Department of War Suspends CMMC Phase 2 Requirements

DoW Suspends CMMC Phase 2 Requirements

The Department of War (DoW) announced that it has suspended CMMC Phase 2 requirements effective July 13, 2026, pausing the certification tier originally set to take effect on November 10, 2026. The move follows Small Business Administration data showing compliance costs were pushing innovative companies out of the Defense Industrial Base. Phase I self-assessment requirements stay in place, and every DIB subcontractor is still on the hook for NIST SP 800-171.

If you’ve been racing toward a Phase 2 deadline, that race is on hold, but the underlying cybersecurity requirements you’ve been working toward have not gone anywhere.

Key Takeaways

  • The Department of War suspended CMMC Phase 2 requirements on July 13, 2026, with no new effective date announced.
  • Phase I self-assessment requirements and DFARS clause 252.204-7012 obligations remain fully in force.
  • DIB subcontractors must still meet NIST SP 800-171 Rev 2 through self-assessments and select government-led reviews.
  • A new CMMC Reform Task Force will deliver recommendations to the DoW CIO.

Table of Contents

Why is The Department of War Suspending CMMC Phase 2 Requirements?

The DoW cited Small Business Administration data showing that CMMC compliance costs were forcing innovative companies out of the Defense Industrial Base, threatening the delivery of capabilities to warfighters.

DoW Chief Information Officer Kirsten A. Davies tied the decision directly to Secretary Pete Hegseth’s push to cut compliance barriers for small and medium-sized businesses.

“In support of Secretary Pete Hegseth's directive to reduce compliance barriers for small and medium sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program.”
Kirsten A. Davies
DoW Chief Information Officer
Does Suspending CMMC Phase 2 Change Your NIST 800 171 Obligations​

Does Suspending CMMC Phase 2 Change Your NIST 800-171 Obligations?

No. Every defense contractor and subcontractor is still required to protect covered defense information under DFARS clause 252.204-7012. During this interim period, the DoW will enforce compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments, with a focus on cyber hygiene rather than paperwork.

See the Department of War’s cybersecurity resources on the DoW CIO Brilliant Basics page. The is the Department’s hub for cyber hygiene resources while the CMMC Reform Task Force does its work.

The Department is also standing up a CMMC Reform Task Force to review the certification program from the ground up. That task force will pull in industry feedback from the Department’s public Request for Information on compliance challenges and deliver recommendations to the DoW CIO within 60 days.

"Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness. We believe the DIB can achieve both, while we reduce unnecessary government red tape."
Kirsten A. Davies
DoW Chief Information Officer

What Should DIB Subcontractors Do While CMMC Phase 2 is Suspended?

Keep building toward NIST SP 800-171 compliance instead of pausing your program, since that is the standard the Department of War is actually enforcing right now. Watch for the CMMC Reform Task Force’s recommendations. Contractors who treat this suspension as a reason to deprioritize cybersecurity risk falling behind once a revised CMMC framework arrives.

Contact an advisor today to explore how we can help you meet your cybersecurity and compliance needs.

img Cayden author section.webp

Cayden Crowise is a marketing copywriter at Teal with over three years of experience creating content focused on managed IT services, AI, automation, cybersecurity, compliance frameworks, and emerging technologies.

Trained in professional writing and marketing communications, Cayden specializes in translating complex topics into outcome-focused guidance for IT leaders, executives, government contractors, and growing organizations.

Their work supports businesses navigating security risk, operational maturity, and business growth.

Recent Articles

The Insider's Edge

The right IT strategies can transform your business. Subscribe now to access curated strategies, trends, and solutions for forward-thinking executives like you.

Categories
Don’t Stop Here

More To Explore

CMMC Assessment Preparation

Best Practices for CMMC Assessment Preparation

The best practices for CMMC assessment preparation are drawn from what C3PAO assessors consistently find, what contractors underestimate, and what separates organizations that pass CMMC