top of page

CMMC Phase 2 Rollout Hits Pause: What It Means for Defense Suppliers

Yesterday, the U.S. Department of Defense/Department of War (DoD/DoW) issued a press release officially pausing Phase 2 of Cybersecurity Maturity Model Certification (CMMC) rollout. In this post, we’ll dig into the announcement and what it means for organizations pursuing compliance. Yes, you still need to meet the requirements! 

Pause menu showing the text: "C3PAO status: paused."

On July 13, 2026, the DoD/DoW issued a press release entitled Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements. In the announcement, the Department immediately suspended Phase 2 of the CMMC Phased Implementation Plan and established a CMMC Reform Task Force to review the program and provide a report within 60 days.

According to the press release, this pause has been instituted to review the substantial impacts of CMMC requirements on small and midsized defense contractors. As an organization working closely with small businesses in the DIB, we’ve seen the technological, financial, and operational burden achieving compliance places on our customers—especially when it comes to the cost of a C3PAO assessment.

In this respect, it’s welcome news for the organizations which comprise the backbone of the defense industrial base, but it also raises questions about how organizations should respond.

What Was Going to Happen in Phase 2?

Phase 1 of CMMC implementation began on November 10, 2025 and kickstarted the inclusion of CMMC Level 1 and Level 2 self-assessments in DoD/DoW solicitations.

Originally, Phase 2 was scheduled to begin on November 10, 2026, at which point applicable solicitations would begin including CMMC Level 2 certification by a C3PAO as a requirement. This is what is currently on hold.

Is CMMC Going Away?

The short answer is: no. The DoD’s press release specifies that it will continue to enforce CMMC Phase 1 (self-assessment) requirements and that implementing the underlying practices defined in NIST SP 800-171 (Rev. 2) are is still a contractual obligation for defense suppliers according to DFARS 252.204-7012.

It’s worth remembering: CMMC does not mandate cybersecurity practices. CMMC is the verification mechanism to ensure contractors are meeting their cybersecurity obligations under existing regulations. While the enforcement mechanisms may change as a result of this pause and review process, the CMMC program and underlying security requirements are not going anywhere.

Should We Still Be Working Towards CMMC Compliance?

Absolutely! DoD solicitations may still require Level 2 compliance via self-assessment as a condition of contract award in the interim. Furthermore, the DoJ has continued cracking down on suppliers found to have misrepresented their cybersecurity compliance status—including a settlement of $500K from a small defense contractor announced just last month.

Failing to achieve compliance, regardless of whether C3PAO assessment requirements change, means a company could be ineligible for future contract awards and potentially at risk of penalties. Additionally, it’s possible that prime contractors may still require their subcontractors to undergo assessment by a C3PAO in order to limit their risk of non-compliance due to contractual flowdown requirements.

So, What Should We Do about the CMMC Rollout Pause?

Continue working towards CMMC compliance! Level 2 self-assessments may still be required, and contractors are still obligated to safeguard covered defense information per DFARS 252.204-7012. Regardless of whether C3PAO certification is reinstated for small businesses, the practices defined in NIST SP 800-171 create a foundation of security that's relevant for all organizations operating in the 21st century!

Closing Thoughts

Yesterday’s announcement from the DoD indicates their desire to ensure small and midsize businesses aren’t boxed out of defense contracts, but it has also muddied the waters within the DIB regarding CMMC—as if it hasn’t already been chaotic enough! Regardless, organizations should continue their efforts to achieve CMMC compliance because Level 2 self-assessments and the underlying DFARS obligations aren’t going anywhere.

Want to join the discussion and impact the future of the CMMC program? Submit a response to the DoD’s new RFI: Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB).

About Triumvirate Cybersecurity

Triumvirate Cybersecurity is a CyberAB Registered Practitioner Organization (RPO) specializing in CMMC compliance for small and mid-size defense contractors. Based in Dayton, Ohio, we help organizations make sense of the requirements, implement effective security programs, and achieve compliance with confidence.

Ready to level up your journey towards compliance? Reach out through our Contact page or directly via email to info@triumviratecyber.org.

_edited.jpg

Sign up for our newsletter to get exclusive updates

By submitting this form, you are providing your consent for Triumvirate Cybersecurity to contact you about its products and services. We will not sell your information to third parties, per our Privacy Policy.

Recent Posts
LinkedIn
CyberAB-RPO-Badge.png
Navigation

Home    About    Services    Pricing    Insights

31 S. Main Street, Suite 040, Dayton, OH 45402

(937) 203-8443    CAGE: 9ZW92

© Triumvirate Cybersecurity 2026

bottom of page