Pentagon suspends CMMC Phase II cybersecurity requirements for defense contractors
The Department of War on July 13, 2026, immediately suspended the next phase of cybersecurity requirements for companies participating in the defense industrial base, changing a requirement that had been scheduled to take effect Nov. 10.
The department said it will conduct a comprehensive review of the Cybersecurity Maturity Model Certification program, known as CMMC. The review is intended to align the program with Secretary of War Pete Hegsethโs Acquisition Transformation System directives.
The suspension affects CMMC Phase II requirements. Phase I self-assessment requirements remain in place, meaning the action does not eliminate all CMMC obligations for defense contractors.
What changed for contractors
CMMC is the federal cybersecurity compliance program for companies that participate in the defense industrial base. Its requirements are intended to govern how those companies protect sensitive government and military information while carrying out federal defense work.
Phase II had been scheduled to become effective on Nov. 10, 2026. The departmentโs announcement removes that immediate deadline while the broader review is underway.
For companies seeking or holding federal defense contracts, the change affects the timing and scope of cybersecurity compliance obligations. Contractors that were preparing for Phase II will now face a different timetable, while Phase I self-assessments continue to apply.
The department described the review as part of a wider effort to change how defense acquisition operates. Its stated goals include faster delivery of capabilities, lower barriers for small and medium-sized businesses, and broader access for nontraditional suppliers.
Why the review matters
The CMMC program sits at the intersection of defense contracting and cybersecurity. Requirements placed on contractors can affect which companies are able to compete for federal work and what steps they must take to protect information connected to government and military programs.
Suspending Phase II could give businesses more time before they must meet that phaseโs requirements. It also creates uncertainty for companies that have already invested in preparations based on the Nov. 10 effective date.
The practical effect will depend on what the department does after reviewing the program. A faster or less burdensome system could make it easier for smaller and nontraditional suppliers to participate in the defense market, consistent with the goals stated in the announcement. At the same time, the program concerns protections for sensitive information, so changes to compliance requirements may affect how those protections are implemented across the contractor market.
The suspension itself is not a permanent repeal of CMMC. Phase I self-assessments remain in force, and the department has not announced that all cybersecurity requirements for defense contractors have been removed.
What happens next
The departmentโs next step is the comprehensive review of CMMC and its alignment with the Acquisition Transformation System directives. The announcement did not set a date for completing the review or specify what replacement requirements, if any, will follow it.
Until further action, companies in the defense industrial base will need to account for the continued Phase I self-assessment requirements while monitoring the departmentโs decisions about Phase II and the future structure of the program.
Sources
- Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements, Department of War, Office of Small Business Programs
Look for updates to this story
Discover more from Interactive News
Subscribe to get the latest posts sent to your email.