The Department of Defense has announced an immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, marking a significant shift in the program’s planned rollout.
Phase II was originally scheduled to begin on November 10, 2026, and would have expanded CMMC requirements to include third-party assessments for applicable Level 2 contractors. The Department’s decision pauses that transition while it conducts a comprehensive, 60-day review of the CMMC program and considers potential reforms.
For defense contractors and organizations throughout the Defense Industrial Base (DIB), the announcement raises important questions: What does the suspension mean for your organization? Are you still required to comply with CMMC? And should you continue preparing for certification?
The short answer: CMMC is not going away, and now is not the time to put cybersecurity efforts on hold.
What the CMMC Phase II Suspension Means
According to the Department of Defense, the suspension is intended to reduce the administrative and financial burdens that the current CMMC framework can place on small, medium-sized, and non-traditional defense contractors while maintaining strong cybersecurity protections across the DIB.
As part of the announcement, the Department is suspending the transition to Phase II requirements, as well as pending and future CMMC implementation milestones in DoD solicitations and contracts. A newly established CMMC Reform Task Force will conduct a top-to-bottom review of the program, incorporating feedback from the industry and examining how CMMC can better support the goals of a secure, resilient, and competitive DIB.
The Department has emphasized that the suspension is not intended to reduce cybersecurity requirements. Rather, the goal is to find a more effective approach to protecting sensitive government information without creating unnecessary barriers for companies that support the defense mission.
Phase I Requirements Are Still in Effect
One of the most important points for defense contractors to understand is that the suspension of Phase II does not eliminate current CMMC obligations.
Phase I requirements remain in place. Contractors may still be required to complete Level 1 or Level 2 self-assessments, depending on their contracts and the information they handle. Organizations must also continue meeting the underlying cybersecurity requirements that apply to their contracts, including requirements associated with protecting Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
In other words, the suspension does not mean contractors can step away from cybersecurity compliance. If your organization is already subject to CMMC requirements, you should continue to understand your obligations and maintain the security practices necessary to protect sensitive information.
What Happened to the November 10, 2026 Deadline?
The November 10, 2026, date was originally expected to mark the beginning of CMMC Phase II. Under the original implementation timeline, this phase would have increased the use of third-party assessments for organizations pursuing CMMC Level 2 compliance.
With Phase II now suspended, that transition will not proceed as originally planned.
However, the Department’s announcement does not provide a new Phase II deadline. Instead, implementation milestones are being held in abeyance while the Department conducts its 60-day review and considers potential changes to the program.
That creates some uncertainty for organizations that have been preparing for a C3PAO assessment. The requirements and timeline contractors were preparing for may change, but the broader need to demonstrate strong cybersecurity practices is unlikely to disappear.
Should You Stop Preparing for CMMC?
While the suspension may provide additional time and flexibility, it should not be viewed as a reason to abandon your cybersecurity roadmap.
The Department’s review could result in changes to how CMMC is structured, assessed, or implemented. However, organizations that have already invested in strengthening their cybersecurity posture will be better positioned to adapt to whatever comes next.
For contractors, this is an opportunity to focus on the fundamentals:
- Understand what data you handle. Identify whether your organization stores, processes, or transmits FCI or CUI and understand where that information exists within your environment.
- Review your current security posture. Evaluate your existing policies, procedures, technologies, and controls against applicable requirements.
- Address security gaps. Use this time to prioritize weaknesses and develop a practical plan for remediation.
- Document your cybersecurity practices. Strong security is important but being able to demonstrate and document how your organization protects sensitive information is equally critical.
- Maintain your compliance efforts. Continue meeting applicable requirements and maintaining your current self-assessment and affirmation obligations.
- Stay informed. The CMMC program is under review, and future guidance could affect the requirements and timelines that apply to your organization.
What Defense Contractors Should Do Next
For now, the best approach is to stay the course while staying flexible.
If your organization has already started preparing for CMMC, continue making progress on the work that strengthens your overall cybersecurity posture. If you have not yet started, this is a good time to assess where you stand and identify the steps needed to protect your environment and sensitive information. (More assessment information on our assessment guides and term explanation page.
The 60-day review may ultimately lead to changes in CMMC requirements, assessment processes, or implementation timelines. But waiting for every detail to be finalized before taking action could leave your organization playing catch-up later.
Cybersecurity maturity takes time to build. Policies need to be developed, technical controls need to be implemented, gaps need to be addressed, and employees need to understand their role in protecting sensitive information.
As the DoD evaluates the future of CMMC, defense contractors should use this window to strengthen their security foundation, address known gaps, and prepare to adapt to the program’s next chapter.
Because whether the next version of CMMC looks exactly like the current one or takes a different approach, one thing is clear: protecting sensitive information will remain essential to the future of the Defense Industrial Base.
Contact our team today if you have questions about CMMC compliance and the future of Phase II.

