Article Summary: The CMMC Phase II Suspension: What DoD Contractors Need to Know
On July 13, 2026, the DoD suspended the CMMC Phase II requirement for many contractors to obtain a C3PAO third-party certification, but it did not suspend the underlying cybersecurity obligations. Contractors handling CUI must still meet DFARS, NIST SP 800-171 and self-assessment requirements while a 60-day reform task force reviews the program.
- What paused: The mandatory C3PAO third-party assessment deadline set for November 10, 2026 is on hold indefinitely.
- What stands: NIST SP 800-171, DFARS 252.204-7012, SPRS self-assessments and required documentation all remain fully in force.
- What’s unclear: Whether third-party certification returns, is modified or is replaced pending the DoD review and RFI feedback.
- What to do: Treat the suspension as schedule relief, not a compliance exemption, and keep improving your posture.
If you’re a Department of Defense (DoD) contractor wondering what the CMMC Phase II suspension means for your contracts, here’s the bottom line up front: the third-party assessment deadline is on hold, but your cybersecurity obligations are not.
On July 13, 2026, the Department of Defense (DoD) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II implementation requirements that were scheduled to take effect on November 10, 2026. Specifically, the DoD has paused the requirement for many contractors handling Controlled Unclassified Information (CUI) to obtain a certification from a Certified Third-Party Assessment Organization (C3PAO). The Department simultaneously established a 60-day CMMC Reform Task Force to perform a comprehensive review of the program and recommend changes.
While this announcement significantly affects certification timelines and assessment planning, it does not eliminate contractors’ cybersecurity obligations under DFARS, NIST SP 800-171 or existing CMMC self-assessment requirements. The technical requirements remain largely unchanged; only the third-party validation mechanism has been suspended pending further review. The Cyber AB and the DoD are still processing and tracking the results of third-party assessments and issuing certificates for Organizations Seeking Certification (OSC).
What the CMMC Phase II Suspension Changes for DoD Contractors
1. DoD Has Suspended CMMC Phase II C3PAO Assessments
Prior to the announcement, CMMC Phase II was scheduled to begin on November 10, 2026. Under Phase II, contractors handling CUI would have been required to obtain an independent assessment conducted by a C3PAO before award of certain contracts.
The DoD has now suspended this transition indefinitely while conducting a comprehensive review of the program. Acquisition officials have been directed not to include Level 2 C3PAO assessment requirements during this suspension period. While the DoD has suspended the third-party assessments, there has been conversation that the five major primes are meeting to possibly establish their own requirements.
2. DoD Is Revising Solicitations to Remove C3PAO Requirements
The DoD has directed contracting activities to amend solicitations and future procurement packages that included C3PAO requirements, substituting self-assessment requirements where appropriate until further notice.
What CMMC and Cybersecurity Requirements Still Apply
Despite widespread discussion that “CMMC has been paused,” defense contractors should understand that the majority of cybersecurity obligations remain fully in effect.
1. NIST SP 800-171 Compliance Is Still Mandatory
Organizations that process, store or transmit CUI remain responsible for implementing the 110 security requirements in NIST SP 800-171 Rev. 2. The suspension does not relax these controls or diminish the expectation that contractors achieve compliance.
2. DFARS 252.204-7012 Obligations Remain in Force
The following DFARS obligations remain unchanged:
- Protection of Covered Defense Information (CDI)
- NIST SP 800-171 implementation
- Cyber incident reporting
- Media preservation requirements
- Flow-down requirements to subcontractors
The DoD explicitly stated that the suspension does not eliminate legal obligations to safeguard federal information.
3. SPRS Self-Assessment Reporting Continues
Phase I requirements of the CMMC program that became effective in November 2025 are still active and contractors remain responsible for:
- Performing self-assessments
- Calculating SPRS scores
- Maintaining supporting documentation
- Updating assessments as required
4. System Security Plans (SSPs) and Documentation Still Required
Contractors should continue maintaining:
- System Security Plans (SSPs)
- Asset inventories
- Network diagrams
- CUI data flow diagrams
- Shared Responsibility Matrices
- Plans of Action and Milestones (POA&Ms)
These artifacts remain foundational requirements for demonstrating compliance with NIST SP 800-171 and for eventual certification when or if third-party assessments return. Consistent with Schneider Downs’ CMMC methodology, these documents remain critical readiness artifacts.
What’s Still Uncertain After the CMMC Phase II Suspension
1. The Future of C3PAO Third-Party Certification
The largest unresolved issue is whether mandatory C3PAO assessments will:
- Return in their current form;
- Be delayed;
- Be modified to reduce cost and complexity;
- Be replaced with an alternative validation model; or
- Be significantly scaled back for certain segments of the Defense Industrial Base.
The DoD has not announced a final direction and is soliciting feedback from the ecosystem via an RFI published on July 14th.
2. What the Long-Term CMMC Program Will Look Like
The Task Force has been directed to develop recommendations that reduce administrative burden while maintaining cybersecurity protections. Several public reports indicate the DoD is evaluating alternatives to the current third-party assessment framework.
3. How CMMC Will Be Enforced in Contracts
Questions remain regarding:
- Whether future contracts will require self-attestation only;
- Which organizations may still need independent assessments;
- How subcontractor requirements will evolve;
- Whether DIBCAC-led Level 3 assessments will proceed as originally envisioned.
No formal guidance has yet been issued regarding these topics.
4. What Happens to Existing CMMC Assessment Investments
Contractors currently preparing for certification face uncertainty regarding:
- Timing of future assessments;
- Value of scheduled readiness reviews;
- C3PAO assessment demand forecasts; and
- Availability of certification pathways after the review concludes.
The DoD review is expected to provide additional guidance, but no outcome has been announced.
What DoD Contractors Should Do During the CMMC Suspension
Until further guidance is issued, contractors should:
- Continue implementing NIST SP 800-171 controls;
- Maintain and improve SPRS scores;
- Complete SSPs, network diagrams and CUI scoping activities;
- Continue readiness assessments and gap remediation efforts;
- Treat the suspension as schedule relief rather than a compliance exemption; and
- Monitor DoD communications regarding the 60-day CMMC Reform Task Force review.
Organizations that pause cybersecurity improvement efforts based on the suspension may find themselves unprepared if the DoD reintroduces an assessment mandate in a revised form. Multiple industry sources have emphasized that the substantive cybersecurity requirements remain intact even though the independent assessment requirement has been paused.
The Bottom Line: CMMC Is Paused, but Compliance Is Not
The DoD has suspended the requirement for most CMMC Level 2 third-party assessments, but it has not suspended the cybersecurity requirements that underpin CMMC. Contractors handling CUI remain obligated to implement NIST SP 800-171 controls, maintain required documentation, perform self-assessments, report SPRS scores and comply with DFARS cybersecurity requirements. The principal uncertainty is no longer what security controls are required but rather how and when compliance will ultimately be validated.
How Schneider Downs Can Help You Navigate the CMMC Pause
The suspension pauses third-party assessments, not the cybersecurity requirements behind them. Contractors who use this window to strengthen their posture will be ready when the DoD finalizes its revised framework. Our IT Risk Advisory team helps on every front that still matters:
- NIST SP 800-171 controls remain a DFARS 252.204-7012 obligation and the foundation of any future certification model. We assess your implementation, close gaps and document evidence.
- Protecting CUI is the program’s entire purpose and does not lapse during the review. We help you scope where CUI lives, apply the right safeguards and shrink your attack surface.
- Documentation — SSPs, network diagrams, CUI data flow diagrams and POA&Ms — turns security into demonstrable compliance. We help you build and maintain it so any future assessment is a confirmation, not a scramble.
- Self-assessments and accurate SPRS scores are still required, and errors carry False Claims Act exposure. We help you run defensible assessments and keep your scores current.
About Schneider Downs IT Risk Advisory
Our IT Risk Advisory practice helps ensure that your organization is risk-focused, promotes sound IT controls, ensures the timely resolution of audit deficiencies, and informs the board of directors of the effectiveness of risk management practices. We will partner with you to provide comprehensive IT audits and compliance reviews that will ensure your organization has effective and efficient technology controls that better align the technology function with their business and risk strategies.
To learn more, visit our IT Risk Advisory page or contact us at [email protected].
Related Posts
- U.S. Banking Regulators Expand AI Supervision: What Financial Institutions Need to Know
- CMMC FAQs Part 2– CMMC Model Guide v1.02
- The Latest on the Department of Defense CMMC Certification Levels and Timeline
- Will Cloud Service Providers’ SOC 2 Reports Satisfy SaaS Companies’ Customer Assurance Needs?