The Department of War (DoW) announced that it has suspended CMMC Phase 2 requirements effective July 13, 2026, pausing the certification tier originally set to take effect on November 10, 2026. The move follows Small Business Administration data showing compliance costs were pushing innovative companies out of the Defense Industrial Base. Phase I self-assessment requirements stay in place, and every DIB subcontractor is still on the hook for NIST SP 800-171.
If you’ve been racing toward a Phase 2 deadline, that race is on hold, but the underlying cybersecurity requirements you’ve been working toward have not gone anywhere.
Key Takeaways
- The Department of War suspended CMMC Phase 2 requirements on July 13, 2026, with no new effective date announced.
- Phase I self-assessment requirements and DFARS clause 252.204-7012 obligations remain fully in force.
- DIB subcontractors must still meet NIST SP 800-171 Rev 2 through self-assessments and select government-led reviews.
- A new CMMC Reform Task Force will deliver recommendations to the DoW CIO.
Table of Contents
Why is The Department of War Suspending CMMC Phase 2 Requirements?
The DoW cited Small Business Administration data showing that CMMC compliance costs were forcing innovative companies out of the Defense Industrial Base, threatening the delivery of capabilities to warfighters.
DoW Chief Information Officer Kirsten A. Davies tied the decision directly to Secretary Pete Hegseth’s push to cut compliance barriers for small and medium-sized businesses.
Does Suspending CMMC Phase 2 Change Your NIST 800-171 Obligations?
No. Every defense contractor and subcontractor is still required to protect covered defense information under DFARS clause 252.204-7012. During this interim period, the DoW will enforce compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments, with a focus on cyber hygiene rather than paperwork.
See the Department of War’s cybersecurity resources on the DoW CIO Brilliant Basics page. The is the Department’s hub for cyber hygiene resources while the CMMC Reform Task Force does its work.
The Department is also standing up a CMMC Reform Task Force to review the certification program from the ground up. That task force will pull in industry feedback from the Department’s public Request for Information on compliance challenges and deliver recommendations to the DoW CIO within 60 days.
What Should DIB Subcontractors Do While CMMC Phase 2 is Suspended?
Keep building toward NIST SP 800-171 compliance instead of pausing your program, since that is the standard the Department of War is actually enforcing right now. Watch for the CMMC Reform Task Force’s recommendations. Contractors who treat this suspension as a reason to deprioritize cybersecurity risk falling behind once a revised CMMC framework arrives.
Contact an advisor today to explore how we can help you meet your cybersecurity and compliance needs.




