CMMC Phase II is paused — your cybersecurity efforts shouldn’t be
- While the DoD has suspended CMMC Phase II implementation, contractors are still expected to protect Controlled Unclassified Information (CUI) and meet core cybersecurity obligations under frameworks such as NIST 800-171 and DFARS requirements.
- Organizations should maintain system security plans (SSPs), POA&Ms, self-assessment results, SPRS records and implementation evidence to support future reviews and help ensure leadership can confidently attest to compliance status.
- Contractors can take advantage of the pause to speak with RPOs to explore reducing CUI scope, improve documentation, strengthen identity and access management, close security gaps and build a more sustainable compliance program that will remain valuable regardless of how CMMC reforms evolve.
The Department of Defense’s recent decision to suspend CMMC Phase II requirements has created uncertainty across the Defense Industrial Base. For many organizations, the immediate questions are simple: Is CMMC going away? Was all our preparation wasted? Should we stop investing in cybersecurity readiness?
The short answer is no.
While the Phase II implementation milestone has been suspended, contractors should avoid interpreting this development as a rollback of cybersecurity expectations. The latest public guidance points to a more nuanced reality: The certification model is under review, but the obligation to protect federal information remains firmly in place.
How defense contractors should respond
Following the DoD’s announcement, defense contractors should still prioritize the following actions:
- Continue implementing NIST 800-171 R2: The security requirement remains the keystone for CUI protection.
- Maintain SSPs, POA&Ms, SPRS/self-assessment evidence: These records support defensible representations and future review readiness.
- Do not overstate C3PAO requirements during the suspension: Current DoD guidance temporarily emphasizes self-assessments while CMMC program reforms are being evaluated.
- Treat voluntary certification as a business decision: Certification may be valuable for prime/customer assurance, but it should be evaluated in context.
- Monitor the reform process and public guidance: The CMMC model may change, and contractors should align decisions with authoritative updates.
- Use the pause to reduce scope and improve evidence: Work with an RPO to right-size your scope, clean boundaries and repeatable evidence collection to reduce long-term compliance friction.
What actually happened?
On July 13, 2026, the Department of Defense announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026.
At the same time, the department announced a comprehensive review of CMMC through a CMMC Reform Task Force focused on reducing unnecessary burden while preserving cybersecurity and operational resilience across the Defense Industrial Base.
That distinction matters. The government paused a certification implementation milestone. It did not eliminate the underlying obligation to safeguard federal information.
The most important distinction: certification versus security
One of the most common misconceptions about CMMC is that certification itself is the objective. It is not. The objective is to protect CUI and other covered federal information handled by defense contractors and subcontractors.
CMMC has historically served as a verification mechanism. The security expectations themselves are rooted in requirements such as NIST 800-171 and DFARS 252.204-7012. Those obligations continue to matter even while the Phase II implementation approach is under review.
What CMMC elements are still in place?
The following key elements remain relevant for contractors:
- Phase I self-assessment requirements remain in place.
- Compliance with NIST 800-171 remains central for organizations handling CUI.
- DFARS 252.204-7012 remains important for safeguarding covered defense information and maintaining cyber incident reporting readiness.
Contractors should continue maintaining system security plans, plans of action and milestones, SPRS-related self-assessment records, evidence of implementation and leadership awareness of what the organization is representing to the government and its customers. False Claims Act exposure can arise when contractors knowingly misrepresent cybersecurity practices, submit inaccurate compliance information or fail to meet material contractual cybersecurity obligations.
What about C3PAOs?
This is where the situation requires precision. The Cyber AB has stated that CMMC ecosystem elements remain operational and available, including C3PAO Level 2 certification assessments, CAICO-sanctioned training, exams, practitioner support and DIBCAC assessment activity for C3PAOs and candidate C3PAOs.
However, DoD implementation guidance also provides an important contracting limitation during the suspension. Program managers are directed to use CMMC level 1 (self) or CMMC level 2 (self) requirements during this period and may not designate CMMC level 2 (C3PAO) or level 3 (DIBCAC) assessments while the review is underway.
In plain English: The ecosystem may still be available, but contractors should not assume that level 2 third-party certification is currently required across applicable DoD awards during the suspension. Voluntary certification may still have business value in specific customer, prime contractor or supplier assurance contexts, but it should be evaluated as a business decision rather than treated as a universal current mandate.
Why continuing CMMC readiness still makes business sense
Even if the formal certification pathway changes, cybersecurity expectations from customers, primes, and the government are unlikely to disappear. Many contractors will still be asked to demonstrate how they protect CUI, assess themselves against NIST 800-171 and track remediation progress.
The pause can be used productively. These activities and controls are always in season:
- Reduce CUI scope
- Incorporate data classification
- Optimize your identity access management
- Run tabletop exercises
- Clean up documentation
Close high-priority POA&M items of your NIST 800-171 gap assessment. These activities retain value whether the future model emphasizes self-assessment, government-led review, third-party assessment or a redesigned hybrid approach.
Watch the reform process closely
The suspension is only one part of the story. The DoD also issued a public Request for Information seeking industry input on reducing compliance costs and administrative burden while improving cybersecurity and operational resilience. The RFI specifically asks for feedback on cost drivers, control effectiveness, commercial cybersecurity capabilities, self-assessment challenges and actionable reform recommendations.
For defense contractors and service providers, this is an important signal. The future of CMMC may be shaped not only by government policy but also by industry feedback about what actually improves security and what creates unnecessary friction.
How Wipfli can help
Wipfli is a Readiness Practioner Organization for CMMC (RPO) with cybersecurity and GRC teams who help organizations move forward confidently regardless of how the final CMMC reform effort unfolds. Rather than focusing solely on certification milestones, we help organizations build sustainable cybersecurity programs that improve security outcomes, satisfy customer expectations and support future compliance requirements. Start a conversation.
Stay ahead of evolving CMMC requirements
Read more
- Tech companies experience thousands of attempted cyberattacks each day. Are your defenses ready for 2026?
- Physical penetration testing is the missing layer for stronger cybersecurity
- Nation-state actors are increasingly launching cyberattacks on businesses and critical infrastructure. How should your organization prepare?