The Department of War (DoW) recently announced that it is suspending the implementation of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which were scheduled to take effect on Nov. 10, 2026. In the meantime, the DoW is launching what it calls a “comprehensive review” of the CMMC program with the goal of “replacing bureaucratic compliance with scalable, resilient cybersecurity measures.”
While this change delays the next phase of the CMMC rollout, organizations are still responsible for protecting sensitive government information and complying with existing contract requirements.
Here’s what defense contractors and subcontractors need to know now.
On July 13, the DoW announced it was suspending the transition to CMMC Phase II and pausing related implementation milestones. In addition, a task force has been established to review industry feedback and recommend updates to the CMMC program over the next 60 days.
This means that the DoW has temporarily put the next phase of CMMC implementation on hold while it evaluates whether the program can better support innovation and reduce red tape for defense contractors.
While the suspension is in effect, contractors should not expect new solicitations or contracts to include the previously planned Phase II requirements. However, it’s important to note that the suspension applies only to CMMC certification requirements—not the underlying cybersecurity expectations.
Although the CMMC Phase II requirements have been suspended, organizations should not interpret this announcement as a free pass to put cybersecurity initiatives on hold.
Several important requirements remain in place:
The DoW said it will continue relying on “self-assessments and select government-led assessments” to evaluate organizations’ security compliance during its review period.
In other words, the certification timeline has changed—but the expectation to protect sensitive government information has not.
For organizations that were preparing for a formal C3PAO assessment later this year, this announcement may provide some extra time before third-party certification becomes mandatory. However, this should not be seen as an opportunity to hit pause on your cybersecurity efforts.
Organizations that continue to strengthen their security programs now will be better positioned to meet future CMMC expectations as the program evolves. What’s more, investing in security policies, technical controls and documentation, and NIST SP 800-171 implementation provides value beyond CMMC compliance by reducing risk and building trust with customers in both the public and private sectors.
Organizations that delay these efforts may ultimately face a compressed timeline if new certification requirements are introduced following the DoW’s 60-day review.
While waiting for additional guidance to be released in the coming months, we recommend that organizations continue to maintain compliance with the existing cybersecurity requirements outlined in their contracts with the DoW and work to address any known security gaps.
In addition, compliance leaders should monitor the DoW for future announcements about the CMMC program and its implementation.
Preparing now helps reduce future compliance challenges while strengthening your organization’s security posture today.
While certification timelines may shift, building a strong cybersecurity program remains a worthwhile investment. At BARR Advisory, we have the experience and expertise to help your organization prepare for whatever comes next.
Whether you’re preparing for certification or strengthening your cybersecurity program, we can assist with a gap analysis, remediation guidance, ongoing consulting support, and practical resources to help streamline your compliance journey.
As the DoW evaluates the future of CMMC, organizations that continue investing in cybersecurity will be well-positioned to adapt to any new requirements without disrupting their operations. Contact us today to find out how we can help.