CMMC Phase II Requirements Suspended: What Defense Contractors Need to Know
The Department of War has announced the suspension of CMMC Phase II requirements, pausing the planned rollout of mandatory third-party cybersecurity assessments while it conducts a 60-day review of the program. The goal is to reduce compliance burdens, particularly for small and mid-sized defense contractors, while preserving competition and innovation across the Defense Industrial Base.
What does this mean for contractors?
✅ Third-party CMMC Level 2 assessments are temporarily on hold.
✅ Self-assessments remain in effect where applicable under current Phase I requirements.
✅ Organizations should continue strengthening their cybersecurity posture rather than viewing this as a reason to delay.
While this announcement provides temporary relief, cybersecurity expectations aren’t going away. Organizations that continue investing in NIST SP 800-171 alignment, documentation, and security maturity will be better positioned for future contract opportunities – regardless of how the CMMC program evolves.
This is a reminder that compliance is more than checking a box; it’s about protecting sensitive information and building resilience across the defense supply chain.


