Blog Post Cover

Exploring the Cause and Impact of the CMMC Phase 2 Suspension

by Kerry Rea on 07/22/2026
Share with

The Cybersecurity Maturity Model Certification (CMMC) program is a framework that requires companies contracting with the Department of Defense (DoD) to meet security standards based on the sensitivity of the data they manage. The latest version of the program went into effect in November of 2025. At that time, companies contracting with the DoD had to self-certify that they comply with 15 controls—specified by the National Institute of Standards and Technology's (NIST) SP 800-171—that cover basic cyber hygiene. 

Phase 2, set to begin in November of 2026, would have required contracts dealing with Controlled Unclassified Information (CUI) to be verified through a third-party assessment of compliance with all 110 controls in the NIST standard. That requirement has now been paused. 

What Does the Suspension Mean? 

DoD Chief Information Officer Kirsten Davies issued an announcement about the Phase 2 suspension on July 13. Since Phase 2 had not yet started (meaning there is no current enforcement of third-party assessments) there is no immediate change to contractor requirements. Contractors must still comply with Phase 1 self-attestation rules. 

The suspension exists to allow the DoD 60 days to do a full review of the CMMC program and Phase 2 requirements. According to the announcement, the review is to ensure CMMC is aligned with the Defense Secretary’s Acquisition Transformation System directives, which focus on “lowering barriers for small, medium, and non-traditional businesses, and replacing bureaucratic compliance with scalable, resilient cybersecurity measures.” 

In simple terms, the review is intended to ensure that CMMC requirements do not act as a barrier to small, innovative companies offering needed and cutting-edge products and services to the DoD. The newly established CMMC Reform Task Force will conduct this review of the certification program. The review entails analyzing feedback submitted through a public request for information to determine if changes should be made to lower barriers of entry for companies providing solutions the DoD needs.

Reasons for Review

The CMMC has long faced criticism for potentially being too time-consuming and too expensive for the vast majority of companies to be able to comply. 

A report from the Government Accountability Office in March said that current requirements might prove too difficult and costly for some small businesses to meet. Studies have found that a Level 2 third-party assessment could cost as much as $150,000 to $800,000 in upfront expenses alone. Recent data from the Small Business Administration, gathered from a tour of small to medium-sized businesses across America, found that CMMC compliance was “the number one topic” that came up in conversation. 

Even if a company can afford it, there is concern that there will not be enough assessors to meet demands. As many as 70,000 contractors may need this higher certification. Estimates say there are fewer than 100 certified third-party assessment organizations (3PAOs) in place. While there are efforts to fill out the needed workforce by November 2026, there would likely be a large backlog. 

What’s Next?

The task force has 60 days to complete its review and issue recommendations. By late September, there should be a path forward for security accreditation in the DoD, whether that is following current policy or introducing a revised or new program. 

In the meantime, companies must still comply with self-attestation and should continue working toward the requirements of Phase 2, as many aspects of the program will likely still be required, although perhaps in a new way. 

The pause in CMMC Phase 2 should not be viewed as a reason to delay cybersecurity efforts. Instead, it gives contractors additional time to strengthen their security posture while the DoD refines the program. Organizations that continue preparing for enhanced cybersecurity requirements will be better positioned to adapt, regardless of how the certification framework evolves over the coming months. 

Stay informed on the latest CMMC developments and other government cybersecurity initiatives by exploring the events and resources available on GovEvents and GovWhitePapers.


Topics

Event NewsEvent News ArticlesGov/Mil NewsGov/Mil News Articles

Subscribe

Receive the GovEvents newsletter, featuring our freshest events