There has been significant misinformation circulating since the Department of Defense's recent announcement regarding CMMC. To set the record straight: the CMMC program has not been suspended or eliminated.
Who This Affects
This applies to the entire Defense Industrial Base (DIB) — including prime defense contractors and their downstream suppliers and subcontractors. If your organization touches Controlled Unclassified Information (CUI) or handles Covered Defense Information (CDI) at any tier of the supply chain, your cybersecurity obligations remain in force regardless of this announcement.
What Actually Happened
The DoD acknowledged that only about 5% of the organizations requiring third-party accreditation have completed certification — a number projected to reach just 7% by November. Rather than waiving the requirement outright, the Department announced a 60-day review period, effectively pausing Phase II implementation while it evaluates how to reduce compliance burden and better align the program with its broader acquisition reform objectives.
This is a pause — not a cancellation.
What Changes
- The planned November 10, 2026 Phase II implementation date is on hold and will likely slip by approximately one year — not the first time this program has moved to the right
- Pending and upcoming CMMC certification milestones across solicitations and contracts are suspended during the review period
- The DoD is reassessing the program's rollout to streamline requirements and reduce the compliance load on contractors and suppliers alike
What Does Not Change
- Your obligation to protect federal data remains fully intact — the pause does not remove any underlying cybersecurity requirements for prime contractors or subcontractors
- Phase I self-assessments are still required and remain firmly in place at every tier of the supply chain
- DFARS clause 252.204-7012 still applies — any organization handling Covered Defense Information (CDI), regardless of where they sit in the contractor hierarchy, is not relieved of compliance obligations
- NIST SP 800-171 Rev 2 requirements for protecting controlled unclassified information continue unchanged
What This Means for Your Organization
For prime contractors and their suppliers who were actively preparing for Phase II certification, this announcement reduces immediate deadline pressure — but it is not a free pass. The practical shift should be from "race to meet the certification deadline" to "maintain security hygiene and stay ready for program changes."
Downstream suppliers in particular should resist the temptation to deprioritize compliance efforts. Prime contractors will continue to flow down cybersecurity requirements through their contracts, and suppliers who are not ready when the program resumes will find themselves at a competitive disadvantage — or worse, locked out of contract opportunities entirely.
Organizations that use this window to pause their compliance efforts entirely risk falling behind when enforcement resumes, and it will resume.
Bottom Line
This announcement buys time and introduces uncertainty, but it does not alter the fundamental cybersecurity obligations that defense contractors and their supply chains carry. Treat it as an enforcement delay, not a relaxation of federal cyber compliance standards.
