Skip to content

menu

Open Legal Blog Archive logo
HomeAboutBlogsFAQsSubmit

DoW Suspends CMMC Phase II Requirements – Launches 60-Day Review

By Edwin O. Childs, Andrew Konia, Abram J. Pafford, Jack White, Jason M. Vespoli, Léa Dickinson, Sophie Marsh & John Sullivan on July 14, 2026

On July 13, 2026, the Department of War (DoW) announced the immediate suspension of all Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had originally been scheduled to take effect Nov. 10, 2026, including the transition to mandatory third-party assessments by CMMC Third-Party Assessment Organizations for contractors handling Controlled Unclassified Information. The DoW simultaneously established a CMMC Reform Task Force charged with delivering a comprehensive report within 60 days recommending “realistic, scalable security measures” for the Defense Industrial Base.

The suspension aligns with Secretary of War Pete Hegseth’s Acquisition Transformation System directives and the broader “Arsenal of Freedom” initiative. Critically, the action does not relieve contractors of their underlying obligations to protect federal data, which includes the current DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting) and the NIST SP 800-171 Rev. 2 security controls upon which the CMMC Phase II requirements are based.

Read more
  • Posted in:
    Privacy & Data Security
  • Blog:
    Password Protected
  • Organization:
    McGuireWoods LLP
  • Article: View Original Source

Open Legal Blog Archive, Inc. logo
Seattle, Washington
Copyright © 2026, Open Legal Blog Archive, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo