DOD Pauses CMMC Rollout During Program Review – What Contractors Need to Know

Published: July 14, 2026

Federal Market AnalysisCybersecurityDEFENSEPolicy and LegislationSmall Business

The Pentagon is suspending plans to require third-party assessments this fall, but the underlying standards remain in place.

Yesterday, the Department of Defense/War (DOD/W) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II contract requirements and the launch of a 60-day review of the CMMC program.

The Phase II contract requirements, which were originally scheduled to go into effect on November 10, 2026, would require contractors handling Controlled Unclassified Information (CUI) to obtain third-party assessments certifying the contractor met the Level 2 requirements by the date of contract award.

This announcement stops that progressive implementation in its tracks, while sustaining that contract requirements should still/only include CMMC Level 1 or Level 2 self-assessments during this period.

Implementation Guidance Points to the Reasons and Restrictions on CMMC

In an accompanying memorandum, Removing Barriers to DIB Expansion, DOD/W Chief Information Officer (CIO) Kirsten Davies noted concerns over the cost and administrative burdens of compliance on contractors – especially small and non-traditional businesses – as well as concerns that the number of available third-party assessors is not large enough to conduct the evaluations needed to meet the upcoming November deadline. Those CMMC aspects are driving small and non-traditional businesses away from pursuing defense contracts, which is in direct conflict with the DOD/W’s larger effort to expand the defense industrial base (DIB) supply chain.

A second memorandum, Implementing Suspension of CMMC Phase II, from Under Secretary of War for Acquisition and Sustainment, Michael P. Duffey, prohibits the inclusion of CMMC Level 2 or Level 3 (third-party assessments) requirements during this period. Any existing solicitations or contracts that include such requirements must be modified to remove them.

What Has Not Changed with CMMC

While the higher CMMC levels are in limbo for now, DOD/W held the line on the lower certification levels. However, both memos sustain the enforcement of baseline compliance with NIST SP 800-171 Rev 2 on cyber hygiene requirements based on self-assessments rather than third-party/administrative compliance for Level 1 and Level 2 (self) compliance. Further, both memos also state that DFARS clause 252.204-7012 regarding the Safeguarding Covered Defense Information and Cyber Incident Reporting remains intact and in effect.

Sixty-Day CMMC Program Review Underway

Davies also launched a CMMC Reform Task Force to conduct a 60-day review of the program and to recommend a reformed cybersecurity framework prioritizing speed to obtain capabilities and reduced burden on small and non-traditional businesses, while maintaining the underlying cybersecurity standards behind CMMC.

As part of the CMMC Reform Task Force’s effort, the DOD/W published a request for information (RFI), Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base (DIB), to seek direct input from DIB companies to help guide the CMMC program review. (See GovWin IQ Opportunity 266465.) Responses are due by 12:00 PM Eastern Time (ET) on Friday, August 14, 2026.

Contractor Implications of the CMMC Pause/Review

Based on the DOD/W announcement and memos, here are three contractor implications:

  • Near-term compliance burden is reduced, but not eliminated. During the 60-day review (and until further guidance is issued), contractors should expect self-assessment (L1 and L2) requirements to be included in new and amended solicitations. DOD/W is clear that the higher CMMC Level 2 and Level 3 are currently in suspension while under review, not repealed. DFARS 252.204-7012 and NIST SP 800-171 Rev 2 baseline obligations remain in force, and contractors handling Federal Contract Information (FCI) and/or CUI still carry those safeguarding and reporting responsibilities.
  • Active solicitations and contracts with Level 2 or Level 3 (third-party) requirements will be amended to remove them. For existing contracts with these requirements, removal will occur via modification before the next option period or next scheduled administrative modification, meaning contractors should watch for amendments/modifications on affected instruments rather than assume automatic changes.
  • No waivers will be granted, and the review's outcome will set the next set of rules. Since program offices are already restricted to only setting Level 1 and Level 2 (self) designations, no waivers to CMMC requirements will be granted during the review period. By the end of the review period, including industry feedback via the RFI, the CMMC Reform Task Force is to deliver recommendations to the DOD/W CIO, with further guidance to follow at that point. However, no timeline is set for the release of any forthcoming guidance. As such, contractors should treat current situation as interim while watching for the Task Force's recommendations when they become public.

Other In-Flight CUI Regulations to Monitor

It is important to recognize that the cybersecurity priorities and standards driving the CMMC program is not operating in a vacuum. Several other non-Defense efforts are underway to set requirements for contractors handling CUI outside the defense context.

GSA CUI Policy. In January 2026, GSA issued a policy CIO-IT Security-21-112 Rev. 1 which established CUI handling requirements for nonfederal systems that process, store, or transmit GSA data, effective immediately. The policy applies the same NIST standards that are the basis for CMMC across GSA contracts where CUI is processed, whether in civilian or defense contexts.

FAR CUI Rules. There are multiple relevant Federal Acquisition Regulations (FAR) cases under development and/or review that address CUI. FAR case 2017-016 (addressing FAR parts 11, 12, 2.1, 27, 35, 4, 52, 7) has been ongoing for months and potential changes are still under review.

Another relevant FAR case 2026-001 (addressing FAR parts 1, 2, 4, 33, 39, 40, 53) is open for public comments until July 23, 2026. This case includes the following relevant paragraph: “Cloud Services Controls. The rule proposes to update FAR 52.240-7 to state that if the Contractor uses a cloud service provider to store, process, or transmit any CUI identified in SF XXX, the cloud computing service provider must meet security requirements equivalent to those established by the Government for FedRAMP Moderate baseline. This is meant to provide more flexibility to the contractor while ensuring the contractor implements the applicable security requirements.”

Looking Ahead to . . . CMMC 3.0?

In March 2021, the DOD/W initiated a review of their original CMMC program based on feedback from industry that is remarkably similar to the issues driving the latest review. Back then, the Pentagon took roughly nine months – until November 2021 – to unveil CMMC 2.0, which has been the operating model until now.

It is still too early, of course, to assess what changes might come and whether they will be significant enough to dub the program “CMMC 3.0.” It is also difficult to guess how soon after the 60-day review DOD/W may release any program updates or revisions.

Final Thoughts

According to Deltek’s 2026 Clarity survey, roughly 6 in 10 government contractors expect CMMC to apply to their organization and about half anticipate needing a Level 2 certification or above. Those expectations may shift as the DOD/W updates the CMMC program. However, given the underlying NIST standards and DFAR rules remain in place, contractors seeking federal contracts – in both the defense and civilian sectors – should remain vigilant to meet those technical standards and regulatory requirements or risk being shut out of future opportunities.