Article

The CMMC Phase II Pause: Separating Fact from Fiction for the Defense Industrial Base

July 21, 2026

By Travis Goldbach, VP of CMMC

Since the Department of War announced the suspension of the CMMC Phase II rollout, there has been no shortage of opinions across the Defense Industrial Base. Some have declared the program dead. Others have suggested organizations should stop pursuing certification altogether. Neither conclusion is supported by the facts.

This announcement is not the end of CMMC. It is a pause in one portion of the implementation timeline while the Department reviews the program. Organizations that understand what actually changed, and more importantly what did not change, will be in the strongest position moving forward.


The CMMC Program Is Still Operating

One of the biggest misconceptions is that the CMMC program has been suspended. It has not.

Every major component of the CMMC ecosystem remains operational and available.

  • C3PAO Level 2 Certification Assessments continue to be conducted.
  • CMMC Level 2 Mock Assessments continue to be performed.
  • CAICO-sanctioned training courses remain available.
  • CMMC professional examinations continue without interruption.
  • Registered Practitioner support services remain available.
  • The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) continues assessing C3PAOs and candidate C3PAOs.

The Department of War has not directed The Cyber AB to suspend or modify any of the program elements that fall under its responsibility. Likewise, the Supplier Performance Risk System (SPRS) and the CMMC Enterprise Mission Assurance Support Service (eMASS) remain operational and continue accepting C3PAO certification assessment submissions.

Organizations can still complete a CMMC Level 2 Certification Assessment today and receive a valid certification.

What Was Actually Suspended

The Department suspended the beginning of the CMMC Phase II rollout that was scheduled to begin on November 10.

Specifically, the Department delayed implementation of the requirement that applicable Department solicitations and contracts require a CMMC Level 2 Certification Assessment performed by an authorized C3PAO as a condition of contract award.

As a result, implementation of DFARS Clause 252.204-7021 relating to mandatory C3PAO Level 2 certifications and DIBCAC Level 3 assessments for new Phase II contract awards has also been delayed.

That is an important distinction.

The Department did not suspend cybersecurity requirements.

The Department did not suspend CMMC assessments.

The Department did not suspend The Cyber AB.

The Department did not suspend C3PAOs.

The Department suspended one milestone in the contractual implementation schedule.

Existing DFARS Requirements Remain in Effect

The overwhelming majority of contractual cybersecurity obligations remain exactly as they were before the announcement.

The following DFARS clauses continue to apply to awarded contracts and continue flowing throughout the defense supply chain.

  • 252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting
  • 252.204-7019 Notice of NIST SP 800-171 DoD Assessment Requirements
  • 252.204-7020 NIST SP 800-171 DoD Assessment Requirements
  • 252.204-7021 Cybersecurity Maturity Model Certification Requirements
  • 252.204-7024 Notice on the Use of the Supplier Performance Risk System
  • 252.204-7025 Notice of Cybersecurity Maturity Model Certification Level Requirements

Organizations supporting Department programs continue to have cybersecurity obligations regardless of the temporary delay in Phase II implementation.

Organizations will also continue submitting self affirmations where required for both CMMC Level 1 protecting Federal Contract Information (FCI) and CMMC Level 2 protecting Controlled Unclassified Information (CUI).

The Pause Only Applies Between the Department and Its Contractors

Another important point that has received very little attention is the scope of the suspension.

The Department’s announcement applies only to contracts awarded between the Department of War and the awarded contractor.

It does not invalidate contractual requirements established by prime contractors throughout their supply chains.

Many prime contractors have spent years preparing for CMMC implementation. They have invested heavily in supplier readiness programs, supply chain risk management, and cybersecurity validation. Those business decisions remain theirs to make.

If a prime contractor requires suppliers to obtain CMMC Level 2 Certification as part of its supplier qualification process, this announcement does not eliminate that requirement.

For many organizations, certification will continue to be driven by customer expectations rather than federal contract language.

Competitive Advantage Has Not Changed

Organizations that complete a CMMC Level 2 Certification Assessment today continue to differentiate themselves from competitors.

Independent certification demonstrates that an accredited C3PAO validated an organization’s implementation of NIST SP 800-171 rather than relying solely on self attestation.

That independent validation provides confidence to customers, prime contractors, investors, and acquisition teams.

Certification also provides stronger evidence that an organization exercised due diligence regarding its cybersecurity representations, helping reduce exposure to False Claims Act enforcement should cybersecurity claims ever be challenged.

As supply chain cybersecurity becomes an increasingly important discriminator, organizations with certification will likely continue to enjoy a competitive advantage over peers that delayed preparation.

NIST SP 800-171 Revision 3 Is Likely Delayed

Another practical implication of the announcement is timing.

The suspension of Phase II will likely delay mandatory migration to NIST SP 800-171 Revision 3 until future Federal Acquisition Regulation updates governing Controlled Unclassified Information begin appearing in contracts.

Organizations should certainly begin understanding Revision 3 and planning for its implementation, but there is no indication that immediate migration is necessary.

Increased Oversight Should Still Be Expected

Organizations should avoid interpreting this announcement as a reduction in federal cybersecurity oversight.

With DIBCAC no longer preparing to initiate CMMC Level 3 assessments in the near term, the Department may have additional capacity to conduct non voluntary DFARS 252.204-7012 audits and other oversight activities across the Defense Industrial Base.

Organizations should expect scrutiny of cybersecurity implementation to continue and potentially increase while the broader CMMC program is reviewed.

Do Not Confuse the Program Rollout with the Assessment Process

Another source of confusion has been the use of the term “Phase II.”

The suspension announced by the Department relates to the CMMC Program rollout timeline.

It does not suspend Phase 2 of the CMMC Assessment Process (CAP) Version 2.0, which is the assessment methodology used by authorized C3PAOs during certification assessments.

These are two entirely different concepts.

Certification assessments continue using the established CMMC Assessment Process.

What Executive Leadership Should Do Now

The organizations that will emerge strongest from this period of uncertainty will not be those that stop investing in cybersecurity.

  • Executive leadership should continue implementing NIST SP 800-171.
  • Organizations should continue preparing for independent C3PAO certification assessments.
  • Prime contractor requirements should continue to be monitored closely.
  • Security documentation should continue to mature.
  • System Security Plans and Plans of Action should continue to improve.
  • Internal governance should continue strengthening.
  • Cybersecurity investments should continue supporting operational resilience rather than simply regulatory compliance.

The implementation schedule may have shifted, but the underlying cybersecurity expectations have not.


Final Thoughts

Every major shift in the CMMC program has created uncertainty. Organizations that reacted emotionally often found themselves scrambling when requirements returned. Organizations that stayed focused on building mature cybersecurity programs consistently found themselves ahead of their competitors.

The current pause presents another opportunity.

Organizations can use this time to strengthen cybersecurity, improve documentation, complete independent certification assessments, and position themselves ahead of competitors who choose to wait.

The Department has paused one contractual milestone.

It has not paused the need to protect Controlled Unclassified Information.

It has not paused the responsibility to safeguard the Defense Industrial Base.

It has not paused the expectation that contractors demonstrate cybersecurity maturity.

Those organizations that continue investing now will be best positioned when the next phase of CMMC implementation begins.

Still have questions? Explore our CMMC Phase II Suspension FAQ for answers to the most common questions and practical guidance for navigating the suspension.

Travis Goldbach

Vice President of CMMC

Travis Goldbach is a cybersecurity and compliance leader with 20 years of experience driving growth and go-to-market strategy for federally regulated industries. He currently leads Coalfire Federal’s unified GTM strategy and previously guided AWS toward CMMC certification while helping customers advance secure, scalable compliance in the cloud.

View Full Bio