CMMC Phase II Rollout Suspension: What Defense Contractors Need to Know

  • CMMC Phase I remains in effect and existing contract cybersecurity requirements are unchanged (Self-attestation for DFARS 7021 is a condition of award).
  • Self-attestation tab for CMMC Level 2 requires a score of 88 to self-post your score, which meets “conditional” CMMC status.
  • Phase II rollout of certification requirements in contracts originally starting Nov 10, 2026 is currently paused pending task force review of SMB cost drivers of CMMC.
  • DoW has issued an RFI seeking public input on CMMC’s future and industry cost impacts to small business.
  • C3PAOs are still actively scheduling and performing assessments, and CMMC-related compliance activity is continuing. CMMC will continue to be a differentiator.
  • DFARS 252.204-7012 remains active and unaffected by this review, and prime contractors must still meet current obligations, including applicable subcontractor flow-downs.
This content was generated by AI and reviewed by an editor.

On July 13, 2026, the Department of War (DoW) suspended CMMC Phase II requirements that would have placed third-party certification requirements into new solicitations beginning November 10, 2026. This is only a temporary pause to the implementation of CMMC Phase II, delaying the requirement for mandatory third-party (C3PAO) assessments while it conducts a comprehensive review of the program. The Department emphasized that this is not a rollback of cybersecurity requirements—contractors must still comply with DFARS cybersecurity clauses, implement the security controls in NIST SP 800-171, and continue protecting Controlled Unclassified Information (CUI). 

Instead, this review is focused on determining whether the current certification and assessment model creates unnecessary cost, administrative burden, and barriers to participation in the Defense Industrial Base, particularly for small businesses. During the review, the Department will evaluate alternative approaches that maintain strong cybersecurity while reducing compliance costs, streamlining acquisition, and expanding competition, signaling that the future of CMMC is more likely to involve changes to how compliance is verified rather than what cybersecurity requirements contractors must meet.

The DoW announcement has provided this CMMC Reform Task Force with 60 days to deliver industry-led recommendations. What has not changed are the underlying cybersecurity and CMMC Phase I reporting obligations for defense contractors and subcontractors that handle controlled unclassified information (CUI).


Why the DoW Paused This Phase II of the Rollout

The memorandums repeatedly cite four primary reasons:

  1. CMMC became too expensive: The Department states the current implementation has created prohibitive compliance costs, excessive bureaucracy, and significant administrative overhead rather than simply improving cybersecurity. 
  2. Small businesses are leaving the Defense Industrial Base: The CIO specifically references SBA findings indicating that many small businesses, innovative startups and non-traditional defense contractors were deciding that defense work simply wasn’t worth the compliance burden.  The Department concludes that this ultimately hurts national security because fewer suppliers means less innovation and slower delivery of capability to the warfighter.  
  3. Acquisition speed has become the priority: Everything is now being framed around Secretary Hegseth’s Acquisition Transformation System (ATS).  The repeated themes are: 1) speed to capability, 2) remove bureaucracy, 3) expand the industrial base, 4) increase competition, and 5) buy capability faster.  The CIO repeatedly states cybersecurity must support, not impede, those objectives.  
  4. Cybersecurity still matters: The Department goes out of its way to say that robust cybersecurity remains a non-negotiable priority. The DoW is not walking away from cybersecurity, they are just questioning whether CMMC’s certification model is the right way to enforce it.  This Task Force is soliciting input from industry on how to do just that.


What Changed, Effective Immediately

The implementation memorandum specifically states that during the CMMC Phase II rollout suspension, program offices may require only:

  • Level 1 (Self) (read this as the CMMC Level 1 Self Tab in SPRS)
  • Level 2 (Self) (read this as the CMMC Level 2 Self Tab in SPRS)

They may not require the following for new solicitations during the suspension:

  • Level 2 C3PAO assessments (read this as Level 2 Certification requirement in DFARS 7025 solicitation provision)
  • Level 3 DIBCAC assessments (read this as Level 3 Certification requirement in DFARS 7025 solicitation provision)

Existing solicitations containing those requirements (solicitation Provision DFARS 252.204-7025 and contract clause DFARS 252.204-7021) are directed to be amended as practical.  


What This Does NOT Mean to Contractors

  • It does not mean the CMMC program is canceled. This is a suspension with a 60-day “task force” review of the Phase II rollout of the CMMC Certification requirements to be placed into contracts starting November 10, 2026.  This is  not a repeal, in any way, of CMMC. The Phase I of the CMMC rollout is still in effect for reporting your scores to the CMMC L2 Tab and DFARS 252.204-7012 remains in place for reporting of your SPRS score to the NIST 800-171 tab. The 32 CFR Part 170 rule (which finalized rulemaking for the CMMC program as a whole) remains in place.  DFARS 252.204-7012 and DFARS 252.204-7021 remain in place.   And CMMC could return in a revised, streamlined or substantially similar form. Companies that use this period to maintain progress may be better positioned when the task force reports its recommendations. 
  • It does not mean Phase I of the CMMC Rollout is rescinded. Phase I self-assessment requirements remain in place. Contractors should continue to post their scores on both the NIST 800-171 tab as well as the CMMC L2 “Self” Tab in the Supplier Performance Risk System (SPRS).  To qualify for contracts in the Phase I Rollout of CMMC,  annual affirmations continue to matter, and organizations should ensure that scores are current, accurate and supported by appropriate evidence. 
  • It does not mean DIB contractors can stop protecting CUI. The release states that DFARS 252.204-7012 remains contractually binding on defense contractors and subcontractors handling covered defense information. That clause has required NIST SP 800-171 implementation since 2017.
  • It does not mean NIST SP 800-171 is optional. During this interim period, the DoW is expected to continue enforcing NIST SP 800-171 Rev. 2 compliance through self-assessments and select government-led (DCMA DIBCAC) assessments. Contractors should continue to maintain documentation that supports implementation and be prepared to demonstrate the basis for their compliance posture.
  • It does not mean the DoD will just “roll back” reporting to just the NIST 800-171 SPRS Tab.  The CMMC Level 2 “Self” Tab is the current requirement.  The requirement for the CMMC L2 “Self” (self-attest) tab is more difficult for contractors than the NIST 800-171 tab because they must mark each control as met or not met, and the SPRS system will automatically calculate the contractor’s score.  If your score is not an 88 or above (conditional CMMC certification level) or you have even one control still open that is score as a –3 or –5, the submit button will be grayed out until those minimum conditions are met.
  • It does not mean that the False Claims Act claims risk for contractors has decreased. In a self-attestation environment, the accuracy of the assessment remains a critical control. The Department of Justice’s Civil Cyber-Fraud Initiative has resulted in settlements involving contractors that represented compliance they did not have.  Whistleblowers still exist and can report companies that are knowingly committing fraud to the U.S. Government. Contractors should evaluate whether their self-assessments, SPRS scores and supporting documentation can withstand scrutiny.  Remember that the CMMC L2 “Self” tab in SPRS Provides the DOJ a “system of record” for your scores – and the CMMC L2 is recording each control you have marked as met.  That system of record will keep your scores for 6 years.
  • It does not mean existing certifications have lost value. Contractors that have already earned a Level 2 certification hold third-party validation of NIST SP 800-171 implementation, which may remain important to customers, primes and other stakeholders even while Phase II requirements are under review.
  • It does not mean the threat has paused. Adversaries targeting the Defense Industrial Base (DIB) are not waiting on a task force report. The requirement to protect CUI exists because sensitive defense information continues to be actively targeted.


What is Currently Under Review by the DoW

What appears to be under review is the delivery mechanism: who evaluates implementation, how often assessments occur and how/when certification requirements are incorporated into solicitations. The standard itself has not changed.

The DoW’s reasoning also reflects a concern many contractors have raised: legacy compliance approaches can be costly, administratively burdensome and difficult for small and mid-sized innovators to sustain. The directive emphasizes speed to capability, lower barriers for small and non-traditional businesses, and tangible cyber hygiene rather than administrative overhead.

This is not compliance going away. It is a reminder that compliance activities should be practical, risk-aligned, and tied to meaningful data protection for the Government’s most sensitive but unclassified data flowing through contractor systems.

Contractors do not necessarily need to rebuild their entire enterprise network to handle CUI safely. In many cases, organizations may be able to construct a purpose-built secure enclave, keep commercial operations out of scope where appropriate, automate technical controls and make the cost of compliance more predictable. The objective should be real data protection supported by clear evidence, not administrative checklists that do not reduce risk.


Takeaways

TakeawayRecommendation
Phase I of the CMMC Rollout is still in effect.
CMMC L1/L2 “Self” SPRS tab self-attestations, SPRS NIST 800-171 self-attestations for DFARS 7012
Phase II of the CMMC Rollout is paused for now pending task force review

Officers using DFARS 252.204-7025 in solicitation provisions for new contracts/new options years, requiring CMMC certification as a condition of award is paused.  

Contractors should continue to self-attest in SPRS (1)NIST and 2) CMMC self-attest Tabs) as Phase I is still in effect.

CMMC Third-Party Assessor Organizations (C3PAOs) are still conducting assessments
Continue with scheduled C3PAO assessments, continue to self-attest your CMMC/NIST scores in SPRS.  Don’t pause any progress you have made on CMMC until the DoW reveals their task force recommendations.
DFARS 252.204-7012 is still active in contracts; this has not been affected.
Do not dismantle compliance programs solely to save budget. NIST SP 800-171 Rev. 2 remains unchanged; only one enforcement mechanism is paused.
Contract cyber clauses and requirements currently in your existing contracts aren’t changing.
Talk to your RPO or C3PAO before making significant decisions. Requirements already included in signed contracts do not go away because future solicitations have changed.  Only new contracts so far are being affected in alignment with the certification requirements in DFARS solicitations provisions for new contracts.  Clauses already in your contracts may still remain as-is.
Prime Contractors still have existing contracts with CMMC Phase I rollout obligations and flow-downs to subs.
Watch the flow-downs. Prime contractors will continue to require evidence of cybersecurity implementation from their supply chains, regardless of changes to future solicitation requirements.
There is a DoW RFI submitted to the public to request input on the future of CMMC certifications and cost to industry and especially small business.

If CMMC has or is impacting your organization, consider responding to the RFI if compliance costs, timing or assessment requirements have affected your business. The 60-day review period is an opportunity for industry to provide input on the record.

How BDO Can Help

For more than 100 years, BDO USA has been recognized as a premier accounting, tax, and advisory organization for our exceptional client service; experienced, accessible service teams; focus on quality and efficiency; and our ability to adapt to, and navigate successfully in, a changing marketplace. BDO’s government contracting team works with organizations across the defense industrial base to strengthen documentation, prepare for customer or government assessment expectations, and align CUI protection efforts with broader business and contract requirements 

As a CMMC Registered Practitioner Organization (RPO), BDO has built an IT security compliance team that possesses a deep bench of advanced degrees in Cybersecurity and Information Assurance combined with over 30 years of experience supporting cybersecurity and IT programs in information technology, information assurance, and cybersecurity. BDO’s professionals consist of cybersecurity and information assurance specialists with multiple industry cybersecurity certifications and extensive years of experience in designing cyber solutions for the most demanding threat environments. Our team includes CMMC-certified Registered Practitioners and CMMC Certified Assessors with relevant cybersecurity industry certifications.


Contact a member of our team to learn more.