Department of War Suspends CMMC Phase 2 Requirements and Launches 60-Day Review
- JV
- Jul 30
- 4 min read
A Pause for C3PAOs Means Full Speed Ahead for Contractor Self-Assessments
The Department of War has suspended the November 2026 transition to CMMC Phase 2, including the Level 2 third-party certification and Level 3 government assessment requirements. Phase 1 self-assessment requirements remain in effect, and applicable contractors must continue to meet the underlying cybersecurity requirements.
What the CMMC Phase 2 Suspension Means
On July 13, 2026, the U.S. Department of War announced in an official memorandum that it is suspending plans to implement Phase 2 of the Cybersecurity Maturity Model Certification program.
During the suspension, program managers and requiring activities may include only CMMC Level 1 or Level 2 self-assessments in procurement requests and requirement documents.
They may not designate Level 2 certification by a Certified Third-Party Assessment Organization (C3PAO) or a Level 3 assessment by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC).
The Defense Federal Acquisition Regulation Supplement clause DFARS 252.204-7012, which requires contractors to safeguard Controlled Unclassified Information (CUI) under NIST SP 800-171, remains in effect.
According to the Department of War’s implementation guidance, active solicitations containing Level 2 C3PAO or Level 3 DIBCAC requirements must be amended to remove those requirements.
For existing contracts that already contain those requirements, contracting officers are directed to remove them before the next option period or during the next scheduled administrative modification.

Please note that Prime contractors must continue to review and flow down the CMMC requirements applicable to each subcontract based on the Federal Contract Information or Controlled Unclassified Information involved.
During the suspension, subcontractors should confirm the requirements in their specific subcontract and any instructions from their prime. Under 32 CFR 170.23 and DFARS 252.204-7021, applicable CMMC requirements may flow down to subcontractors. The Cyber AB states that Level 2 C3PAO assessments remain operational and available and may continue to support subcontractor viability with primes.
The Phase 1 requirement that applicable contracts require a CMMC self-assessment remains in effect under applicable regulations and contract requirements. For applicable Level 2 self-assessments, a score must still be recorded in the Supplier Performance Risk System (SPRS) and be defensible.
During the suspension, the Department of War will continue to rely on self-assessments and select government-led assessments. Contractors subject to CMMC Level 2 requirements must continue to meet the underlying requirements, including:
Complying with all 110 security requirements in NIST SP 800-171 Revision 2; and
Ensuring their System Security Plan (SSP) is up to date and accurate.

Inaccurate or inflated self-attestation scores can create exposure under the False Claims Act. In June 2026, the Department of Justice announced a $507,144 settlement resolving allegations that a defense contractor failed to meet contractual cybersecurity requirements.
The related settlement agreement states that the contractor had reported a perfect SPRS score of 110, but a later government assessment produced a substantially lower result.
The False Claims Act authorizes civil penalties and treble damages. Separately, fraud, false statements, and serious contract violations may support suspension or debarment proceedings under FAR Subpart 9.4, including the causes listed in FAR 9.406-2 and FAR 9.407-2.
Why The CMMC Phase 2 Requirements Pause Matters
The memorandum suggests that the CMMC program conflicts with Defense Secretary Pete Hegseth’s Acquisition Transformation System initiative, which intends to foster innovation and eliminate bureaucracy.
The Department of War will focus on “tangible cyber hygiene rather than third-party certifications and bureaucratic, high-cost-imposing red tape.”
Importantly, this is a policy pause rather than a regulatory repeal. The Department of War has neither rescinded the CMMC Program rule under 32 CFR Part 170 nor amended the DFARS, so the requirements could be reinstated quickly.
Although the government no longer requires Level 2 third-party assessments during the suspension, C3PAOs continue to operate, and voluntary certification assessments remain available.
According to the Cyber AB’s statement on the Phase 2 suspension, C3PAO Level 2 assessments remain operational, and certification may continue to support subcontracting viability with primes.

What to Expect From the 60-Day CMMC Review
In addition to suspending Phase 2, the Department of War announced plans to establish a CMMC Reform Task Force. Within 60 days, the task force is scheduled to conduct a comprehensive review of the CMMC program and deliver its findings to Kirsten Davies, the Pentagon’s Chief Information Officer.
The Department of War also issued a Request for Information, “Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base,” inviting stakeholder feedback. Responses are due by August 14, 2026.
The 2021 review of the CMMC program under the Biden Administration ultimately led to CMMC 2.0, a scaled-down program that reduced the number of maturity levels from five to three to streamline the program.
While we cannot predict similar outcomes from this review, we can anticipate additional program guidance resulting from the review period.
The best strategy moving forward is to continue working toward compliance with all 110 NIST SP 800-171 security requirements, keeping you in the best position to protect CUI if a C3PAO assessment is required by the government or your prime.
Being assessment-ready can put your company ahead. Delaying progress can cost you valuable time, especially if deadlines are suddenly shortened. Regardless of what happens, protecting CUI and being recognized as a secure supplier can position your company for success.

About Fortalice Solutions
Fortalice is a cybersecurity firm specializing in cyber incident response, cyber risk management, and cybersecurity for executives, chosen by leaders who need elite, discreet support when cyber incidents threaten operations, reputation, and leadership credibility.
Founded by former White House CIO Theresa Payton, who served in a position defined by trust, discretion, and decision-making at the highest levels, Fortalice brings national-level experience and seasoned judgment to high-pressure, time-sensitive situations where decisions cannot wait and mistakes are costly.
The firm integrates cyber advisory, cyber incident response, technical testing, executive digital protection, and training into a unified approach shaped by real-world incidents and human decision-making, delivering clear, actionable guidance trusted by both executive leadership and security teams.
Connect with Fortalice to ensure trusted, discreet expertise is in place before, during, and after a cyber incident.


