Capabilities
Industries
Quality & Engineering
Resources
About
Learning Center

CMMC Phase Two Is Paused. Here's What Defense Suppliers Should Do Now.

August 10, 2026

CMMC Phase Two Is Paused. Here's What Defense Suppliers Should Do Now.
Manufactured with Speed and Precision

The manufacturing capabilities you need and the engineering support you want, all from a single partner.

Submit a Design

Key Points

  • The suspension is real, but temporary: DoD has paused CMMC phase two third-party assessment requirements and launched a 60-day review, but phase one self-assessment requirements remain in effect.
  • Phase two uncertainty doesn't mean zero obligation: Suppliers handling controlled unclassified information still need to meet NIST SP 800-171 standards, regardless of what happens to third-party audit timelines.
  • Small businesses are the stated driver: DoD CIO Kirsten Davies cited compliance costs, assessment capacity shortages, and regulatory complexity as active barriers pushing suppliers out of the defense industrial base.
  • The program will be restructured, not eliminated: The review is explicitly tasked with finding a replacement framework, so suppliers who stop preparing now will be behind when the new requirements land.
  • Use this window deliberately: The 60-day review period is time to close gaps in documentation, cybersecurity hygiene, and internal controls, not time to stand down.

DoD Just Hit Pause on CMMC Phase Two

The Cybersecurity Maturity Model Certification (CMMC) program hit another inflection point on July 13, 2026. According to Federal News Network, DoD Chief Information Officer Kirsten Davies signed a memo suspending phase two of the CMMC rollout, which would have required third-party assessments across all contracts involving sensitive but unclassified information starting November 10, 2026.

The suspension also pauses all pending and future CMMC milestones "until further notice." A 60-day reform task force has been stood up to recommend a replacement framework.

Phase one requirements, which mandate CMMC self-assessments on applicable contracts, went into effect in November 2025 and remain active. That's the floor suppliers are still operating against right now.

Why DoD Is Pulling Back

Davies' memo is direct about the problem. The current CMMC program, in her words, "imposes significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses that are the engine of American innovation."

The memo cites three compounding problems: prohibitive compliance costs, a severe shortage of qualified CMMC third-party assessment organizations (C3PAOs) to conduct audits, and regulatory timelines that small businesses can't realistically meet. SBA Administrator Kelly Loeffler echoed this, stating that CMMC compliance "was becoming an untenable barrier pushing [small businesses] out of the Defense Industrial Base."

This isn't a novel concern. The Biden administration paused the original CMMC program in 2021 over similar issues, which led to the stripped-down CMMC 2.0 framework. The Pentagon then spent years working through rulemaking before CMMC 2.0 went into effect in November 2025. Now, less than a year later, the program is under review again.

Davies' stated goal for the reform task force is a framework that "prioritizes speed to capability, lowers barriers for small, medium, and non-traditional businesses, and replaces prohibitive, third-party compliance models with scalable, realistic security measures."

That's a significant shift in emphasis. Whatever emerges from this review will look different from what was on the books as of July 13.

Essential Background Reading:

  • Guide to CMMC: A foundational overview of the CMMC framework, its levels, and what defense contractors need to understand before diving into compliance specifics.
  • CMMC Resource Center: Comprehensive collection of CMMC guidance, documentation tools, and compliance resources for defense suppliers at every stage.
  • DFARS and CMMC Resources: Covers the intersection of DFARS regulations and CMMC requirements, including what contractors must satisfy under both frameworks.
  • Cybersecurity in Aerospace Defense: What aerospace and defense suppliers must do now to meet evolving cybersecurity requirements across the supply chain.

What This Means for Suppliers in the DIB

The instinct to stop CMMC prep work is understandable. The instinct is also wrong.

The underlying cybersecurity standards haven't changed. NIST SP 800-171, which forms the technical backbone of CMMC Level 2, still defines what contractors must do to protect controlled unclassified information (CUI). The suspension affects the assessment mechanism, not the underlying requirement to protect CUI.

Suppliers who use this window to close documentation gaps, remediate known vulnerabilities, and build repeatable cybersecurity processes will be positioned to move quickly when the replacement framework arrives. Suppliers who treat the suspension as a reprieve will face compressed timelines and a harder path to compliance under whatever new model emerges.

The 60-day task force is working fast. Davies has tasked it with recommendations, not a rulemaking process. Whatever comes out of that work could move into contracts faster than the original CMMC timeline did.

Related Content:

Actions Worth Taking During the Review Period

The suspension creates a window with a defined end. These are the actions worth prioritizing now:

  • System Security Plan (SSP) review: Ensure your SSP accurately reflects your current environment, not your intended state. Self-assessment scoring under phase one depends on this document being current and defensible.
  • CUI data mapping: Know exactly where CUI lives in your systems, who can access it, and what controls are applied. This is foundational regardless of what the new framework requires.
  • Gap remediation prioritization: Use the NIST SP 800-171 practices as your checklist. Identify which controls have open findings and assign owners with realistic closure dates.
  • Enclave boundary documentation: If you've implemented a CMMC enclave strategy to limit your assessment scope, document the boundary decisions and the rationale. This will matter under any future framework.
  • Third-party assessment readiness: Even if C3PAO timelines shift, government-led assessments are still occurring. Your controls need to hold up regardless of who is reviewing them.

The table below maps the current state of CMMC requirements following the July 13 suspension:

RequirementStatus as of July 13, 2026
Phase 1 self-assessments (applicable contracts)Active
Phase 2 third-party assessments (C3PAO)Suspended
Government-led assessmentsContinuing
Future CMMC milestonesSuspended until further notice
NIST SP 800-171 compliance obligationUnchanged
60-day reform task forceActive

Next Steps:

The Broader Pattern Suppliers Need to Recognize

CMMC has now been paused, restructured, and reviewed multiple times across two administrations. The common thread isn't political instability. It's structural: third-party assessment capacity can't scale fast enough to cover 80,000 companies without squeezing out the small businesses DoD is simultaneously trying to attract.

Whatever the reform task force recommends will have to solve that math problem. Based on Davies' memo language, the likely direction points toward government-led verification models, tiered compliance based on contract risk levels, or both. Neither outcome eliminates the need for suppliers to maintain strong cybersecurity hygiene and accurate documentation.

The suppliers who move fastest when the new framework lands are the ones who treated the current pause as time to build, not time to wait.

See It In Action:

Built for the Mission

Modus Advanced holds CMMC Level 2 certification and operates under AS9100, ISO 9001, and ITAR registration. For defense program teams evaluating suppliers during this period of CMMC transition, working with a partner who already meets the underlying cybersecurity requirements removes one variable from a complicated compliance picture. Let's solve this together.

New call-to-action