercise of the next option period or during the next scheduled administrative modification.
What Hasn’t Changed
Existing contractual requirements remain in effect. The following contractual requirements still apply to all defense contractors:
- FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems). Contractors must implement the 15 security requirements and procedures to protect Federal Contract Information (FCI), which is information provided by or generated by the government that is not intended for public release.
- DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting). Defense contractors that handle CUI during contract performance must implement the 110 security controls of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171. This includes compliance with the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline for contractors that utilize cloud services. Contractors must also adhere to the clause’s cyber incident reporting requirements and flow down the clause to subcontractors handling CUI during subcontract performance.
Further, CMMC Phase I remains in effect during the suspension. Phase I took effect on November 10, 2025, requiring defense solicitations to include CMMC Level 1 and Level 2 self-assessment as eligibility requirements. Contracting officers also have discretion to incorporate these requirements when exercising options on existing contracts.
CMMC Level 1 is a self-assessment intended to confirm a contractor’s compliance with the 15 security requirements of FAR 52.204-21. CMMC Level 1 is a condition for contract award of any contract that involves the handling of FCI.
CMMC Level 2 (Self) is a self-assessment that confirms a contractor’s compliance with both FAR 52.204-21 and all 110 security controls of NIST SP 800-171 Rev. 2. CMMC Level 2 (Self) remains a condition for contract award of any contract where the contractor will store, process, or transmit CUI. The Level 2 (Self) requirements provide contractors with an opportunity to remain eligible for award even if they do not meet all 110 NIST requirements via completion of a Plan of Action and Milestones (POA&M) within 180 days of creation of the POA&M.
Contractor Considerations
While the suspension provides contractors with some breathing room, it is important to keep in mind that it is intended as a temporary opportunity for DoD to reassess the CMMC program. Per the DoD, the CMMC Level 2 (C3PAO) requirements, in their current form, have imposed a significant burden on many government contractors. It is likely that these requirements will resume once these issues are addressed, and contractors would be wise to continue their efforts toward third-party assessment and certification.
Additionally, other elements of the federal government are also working to impose cybersecurity requirements based on the NIST SP 800-171 security controls. For example, the FAR Council recently published a proposed CUI rule that would implement a contractual mechanism to require all federal contractors who handle CUI during contract performance to comply with NIST SP 800-171 Rev. 3, though it does not provide a CMMC-like attestation or certification requirement. Accordingly, contractors who complete the third-party CMMC certification process have verifiable evidence of compliance on file as the rest of the federal government catches up to DoD.