CMMC Phase II Requirements Suspended: What Defense Contractors Need to Know

The Department of War has announced the suspension of CMMC Phase II requirements, pausing the planned rollout of mandatory third-party cybersecurity assessments while it conducts a 60-day review of the program. The goal is to reduce compliance burdens, particularly for small and mid-sized defense contractors, while preserving competition and innovation across the Defense Industrial Base.

What does this mean for contractors?

✅ Third-party CMMC Level 2 assessments are temporarily on hold.
✅ Self-assessments remain in effect where applicable under current Phase I requirements.
✅ Organizations should continue strengthening their cybersecurity posture rather than viewing this as a reason to delay.

While this announcement provides temporary relief, cybersecurity expectations aren’t going away. Organizations that continue investing in NIST SP 800-171 alignment, documentation, and security maturity will be better positioned for future contract opportunities – regardless of how the CMMC program evolves.

This is a reminder that compliance is more than checking a box; it’s about protecting sensitive information and building resilience across the defense supply chain.

Source: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/