The Department of War’s decision to suspend CMMC Phase II has created understandable questions across the Defense Industrial Base. Contractors are evaluating what the announcement means for certification, existing compliance obligations, current assessments, and future contract requirements.
The most important distinction is clear: the Department suspended the next phase of CMMC implementation. It did not suspend the obligation to protect Controlled Unclassified Information.
CMMC Phase I remains in effect. Contractors must continue meeting applicable DFARS requirements, implementing NIST SP 800-171 Revision 2, maintaining accurate self-assessments, and protecting federal information. The Department has established a 60-day review process to evaluate the future structure and implementation of the program.
Below are answers to the questions Coalfire Federal is hearing from organizations across the Defense Industrial Base.
No.
The Department suspended CMMC Phase II, which had been scheduled to begin on November 10, 2026. It did not cancel CMMC, eliminate Phase I, or remove the underlying cybersecurity obligations that apply to defense contractors.
The Department is reviewing the program and evaluating potential reforms. The outcome of that review has not yet been announced.
The Department suspended pending and future CMMC implementation milestones, including the planned transition to Phase II third-party assessment requirements.
The suspension changes the immediate certification timeline. It does not change the requirement to safeguard federal information.
The following remain in effect:
The certification mechanism is under review. The underlying security responsibilities remain.
Yes.
Contractors that handle Covered Defense Information or Controlled Unclassified Information remain responsible for implementing NIST SP 800-171 as required by their contracts.
The Department specifically identified NIST SP 800-171 Revision 2 as the applicable interim standard during the review period.
Yes.
Phase I self-assessment requirements remain active. Organizations must continue completing applicable self-assessments, submitting accurate scores to the Supplier Performance Risk System, and completing required annual affirmations.
The suspension of Phase II should not be interpreted as permission to allow an SPRS score or supporting evidence to become outdated.
Yes.
The obligation to protect CUI existed before CMMC and remains in place.
CMMC was designed to provide greater assurance that contractors had implemented the cybersecurity requirements they reported. Suspending one stage of that verification process does not remove the underlying contractual duty to safeguard the information.
For most organizations, stopping completely would create unnecessary risk.
The Department has not announced what will replace or modify the current Phase II model. Contractors should avoid making significant compliance decisions based on assumptions about the review’s outcome.
Organizations should continue work that supports their existing contractual and cybersecurity obligations, including:
This work remains relevant regardless of how the Department ultimately adjusts the certification process.
For many organizations, yes.
A Mock Assessment can provide an independent view of how well an organization’s current implementation aligns with NIST SP 800-171 and the CMMC assessment methodology. It can also identify gaps between documented policies, technical implementation, and available objective evidence.
Organizations may use the additional time to:
A Mock Assessment should be treated as an independent evaluation of the current environment, not as a guarantee of a future certification result.
Organizations should evaluate their circumstances before canceling or changing an engagement.
Relevant factors may include:
Organizations with a scheduled or active assessment should speak directly with their C3PAO to understand their options and the current status of the assessment process.
The Department’s announcement did not revoke certifications that had already been issued.
Organizations with an existing certification should continue maintaining the environment, evidence, and practices that supported the assessment. They should also continue meeting applicable affirmation and contractual requirements.
The Department’s initial announcement did not fully explain how assessments already in process would be handled.
Organizations in this situation should confirm their status directly with their C3PAO and monitor additional guidance from the Department, the Cyber AB, and other authoritative sources.
Existing contract terms generally remain controlling until the contract is formally modified.
The Department indicated that program managers and contracting officers would address suspended requirements in active solicitations and contracts. Contractors should not assume that a requirement has been removed before receiving an official modification.
Questions about a specific contract should be directed to the appropriate contracting officer.
Applicable contractual flow-down requirements remain important.
Prime contractors and subcontractors should review their agreements to determine which DFARS, CUI protection, reporting, and CMMC-related provisions currently apply. A change to the Department’s implementation schedule does not automatically modify the terms of an agreement between a prime and its suppliers.
Suppliers should communicate directly with their prime contractors when expectations are unclear.
The Department identified NIST SP 800-171 Revision 2 as the applicable interim standard.
The announcement did not establish when or whether Revision 3 will become part of a revised CMMC program. Contractors should follow current contractual requirements unless authoritative guidance states otherwise.
Yes.
The Department is conducting a formal review of the program through a CMMC Reform Task Force. Potential changes could affect implementation timelines, assessment requirements, scalability, costs, or how requirements apply to different segments of the Defense Industrial Base.
The final structure is not yet known. Contractors should distinguish confirmed requirements from speculation until the Department releases additional guidance.
Organizations should take a measured approach based on current obligations and business risk.
Coalfire Federal recommends that contractors:
The timeline has changed, but the threat environment, contractual obligations, and need for defensible cybersecurity practices have not.
No.
The Department did not suspend C3PAO operations or prohibit organizations from pursuing independent certification assessments. Authorized C3PAOs remain operational and continue conducting assessments for organizations that choose to move forward.
Organizations should evaluate whether completing an assessment now supports customer requirements, competitive positioning, contractual obligations, or overall cybersecurity maturity.
Many organizations view certification as a business decision rather than simply a compliance exercise.
Benefits may include:
Organizations that are prepared today may have greater flexibility than those waiting until requirements become mandatory again.
Yes.
While no timeline has been announced, organizations should recognize that implementation schedules can change.
Waiting until requirements are finalized could create scheduling challenges, remediation delays, or limited assessment availability if demand increases significantly.
Maintaining readiness reduces the risk of having to accelerate major cybersecurity improvements under compressed timelines.
They may.
Although certification requirements have been suspended for now, contracting officers, prime contractors, and acquisition teams may continue evaluating contractor cybersecurity maturity through existing contractual requirements, supplier risk reviews, or proposal evaluations.
Organizations should be prepared to explain their cybersecurity posture and demonstrate implementation of applicable contractual requirements.
Yes.
Prime contractors remain responsible for managing supply chain risk and ensuring subcontractors satisfy applicable contractual cybersecurity requirements.
Many primes are expected to continue requesting evidence of NIST SP 800-171 implementation, SPRS scores, supplier cybersecurity questionnaires, or other documentation while the Department completes its review.
Potentially.
Organizations should carefully review each solicitation.
Some solicitations may be amended to reflect the Department's announcement, while others may continue requiring existing cybersecurity documentation or other evidence of compliance until officially modified.
Offerors should never assume solicitation requirements have changed unless the contracting activity issues formal guidance.
Yes.
The suspension does not eliminate the importance of maintaining an accurate and supportable SPRS score where required by contract.
Organizations should continue implementing NIST SP 800-171 requirements and updating their SPRS submissions as improvements are completed.
No.
Organizations remain responsible for ensuring that representations regarding cybersecurity implementation are accurate.
Submitting inaccurate SPRS scores, annual affirmations, proposal certifications, or contractual representations may still create legal and contractual risk regardless of changes to the CMMC implementation schedule.
Absolutely.
One of the most time-consuming aspects of any assessment is assembling objective evidence demonstrating implementation.
Organizations that continue documenting policies, procedures, technical configurations, screenshots, system settings, interview evidence, and operational records will be significantly better prepared regardless of future program changes.
Executive leadership should focus on governance rather than waiting for additional announcements.
Recommended actions include:
Generally, no.
Many cyber insurance carriers evaluate an organization's overall cybersecurity maturity, governance, and implementation of recognized security frameworks.
Maintaining progress toward NIST SP 800-171 and CMMC readiness may continue supporting broader enterprise risk management objectives beyond DoD compliance.
Potentially.
If certification requirements are reinstated after the review period, many organizations that delayed preparation could seek assessments simultaneously.
Historically, periods of increased regulatory demand have resulted in longer scheduling timelines and reduced assessment availability.
Organizations that maintain readiness may have greater flexibility if demand increases.
Organizations should avoid making decisions based on speculation.
Specifically, they should avoid:
Maintaining steady progress is generally lower risk than pausing efforts based on assumptions.
Coalfire Federal helps organizations independently evaluate their cybersecurity posture and understand how current requirements apply to their environments.
Depending on an organization’s needs and engagement status, our teams provide:
Coalfire Federal maintains the independence and impartiality required of an Authorized C3PAO. Advisory or readiness services and official CMMC assessments are performed under applicable independence requirements.
Whether your organization is reviewing an existing assessment plan, validating its current position, or determining how the suspension affects its contracts, the next step should be based on verified requirements and business risk rather than speculation.