CMMC Phase 2 Is Paused: What Defense Contractors Should Do Next
The Pentagon’s decision to suspend Phase 2 of the Cybersecurity Maturity Model Certification program has created new uncertainty across the defense industrial base. However, the most important point for defense contractors is clear:
CMMC Phase 2 may be paused, but the responsibility to protect federal information has not been paused.
The suspension primarily affects the planned expansion of mandatory third-party CMMC assessments. Existing cybersecurity requirements, including self-assessments and protections for Federal Contract Information and Controlled Unclassified Information, remain in effect.
For contractors, this is not the time to abandon cybersecurity preparation. It is an opportunity to shift the focus from preparing for an assessment deadline to building cybersecurity practices that work every day.
What Changed With CMMC Phase 2?
On July 13, 2026, the Pentagon announced the immediate suspension of CMMC Phase 2 requirements, which had been scheduled to take effect on November 10, 2026. It also established a CMMC Reform Task Force to conduct a comprehensive 60-day review of the certification program.
Under the original implementation schedule, Phase 2 would have introduced CMMC Level 2 certification requirements, to be conducted by authorized third-party assessment organizations (C3PAOs), in applicable solicitations and contracts.
The suspension also pauses future implementation milestones while the department considers how to reduce compliance expenses, lower barriers for small and nontraditional businesses, and create a more scalable cybersecurity accountability model.
The review does not necessarily mean that CMMC will disappear. It means that the Pentagon is reconsidering how certification, self-assessment, government oversight, and automated compliance tools should work together.
What CMMC Requirements Remain in Place?
Although the Phase 2 rollout is suspended, Phase 1 self-assessment requirements remain active.
During the review period, applicable procurement requirements may continue to rely on:
- CMMC Level 1 self-assessments for organizations handling Federal Contract Information
- CMMC Level 2 self-assessments for organizations handling Controlled Unclassified Information
- Select government-led cybersecurity assessments.
- Additional cybersecurity protections required by applicable laws, regulations, or contract terms
CMMC Level 1 addresses the basic safeguarding requirements for Federal Contract Information. Level 2 aligns with NIST Special Publication 800-171 Revision 2 and addresses the protection of Controlled Unclassified Information.
Contractors and subcontractors also remain responsible for complying with applicable contract clauses, including DFARS 252.204-7012, which covers safeguarding Covered Defense Information and reporting cyber incidents. The Pentagon specifically emphasized that suspending Phase 2 does not eliminate the requirement to protect federal data.
In other words, the assessment process may change, but the underlying security responsibilities have not.
Why Did the Pentagon Pause CMMC Phase 2?
CMMC was created to provide greater assurance that defense contractors had properly implemented required cybersecurity controls. However, industry participants have raised concerns about the expense, administrative burden, and availability of third-party assessments.
The Pentagon said these challenges were creating barriers for small, medium-sized and nontraditional businesses seeking to enter or remain in the defense industrial base. Its review will examine how to preserve cybersecurity accountability without unnecessarily restricting competition or slowing the delivery of capabilities to the military.
That creates a difficult but necessary balancing act.
Defense information must be protected against increasingly capable adversaries. At the same time, cybersecurity requirements must be realistic enough for smaller suppliers, manufacturers, and technology companies to implement.
The likely question is no longer whether defense contractors will be accountable for cybersecurity. The question is how that accountability will be measured and verified.
What Should Defense Contractors Do During the CMMC Pause?
1. Continue Implementing Required Security Controls
Organizations should not interpret the suspension as permission to stop working toward NIST SP 800-171 alignment or other contractual cybersecurity requirements.
The controls involved in CMMC address real operational risks, including access management, incident response, system monitoring, configuration management, and the protection of sensitive information. These practices remain valuable regardless of what the final certification process looks like.
2. Review the Accuracy of Self-Assessments
The temporary emphasis on self-assessment does not make documentation less important.
Contractors should be prepared to demonstrate how controls are implemented, who is responsible for them, and what evidence supports each assessment response. An optimistic score that cannot be supported by policies, system configurations, logs or operational practices can create significant risk.
Cybersecurity teams should treat self-assessment as an evidence-based evaluation, not a paperwork exercise.
3. Strengthen the People Responsible for Cybersecurity
Security controls are only effective when employees understand how to perform them.
A policy may say that an organization monitors security events, responds to incidents and manages privileged access. The real question is whether its workforce can carry out those responsibilities under pressure.
Role-based cybersecurity training can help administrators, analysts, managers and technical teams understand both the control requirement and the operational activity behind it.
4. Test Cybersecurity Readiness in Realistic Scenarios
Documentation can show that a process exists. It does not always prove that the process will work during an attack.
Hands-on labs, cyber ranges, and scenario-based exercises can help organizations evaluate whether their teams can:
- Detect suspicious behavior
- Investigate alerts
- Escalate potential incidents
- Contain compromised systems
- Preserve evidence
- Communicate during an incident.
- Restore operations safely
This kind of validation supports more than compliance. It helps organizations identify weaknesses before an adversary finds them.
5. Monitor Official CMMC Guidance
The CMMC Reform Task Force is expected to evaluate options for lowering compliance burdens while maintaining meaningful cybersecurity protections.
Contractors should monitor the official CMMC program page for updated implementation guidance rather than relying entirely on unofficial summaries or assumptions.
Organizations should also review active solicitations and contracts carefully. The implementation guidance directs contracting officials to amend certain solicitations and contracts that include suspended CMMC Level 2 third-party or Level 3 government assessment requirements.
Could Automation Become a Larger Part of CMMC?
One possible direction for CMMC reform is greater use of automated security validation and machine-readable compliance information.
The National Institute of Standards and Technology’s Open Security Controls Assessment Language, or OSCAL, provides standardized formats for representing security controls, system security plans, assessment plans and assessment results. These formats are designed to support automation, traceability and continuous monitoring.
Automated tools cannot completely replace human judgment. Still, they can reduce repetitive documentation and make it easier to continuously evaluate security controls rather than preparing for a single assessment.
That would represent an important shift: from proving compliance at a single point in time to demonstrating security performance over time.
Cybersecurity Readiness Matters More Than the Certification Label
The future structure of CMMC may be uncertain, but the threat facing the defense industrial base is not.
Defense contractors possess technical data, intellectual property and sensitive operational information that remain attractive targets for nation-state adversaries and other threat actors. Whether an organization is preparing for a self-assessment, third-party certification or government review, it must still be able to protect that information.
The strongest response to the CMMC Phase 2 pause is not to stop preparing. It is to make preparation more operational.
Organizations should use this period to validate controls, improve documentation, train responsible personnel, and test whether their cybersecurity processes work under realistic conditions. No matter what the Pentagon’s review produces, those investments will continue to support contract readiness, operational resilience and national security.
Applied Technology Academy helps government organizations and defense industry teams build practical cybersecurity capabilities through instructor-led training, certification preparation and hands-on technical learning. By developing the people responsible for implementing and maintaining security controls, organizations can move beyond checklist compliance and build cybersecurity practices that stand up to real-world threats.
Frequently Asked Questions
Has CMMC been canceled?
No. The Pentagon suspended the transition to CMMC Phase 2 and future implementation milestones while it conducts a 60-day review. Phase 1 self-assessment requirements remain in place.
Are defense contractors still required to protect CUI?
Yes. Contractors handling Controlled Unclassified Information remain responsible for applicable safeguarding requirements, including those associated with NIST SP 800-171 and DFARS 252.204-7012.
Should companies stop preparing for CMMC certification?
Companies should not stop strengthening their cybersecurity programs. The certification structure may change, but the underlying security controls and contractual responsibilities remain important. Organizations should review their specific contracts and continue building evidence-based, operational cybersecurity practices.
What is the difference between CMMC Level 1 and Level 2?
CMMC Level 1 focuses on basic safeguarding practices for Federal Contract Information. CMMC Level 2 aligns with NIST SP 800-171 and applies to organizations responsible for protecting Controlled Unclassified Information.