Why Every Defense Contractor Is Asking the Same Questions Right Now
On July 13, 2026, the Department of War suspended implementation of CMMC Phase II, triggering widespread confusion across the Defense Industrial Base. Some contractors assumed CMMC had been canceled. It has not.
The DoW announcement paused the planned rollout of mandatory third-party C3PAO assessments and launched a 60-day review of the program. It did not eliminate CMMC. It did not remove cybersecurity obligations. It did not cancel self-assessments. And it did not change what defense contractors are contractually required to do to protect Controlled Unclassified Information.
Here is a plain-language breakdown of what actually changed, what did not, and what your organization should do right now.
What Changed vs. What Did Not
| What Changed | What Did Not Change |
| CMMC Phase II implementation suspended | DFARS 252.204-7012 still fully applies |
| Mandatory C3PAO rollout delayed | NIST SP 800-171 Rev 2 security requirements still in effect |
| Level 2 (C3PAO) and Level 3 (DIBCAC) temporarily suspended from solicitations | Level 1 and Level 2 self-assessments continue |
| CMMC program under 60-day DoW review | CUI must still be protected |
| C3PAO assessments cannot be designated in new solicitations | SPRS submissions and annual affirmations still required |
| Task force reviewing implementation approach | Minimum SPRS score threshold of 88 out of 110 unchanged |
A Timeline of CMMC Phase II
| Date | Event |
| October 15, 2024 | CMMC final rule published in Federal Register |
| November 10, 2025 | Phase I enforcement begins — self-assessments required in solicitations |
| November 10, 2026 | Phase II planned — mandatory C3PAO assessments scheduled to begin |
| July 13, 2026 | DoW suspends Phase II implementation — 60-day review announced |
| August 14, 2026 | RFI response deadline — contractors submit feedback to CMMC Reform Task Force |
| September 13, 2026 | Task force recommendations expected |
So What Did the Department of War Actually Announce?
The Department of War announced that it is suspending the implementation of CMMC Phase II requirements while it conducts a comprehensive 60-day review of the program as part of Secretary Pete Hegseth’s Acquisition Transformation System initiative, focused on reducing unnecessary bureaucracy, improving efficiency, and accelerating the delivery of critical capabilities to the warfighter.
The Department of War’s implementing memorandum (26-P-1023, signed by Under Secretary of War for Acquisition and Sustainment Michael Duffey) spells out exactly what this means for procurement documents during the suspension. Program Managers and requiring activities may only include CMMC Level 1 (Self) or CMMC Level 2 (Self) assessment requirements in solicitations. They are not permitted to designate CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC) assessments while the review is underway.
In practical terms, self-assessment stays available and is expected to continue. The third-party and government-led certification tiers are what is on hold.
Why Did the Department of War Pause CMMC Phase II?
The Department of War wants to determine whether the current implementation timeline and certification process create unnecessary challenges for contractors, particularly small and mid-sized businesses that make up a significant portion of the Defense Industrial Base.
Under Secretary Michael Duffey was direct about the policy intent, stating in the DoW announcement:
“Our decision ensures a strict security baseline is maintained, while removing paralyzing costs, keeping innovators and competition growing in the defense supply chain, and delivering what our warfighters need to succeed.”
Rather than assuming the current implementation is the only path forward, the Department of War is taking the opportunity to evaluate whether improvements can be made before mandatory third-party assessments become a contract requirement. This review should be viewed as an effort to improve implementation, not an indication that cybersecurity is becoming less important.
If your organization supports defense contracts and is unsure how CMMC timelines, SPRS requirements, or assessment readiness apply to you, now is the time to get clarity.
Does This Mean Cybersecurity Is Less Important Now?
No. And the Department of War has said so directly.
DoW Chief Information Officer Kirsten Davies reaffirmed in the July 13 announcement:
“Robust cybersecurity and operational resilience remain critical to protecting American innovation, strengthening the Defense Industrial Base, and supporting warfighter readiness.”
That statement should remove any doubt about the Department of War’s priorities. Cybersecurity has not been deprioritized. Protecting sensitive government information remains essential, and contractors that store, process, or transmit Controlled Unclassified Information are still expected to maintain appropriate cybersecurity safeguards.
The Department of War is reviewing how CMMC Phase II will be implemented, not whether cybersecurity remains necessary.
What Is CMMC Phase II and Why Does the Pause Matter?
CMMC is being introduced in multiple phases.
Phase I focuses primarily on self-assessments for contracts requiring lower levels of verification.
Phase II introduces mandatory third-party certification for many contractors that handle Controlled Unclassified Information. Under the original implementation schedule, organizations within this scope would need to successfully complete an assessment performed by an authorized Certified Third-Party Assessment Organization (C3PAO) before receiving certain contract awards. It is this planned implementation that is now under review.
The Department of War has not announced that C3PAO assessments are being eliminated. Instead, it is evaluating whether the current November 2026 implementation timeline remains appropriate or whether adjustments should be made.
It is worth noting that CMMC Level 2 self-assessment is not a rubber stamp. Under the existing NIST SP 800-171 scoring methodology, organizations still need a minimum SPRS score of 88 out of 110 to demonstrate an acceptable level of implementation. The suspension changes who verifies that score, not the bar itself.
What Requirements Are Still Fully in Effect?
The DoW’s news release is explicit: this action does not eliminate the requirement for companies to protect federal data.
All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012. The Phase II pause affects the third-party certification mechanism, not the underlying safeguarding obligation itself.
Organizations should continue implementing and maintaining applicable NIST SP 800-171 Rev 2 security controls. The Department of War’s implementing memorandum specifically directs that baseline compliance during the suspension period is enforced through NIST SP 800-171 Rev 2, via CMMC Level 1 and Level 2 self-assessment and select government-led assessments.
Required documentation should continue to be developed and maintained. Evidence supporting implemented security controls should continue to be collected. Internal cybersecurity improvements should continue moving forward.
Should We Stop Preparing for CMMC?
No. And here is why.
Based on current contractual obligations under 32 CFR Part 170 and DFARS 252.204-7012, our recommendation is clear.
Continue preparing. Continue strengthening your cybersecurity program. Continue documenting your environment. Continue implementing technical controls. Continue training your employees. Continue improving your overall security posture.
Whether the Department of War maintains the current timeline, delays implementation, or adjusts the certification process, organizations that continue preparing today will be in a stronger position regardless of how the review concludes. Waiting for the review to conclude creates unnecessary risk and could leave companies scrambling if certification requirements move forward sooner than expected.
Where Can Contractors Find Official Updates and Submit Feedback?
Request for Information. The Department of War has published a formal Request for Information on SAM.gov on reforming CMMC and reducing compliance burden for the Defense Industrial Base. This is the formal mechanism for contractors to submit feedback on cost drivers, administrative burdens, and which security controls deliver meaningful risk reduction. The response deadline is August 14, 2026.
The RFI asks contractors to address seven specific questions covering the top cost drivers and administrative burdens experienced with CMMC and NIST SP 800-171 Rev 2, which security controls deliver the most tangible cybersecurity risk reduction, which requirements create the highest overhead with the least measurable improvement, how commercial cybersecurity capabilities could be better recognized within the compliance framework, what challenges organizations face with Phase I self-assessments, and what specific policy changes would reduce costs for small and non-traditional businesses without degrading the protection of federal data.
Responses that bring real cost and operational data rather than general commentary are likely to carry the most weight with the Task Force.
Brilliant Basics. The DoW’s Brilliant Basics page is the designated source for program updates as the review progresses, including the task force’s eventual recommendations expected on or about September 13, 2026.
Project Spectrum. Project Spectrum is the Department of War’s cybersecurity readiness and compliance resource offering self-assessment tools, cybersecurity readiness training, advisory services, and policy and documentation templates to help organizations strengthen their security posture while the review is underway.
What Does Brea Networks Recommend?
At Brea Networks, we believe this announcement should be viewed as an opportunity to gain clarity, not as a reason to pause cybersecurity efforts.
The Department of War is evaluating the implementation of CMMC Phase II to ensure the certification process effectively supports both national security and the businesses that make up the Defense Industrial Base. Secretary Pete Hegseth’s focus on acquisition reform seeks to reduce unnecessary administrative burdens while maintaining the capabilities needed to protect the nation. Chief Information Officer Kirsten Davies has reinforced that cybersecurity remains fundamental to protecting America’s defense supply chain.
Taken together, these messages tell a consistent story. The Department of War is reviewing the implementation of mandatory third-party C3PAO assessments, not the importance of cybersecurity itself.
Our recommendation is to use this period to close gaps, strengthen documentation, improve your SPRS score, and get your evidence package in order. Whatever the outcome of the review, organizations that have done that work will be in a stronger position than those that waited.
What Should We Expect After the 60-Day Review?
The task force recommendations are expected on or about September 13, 2026. At that point, the Department of War will have several options: maintain the current November 2026 Phase II timeline, adjust the timeline, modify the certification requirements, or take a different approach to implementation entirely.
What we do not know is which path the Department of War will choose. What we do know is that the underlying obligation to protect Controlled Unclassified Information under DFARS 252.204-7012 will not change regardless of what the task force recommends.
The Department of War has not announced the end of CMMC. It has not eliminated the responsibility to protect Controlled Unclassified Information. It has not removed existing cybersecurity expectations for defense contractors. It is reviewing whether the implementation of mandatory third-party assessments should proceed as originally planned or be adjusted to better support the Defense Industrial Base.
For defense contractors, the path forward is clear. Continue preparing. Continue strengthening your cybersecurity program. Continue protecting sensitive information.
Are Annual Affirmations Still Required?
Yes. Annual affirmations remain part of the CMMC program.
Organizations required to perform CMMC self-assessments continue to submit affirmations in SPRS as required by the CMMC rule under 32 CFR § 170.22. Although the Department of War has temporarily paused the implementation of Phase II Level 2 (C3PAO) requirements, it has not announced the elimination of annual affirmations or the underlying cybersecurity obligations established under the CMMC program.
Contractors should continue maintaining accurate documentation and security evidence supporting their reported compliance posture.
Frequently Asked Questions About the CMMC Phase II Suspension
Is CMMC canceled? No. The Department of War has suspended the implementation of CMMC Phase II during a 60-day review. The CMMC program itself has not been eliminated. The CMMC program rule at 32 CFR Part 170 remains in effect.
Is CMMC still required? Yes. CMMC Level 1 and Level 2 self-assessments continue to be required in solicitations during the review period. The underlying cybersecurity obligations under DFARS 252.204-7012 and NIST SP 800-171 have not changed.
Do I still need a C3PAO assessment? The Department of War has temporarily suspended the requirement to designate CMMC Level 2 (C3PAO) assessments in new solicitations during the review period. The implementing memorandum (26-P-1023) prohibits Program Managers from including C3PAO or DIBCAC requirements in solicitations while the review is underway. Whether C3PAO assessments will be required after the review concludes depends on the task force recommendations expected by September 13, 2026.
What happens to my SPRS score? Nothing changes. SPRS submissions remain required under DFARS 252.204-7019 and DFARS 252.204-7020. Your score must accurately reflect your actual implementation of NIST SP 800-171 security requirements. The minimum score threshold of 88 out of 110 for self-assessment remains unchanged.
Should I stop implementing NIST SP 800-171? No. The DoW implementing memorandum specifically directs that baseline compliance during the suspension period is enforced through NIST SP 800-171 Rev 2. Organizations should continue implementing and maintaining all applicable security requirements.
Can contracts still require self-assessments? Yes. CMMC Level 1 (Self) and Level 2 (Self) assessment requirements may still be included in solicitations during the suspension period. Only the C3PAO and DIBCAC certification tiers are prohibited from new solicitations while the review is underway.
What is the RFI deadline for contractors to submit feedback? The formal Request for Information response deadline is August 14, 2026. Organizations with real cost and implementation data are strongly encouraged to respond.
Not Sure Where You Stand? Start Here
The Phase II suspension changes how CMMC will be implemented, not whether cybersecurity matters. Organizations that continue strengthening their NIST SP 800-171 compliance will be in a stronger position regardless of the outcome of the Department of War’s review.
If you are unsure whether your environment is ready for a Level 2 self-assessment or future certification, now is the time to perform a gap assessment rather than waiting for new guidance. The contractors who use this review period wisely will be ahead of the field when implementation requirements are confirmed.
Schedule a free consultation with the Brea Networks team to review your current environment, identify compliance risks, and understand what steps are required to move forward. A short conversation can help you avoid costly mistakes and focus on what matters for contract eligibility and security.
About Brea Networks
Brea Networks is a cybersecurity and compliance-focused IT partner supporting Defense Industrial Base contractors. We help organizations implement the security requirements outlined in FAR 52.204-21, DFARS 252.204-7012, NIST SP 800-171, and the CMMC framework. Whether your organization is completing a Level 2 self-assessment or preparing for future third-party certification, we help define assessment scope, strengthen cybersecurity, prepare documentation, improve SPRS readiness, and build sustainable compliance programs that protect FCI and CUI.
Government and official sources referenced in this post:
- DoW — CMMC Phase II Suspension Announcement, July 13, 2026
- DoW CIO — CMMC Program
- DoW CIO — Kirsten Davies, Chief Information Officer
- SAM.gov — CMMC Reform RFI, Deadline August 14, 2026
- Project Spectrum — DoW Cybersecurity Readiness Resource
- eCFR — 32 CFR Part 170, CMMC Program Rule
- eCFR — 32 CFR § 170.22, Annual Affirmation Requirements
- Acquisition.gov — FAR 52.204-21
- Acquisition.gov — DFARS 252.204-7012
- Acquisition.gov — DFARS 252.204-7019
- Acquisition.gov — DFARS 252.204-7020
- NIST SP 800-171 Revision 2
- SPRS — Supplier Performance Risk System
- National Archives — About CUI