CMMC Phase Two Is Paused. Here's What Defense Suppliers Should Do Now.
August 10, 2026
.png?width=900&name=Breaking%20News%20(1).png)
Manufactured with Speed and Precision
The manufacturing capabilities you need and the engineering support you want, all from a single partner.
Submit a DesignKey Points
- The suspension is real, but temporary: DoD has paused CMMC phase two third-party assessment requirements and launched a 60-day review, but phase one self-assessment requirements remain in effect.
- Phase two uncertainty doesn't mean zero obligation: Suppliers handling controlled unclassified information still need to meet NIST SP 800-171 standards, regardless of what happens to third-party audit timelines.
- Small businesses are the stated driver: DoD CIO Kirsten Davies cited compliance costs, assessment capacity shortages, and regulatory complexity as active barriers pushing suppliers out of the defense industrial base.
- The program will be restructured, not eliminated: The review is explicitly tasked with finding a replacement framework, so suppliers who stop preparing now will be behind when the new requirements land.
- Use this window deliberately: The 60-day review period is time to close gaps in documentation, cybersecurity hygiene, and internal controls, not time to stand down.
DoD Just Hit Pause on CMMC Phase Two
The Cybersecurity Maturity Model Certification (CMMC) program hit another inflection point on July 13, 2026. According to Federal News Network, DoD Chief Information Officer Kirsten Davies signed a memo suspending phase two of the CMMC rollout, which would have required third-party assessments across all contracts involving sensitive but unclassified information starting November 10, 2026.
The suspension also pauses all pending and future CMMC milestones "until further notice." A 60-day reform task force has been stood up to recommend a replacement framework.
Phase one requirements, which mandate CMMC self-assessments on applicable contracts, went into effect in November 2025 and remain active. That's the floor suppliers are still operating against right now.
Why DoD Is Pulling Back
Davies' memo is direct about the problem. The current CMMC program, in her words, "imposes significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses that are the engine of American innovation."
The memo cites three compounding problems: prohibitive compliance costs, a severe shortage of qualified CMMC third-party assessment organizations (C3PAOs) to conduct audits, and regulatory timelines that small businesses can't realistically meet. SBA Administrator Kelly Loeffler echoed this, stating that CMMC compliance "was becoming an untenable barrier pushing [small businesses] out of the Defense Industrial Base."
This isn't a novel concern. The Biden administration paused the original CMMC program in 2021 over similar issues, which led to the stripped-down CMMC 2.0 framework. The Pentagon then spent years working through rulemaking before CMMC 2.0 went into effect in November 2025. Now, less than a year later, the program is under review again.
Davies' stated goal for the reform task force is a framework that "prioritizes speed to capability, lowers barriers for small, medium, and non-traditional businesses, and replaces prohibitive, third-party compliance models with scalable, realistic security measures."
That's a significant shift in emphasis. Whatever emerges from this review will look different from what was on the books as of July 13.
Essential Background Reading:
- Guide to CMMC: A foundational overview of the CMMC framework, its levels, and what defense contractors need to understand before diving into compliance specifics.
- CMMC Resource Center: Comprehensive collection of CMMC guidance, documentation tools, and compliance resources for defense suppliers at every stage.
- DFARS and CMMC Resources: Covers the intersection of DFARS regulations and CMMC requirements, including what contractors must satisfy under both frameworks.
- Cybersecurity in Aerospace Defense: What aerospace and defense suppliers must do now to meet evolving cybersecurity requirements across the supply chain.
What This Means for Suppliers in the DIB
The instinct to stop CMMC prep work is understandable. The instinct is also wrong.
The underlying cybersecurity standards haven't changed. NIST SP 800-171, which forms the technical backbone of CMMC Level 2, still defines what contractors must do to protect controlled unclassified information (CUI). The suspension affects the assessment mechanism, not the underlying requirement to protect CUI.
Suppliers who use this window to close documentation gaps, remediate known vulnerabilities, and build repeatable cybersecurity processes will be positioned to move quickly when the replacement framework arrives. Suppliers who treat the suspension as a reprieve will face compressed timelines and a harder path to compliance under whatever new model emerges.
The 60-day task force is working fast. Davies has tasked it with recommendations, not a rulemaking process. Whatever comes out of that work could move into contracts faster than the original CMMC timeline did.
Related Content:
- CMMC Certified Manufacturing: How CMMC-certified manufacturing operations handle CUI, documentation, and access controls within a production environment.
- CMMC for Subcontractors: What CMMC compliance means specifically for subcontractors in the defense industrial base, including flow-down requirements.
- CMMC Level 2 Requirements: A detailed breakdown of what CMMC Level 2 demands, how it maps to NIST SP 800-171, and what suppliers need to demonstrate.
- Midsize Suppliers Reshaping Aerospace and Defense: How midsize suppliers are changing their role in the defense supply chain and what compliance requirements mean for their positioning.
Actions Worth Taking During the Review Period
The suspension creates a window with a defined end. These are the actions worth prioritizing now:
- System Security Plan (SSP) review: Ensure your SSP accurately reflects your current environment, not your intended state. Self-assessment scoring under phase one depends on this document being current and defensible.
- CUI data mapping: Know exactly where CUI lives in your systems, who can access it, and what controls are applied. This is foundational regardless of what the new framework requires.
- Gap remediation prioritization: Use the NIST SP 800-171 practices as your checklist. Identify which controls have open findings and assign owners with realistic closure dates.
- Enclave boundary documentation: If you've implemented a CMMC enclave strategy to limit your assessment scope, document the boundary decisions and the rationale. This will matter under any future framework.
- Third-party assessment readiness: Even if C3PAO timelines shift, government-led assessments are still occurring. Your controls need to hold up regardless of who is reviewing them.
The table below maps the current state of CMMC requirements following the July 13 suspension:
| Requirement | Status as of July 13, 2026 |
|---|---|
| Phase 1 self-assessments (applicable contracts) | Active |
| Phase 2 third-party assessments (C3PAO) | Suspended |
| Government-led assessments | Continuing |
| Future CMMC milestones | Suspended until further notice |
| NIST SP 800-171 compliance obligation | Unchanged |
| 60-day reform task force | Active |
Next Steps:
- CMMC Certified FIP Gasket Dispensing: How form-in-place gasket dispensing is performed within a CMMC-certified environment for defense hardware applications.
- CMMC Certified CNC Machining: CNC machining services that operate within a certified CMMC environment, maintaining full traceability and access controls.
- Vertical Integration Under CMMC: How vertically integrated suppliers reduce lead times while maintaining CMMC compliance across all manufacturing functions.
- Defense Supply Chain CMMC Verification: A guide to CMMC verification requirements within defense supply chains, including how to evaluate and qualify suppliers.
The Broader Pattern Suppliers Need to Recognize
CMMC has now been paused, restructured, and reviewed multiple times across two administrations. The common thread isn't political instability. It's structural: third-party assessment capacity can't scale fast enough to cover 80,000 companies without squeezing out the small businesses DoD is simultaneously trying to attract.
Whatever the reform task force recommends will have to solve that math problem. Based on Davies' memo language, the likely direction points toward government-led verification models, tiered compliance based on contract risk levels, or both. Neither outcome eliminates the need for suppliers to maintain strong cybersecurity hygiene and accurate documentation.
The suppliers who move fastest when the new framework lands are the ones who treated the current pause as time to build, not time to wait.
See It In Action:
- DoD Telecommunications Case Study: How Modus Advanced supported a DoD telecommunications program with precision manufacturing inside a compliant, traceable production environment.
- Modus Achieves CMMC Level 2: The story of how Modus Advanced achieved CMMC Level 2 certification and what it means for defense manufacturing security standards.
- CMMC Compliant Build-to-Print Manufacturing: How build-to-print manufacturers can achieve and demonstrate CMMC compliance on defense contracts.
Built for the Mission
Modus Advanced holds CMMC Level 2 certification and operates under AS9100, ISO 9001, and ITAR registration. For defense program teams evaluating suppliers during this period of CMMC transition, working with a partner who already meets the underlying cybersecurity requirements removes one variable from a complicated compliance picture. Let's solve this together.
