The Department of War suspended the transition to CMMC Phase II requirements and other pending or future implementation milestones on July 13, 2026, but it did not suspend cybersecurity obligations. Phase I self-assessment requirements remain in place, DFARS 252.204-7012 still applies, and the Department says it will continue enforcing NIST SP 800-171 Rev 2 through self-assessments and selected government-led assessments during the 60-day review.
CMMC Phase II Suspended: What the 60-Day Review Means for Defense Contractors
CMMC stands for Cybersecurity Maturity Model Certification. It is a U.S. Department of Defense program intended to help ensure that contractors and subcontractors appropriately protect sensitive federal information.
On July 13, 2026, the Department of War announced an immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026. The same announcement launched a 60-day top-to-bottom review of the broader CMMC program.
That headline matters, but the details matter more. This is not a cancellation of cybersecurity obligations for defense contractors. It is not permission to ignore Federal Contract Information (FCI), Controlled Unclassified Information (CUI), or the practical work of maintaining a supportable security baseline.
If you need the broader readiness context first, start with CMMC readiness support, the CMMC readiness guide, and the small-manufacturer resource hub at CMMC resources for small manufacturers.
We can quickly review your setup and show you what’s working and what needs improvement.
Use the IT Cost Savings Calculator to estimate annual waste from recurring support drag, outages, emergency work, and security cleanup before you decide what to prioritize.
Executive summary
| What changed | The Department suspended the transition to Phase II requirements and paused pending and future CMMC implementation milestones across Department of War solicitations and contracts. |
|---|---|
| What did not change | Phase I self-assessment requirements remain in place. Contractors still have to safeguard federal data, and DFARS clause 252.204-7012 still applies. |
| What the Department says will continue | During the interim period, the Department says it will enforce cybersecurity compliance with NIST SP 800-171 Rev 2 through self-assessments and selected government-led assessments. |
| What happens next | A CMMC reform task force has 60 days to review the program, synthesize industry feedback, and recommend more realistic, scalable security measures. |
| What smart contractors should do now | Do not stop readiness work. Recheck scope, strengthen evidence, and separate mandatory current obligations from assumptions about future assessment timing. |
What the Department actually announced on July 13, 2026
The Department of War release used unusually direct language. It announced the immediate suspension of CMMC Phase II requirements, noted that those requirements had been planned for November 10, 2026, and said the Department would begin a comprehensive review aimed at lowering barriers for small, medium, and non-traditional businesses while replacing what it described as bureaucratic compliance with more scalable cybersecurity measures.
The release also said the Department will suspend the transition to Phase II requirements as well as pending and future CMMC implementation milestones across Department solicitations and contracts. That sentence is the core reason contractors are asking whether the schedule has fundamentally changed. The answer is yes on schedule pressure for Phase II, but no on the underlying expectation that contractors protect government information responsibly.
The related Pentagon news coverage reinforced the same point. Department leaders described the current program as too burdensome, especially for small businesses, but repeatedly said cybersecurity remains a nonnegotiable priority. In other words, the Department is challenging the implementation model, not walking away from the security outcome.
What Phase II suspension does and does not mean
The easiest mistake right now is reading the word “suspension” as if the whole CMMC framework disappeared. That is not what the official pages say.
What it does mean
- The Department paused the move into Phase II requirements that had been expected in November 2026.
- Pending and future CMMC implementation milestones tied to that transition are also suspended for now.
- The Department has opened a 60-day review and reform process to gather feedback and recommend changes.
What it does not mean
- It does not remove the need to protect FCI or CUI.
- It does not erase contract obligations tied to safeguarding covered defense information.
- It does not mean that self-assessment, evidence, and technical readiness work can be ignored.
- It does not guarantee that future reforms will be easier for companies with weak scope, weak identity controls, or poor documentation.
The Department of War CIO’s CMMC pages now state that the program is paused in Phase 1. Those same pages also state that the action does not eliminate the requirement for companies to protect information in accordance with DFARS 252.204-7012. That is the key anchor contractors should use when filtering speculation.
What remains in effect right now
If you only remember one section from this article, make it this one. Several obligations remain active even while the Department reviews the Phase II path.
1. Phase I self-assessment requirements remain in place
The Department’s release said it plainly: all Phase I self-assessment requirements remain firmly in place. The CIO site repeats that message. For contractors handling FCI, this matters because the baseline expectations tied to self-assessment have not been set aside.
If your current question is whether your Level 1 position is actually supportable, compare the evergreen guidance on CMMC Level 1 readiness, the intake page at CMMC Level 1 readiness check, and the warning signs on CMMC self-assessment risk.
2. DFARS 252.204-7012 still matters
The Department specifically said this action does not eliminate the requirement for contractors and subcontractors to safeguard covered defense information in accordance with DFARS clause 252.204-7012. That means the suspension should not be treated as a waiver from core data-protection responsibilities.
For many contractors, that is the operational reality check. Whether or not a future milestone slips, contract language and customer expectations still put pressure on access control, endpoint management, backup discipline, incident handling, and evidence collection.
3. NIST SP 800-171 Rev 2 enforcement continues during the interim period
The July 13 release says the Department will enforce cybersecurity compliance with NIST SP 800-171 Rev 2 through self-assessments and select government-led assessments during the review period. The CIO CMMC pages use similar language.
That is a major point for Level 2 conversations. If your business handles CUI, the absence of a near-term Phase II milestone does not suddenly make NIST 800-171 alignment optional. It shifts the timing conversation, not the need for a defensible boundary and evidence trail. If your environment is already wrestling with CUI scope, review the practical baseline on CMMC Level 2 readiness and the planning guidance in our Level 2 readiness roadmap article.
Why the Department says it made this move
The public rationale is consistent across the release, the Pentagon coverage, and the CIO site updates.
- The Department says current CMMC requirements created prohibitive compliance costs and bureaucratic burden, especially for small businesses.
- Leadership said the available pool of assessors was not large enough to handle the upcoming demand.
- The 60-day review is supposed to gather industry feedback and recommend realistic, scalable measures that lower barriers while still improving cybersecurity and resilience.
Whether you agree with that policy direction or not, the practical takeaway for contractors is straightforward: the government is signaling that assessment mechanics may change, but it is not signaling that loose operations, shared accounts, weak evidence, or unclear scope will become acceptable.
That distinction is where disciplined contractors can make better decisions than reactive ones. Mid-article, this is also where it helps to understand why Sun Life Tech emphasizes operational clarity over compliance theater. When timing changes, companies with cleaner systems usually adapt faster than companies that relied on deadlines alone to drive cleanup.
What the 60-day review likely means for different contractor types
Small businesses and new defense entrants
For small companies, the biggest short-term effect is probably breathing room. Businesses that feared the November Phase II date may feel less pressure to rush incomplete documentation or overbuy tools. That breathing room is useful only if it gets turned into real cleanup work.
If you are a newer subcontractor or a regional manufacturer just trying to stay supportable, now is a good time to confirm what data you actually handle, who has access to it, and whether your self-assessment answers match reality. That is usually more valuable than debating rumors about what the task force might recommend.
Contractors already working through Level 1 obligations
For businesses focused mainly on FCI, the official guidance is clear enough to support action: Phase I remains active. If you already affirmed, or you are about to, the question is not whether the Department paused Phase II. The question is whether you can support what your business is currently saying about identity, devices, backups, and day-to-day handling of information.
That is why so many companies end up needing the combination of a simple technical baseline, evidence organization, and practical review. If your environment still depends on shared accounts, vendor shortcuts, or undocumented exceptions, the suspension does not reduce that risk.
Contractors handling CUI and Level 2-style expectations
For contractors handling CUI, the review creates strategic uncertainty but not a reason to pause core remediation. Scope definition, boundary design, access control, logging, documentation, and evidence are still the right work. In fact, they may become even more valuable if the reformed program puts more weight on scalable, operationally credible controls.
Contractors with broad, messy environments should resist the temptation to interpret the pause as permission to delay. Scope confusion compounds cost. It rarely gets cheaper later.
Prime contractors and supplier-management teams
Primes will still need ways to evaluate supplier cybersecurity maturity. Even if government milestones move, supplier questionnaires, contract flow-downs, and internal risk reviews do not disappear overnight. Many primes may become more focused, not less, on whether subcontractors can explain their current safeguards without overselling them.
A practical contractor action plan for the next 60 days
The smartest response to this announcement is disciplined triage, not celebration and not panic.
1. Reconfirm your current obligation set
Start with current contracts, current flow-downs, current handling of FCI or CUI, and any self-assessment or affirmation status your business already relies on. The goal is to separate what is active today from what you assumed would happen in November.
2. Review scope before you review paperwork
Map where government-related data lives, who touches it, which devices are in scope, and what vendors or outside parties still have access. A clean scope review usually exposes more useful work than another round of policy editing.
3. Tighten evidence for anything you already claim
If you say MFA is enforced, confirm it. If you say backups are tested, locate the proof. If you say accounts are reviewed, make sure someone owns that process. The biggest risk after any policy announcement is that teams relax while their current claims remain weak.
4. Avoid overclaiming in customer and prime conversations
Do not let “Phase II was suspended” turn into “we no longer have to worry about this.” That is a poor summary of the official guidance and a risky message to put in writing. Clearer, narrower language is safer: current obligations remain, future milestones are being reviewed, and the business is maintaining or improving its cybersecurity baseline in the meantime.
5. Use the pause to reduce expensive chaos
If you were racing toward November with an unclear plan, use this period to simplify. Clean up identity. Standardize endpoints. Verify backups. Organize your evidence. Clarify ownership. Those are the same moves that support both readiness and real-world resilience.
Common mistakes contractors should avoid right now
| Mistake | Why it is risky | Better move |
|---|---|---|
| Stopping readiness work entirely | Current obligations and customer expectations still exist. | Continue practical remediation and evidence work tied to today’s scope. |
| Treating the suspension like a full CMMC repeal | The official sources do not say that, and contractors can misstate their position. | Use the Department’s narrower language: Phase II and related milestones are suspended, while Phase I and safeguarding obligations remain. |
| Assuming Level 2 work no longer matters | NIST SP 800-171 Rev 2 enforcement is still referenced during the interim period. | Keep working on CUI scope, access control, documentation, and evidence. |
| Focusing only on documents | Weak operations make weak evidence. | Start with scope, identity, endpoints, backups, and ownership. |
| Using vague language with primes or customers | Overstatements create trust and contract risk. | Describe the current state accurately and support it with evidence. |
What this means for Sun Life Tech clients and similar contractors
For most small and mid-sized contractors, the answer is not to build a giant compliance project around headlines. It is to make the environment easier to explain, easier to maintain, and harder to misrepresent.
That usually means a practical sequence:
- confirm whether the business is mainly in an FCI conversation, a CUI conversation, or a mixed environment,
- clean up the systems and users that are already creating risk,
- organize evidence around the controls that really exist, and
- avoid turning preparation help into certification claims.
If you want a grounded next step, use the service overview at CMMC readiness support, compare the level-specific pages for Level 1 and Level 2, and keep the broader article cluster nearby through the CMMC resource hub.
Important disclaimer
This article is for general educational and operational planning purposes only. It is not legal advice, it is not a certification opinion, and it should not replace review of your actual contract language, flow-down requirements, SPRS posture, or advice from qualified legal counsel where needed. Sun Life Tech provides readiness support, technical review, documentation help, and remediation guidance. Sun Life Tech does not guarantee certification or contract outcomes.
FAQ
Did the Department of War cancel CMMC?
No. The official July 13, 2026 announcements say the Department suspended Phase II requirements and related future implementation milestones, but Phase I self-assessment requirements remain in place and the Department continues to require protection of federal data.
Do contractors still have to follow DFARS 252.204-7012?
Yes. The official release explicitly says the suspension does not eliminate the requirement for contractors and subcontractors to safeguard covered defense information in accordance with DFARS clause 252.204-7012.
Does the 60-day review mean Level 2 work should stop?
No. The Department says it will continue enforcing NIST SP 800-171 Rev 2 through self-assessments and selected government-led assessments during the interim period, so contractors handling CUI still need defensible scope, controls, and evidence.
What should a small defense contractor do right now?
Reconfirm current obligations, review scope, tighten evidence for any safeguards already claimed, and avoid overstating what the suspension means in customer or prime-contractor conversations.
Can Sun Life Tech certify a contractor for CMMC?
No. Sun Life Tech provides readiness support, technical review, documentation help, and remediation guidance. It does not act as a certifier, provide legal opinions, or guarantee assessment outcomes.
Official sources
- Department of War press release: Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements
- Pentagon News coverage: War Department Changes Cybersecurity Maturity Model Certification Requirements
- DoD CIO CMMC landing page
- DoD CIO About CMMC page
Need help reviewing where your business stands now?
If the suspension changed your timeline but not your risk, the right next step is usually a clearer view of scope, current controls, and evidence quality before assumptions harden into contract problems.
For a practical baseline, review CMMC readiness support, use the self-assessment risk page if you are worried about unsupported answers, and compare your operating model with how Sun Life Tech structures readiness work.
Review CMMC readiness support
Browse CMMC resources for small manufacturers
Talk with Sun Life Tech about your current position
Recommended resources
These pages map directly to the services and next-step resources behind this topic.
Get the PDF instantly. Use it to tighten your baseline and reduce avoidable incidents.
Continue Learning About Business AI
Keep reading with the most relevant next articles.
CMMC Level 2 Readiness Roadmap: A Practical Plan Aligned to NIST 800-171
A step-by-step Level 2 roadmap: scoping CUI, building the SSP/POA&M, tightening identity and endpoints, and collecting evidence so readiness becomes predictable.
The Risk of Self-Certifying CMMC Level 1 Without Evidence
Why self-certifying CMMC Level 1 without supportable evidence creates avoidable business risk for manufacturers and defense subcontractors.
