CMMC Phase II Has Been Suspended (But Not Canceled): What the Pause Means for Each DIB Stakeholder

The Department of War (DoW) dropped a bombshell on July 13, 2026, when it immediately suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program.

The deadline for third-party compliance audits was set for November 10th, 2026. But DoW had another idea in mind. To align with its Acquisition Reform Agenda and remove barriers to innovation, DoW launched a CMMC Reform Task Force. It felt the CMMC program itself had become “structurally incompatible” with the expanding Defense Industrial Base (DIB). This also meant a 60-day window to redesign the program’s structure.

Note that the CMMC Phase II suspension is a pause, not a cancellation. The Reform Task Force is reviewing how the program verifies compliance, not whether contractors need to protect Controlled Unclassified Information (CUI). This is an important distinction as we breakdown the stakeholder below:  

Small and Mid-Sized Contractors – Immediate Relief 

Smaller defense contractors are the biggest winners in this. In fact, the Small Business Administration (SBA) commended the decision shortly after.

Compliance costs were nearing almost $600,000 per firm. And it was extremely difficult to procure a Certified Third-Party Assessor Organization (C3PAO), with only about 100 assessors existing for over 100,000 DIB companies. The tight deadline would’ve likely locked many small businesses out of procurement cycles.  

Of course, this is only a relief (and not a permanent decision). Most small contractors would take self-assessments and implement CUI protections over an expensive audit, even if only temporarily.

New Defense Suppliers (per ATS) – Lower Barriers to Entry 

DoW’s Acquisition Transformation System (ATS) is all about “speed to capability.” The goal was to remove any barriers to innovation, even if it meant quickly bringing new companies into the defense supply chain.

Compliance is a massive burden for new entrants in any marketplace. But now, brand new defense suppliers and contractors can enter the DIB and try to win their first contract before third-party certifications are back on the table.

DoW’s Acquisition Reform Agenda – Positive Momentum 

The suspension is a flagship achievement for the reform agenda. It signals that DoW was serious about ensuring faster delivery of capabilities to its warfighters. And if done correctly, the 60-day review and onslaught of Requests for Information (RFIs) give the DoW a chance to redesign the program to match its “tangible cyber hygiene” agenda.

Early CMMC-Adoptors  – Lasting Advantage 

Companies that pushed through CMMC Level 2 certification before the pause are holding onto a head start.

And for certified companies, they’ll also find that private-sector counterparts increasingly prefer working with partners who hold the same standard, regardless of what’s required for contract award. And if the 60-day review reinstates third-party verification in some form (which is a likely outcome), early adopters walk back in already certified, while competitors start from zero.

The honest caveat: there’s no immediate mandate-driven advantage while the pause lasts. But the work, the credential, and the market relationships built around it are durable. The requirement paused; its value didn’t.

C3PAOs – Under Pressure 

C3PAOs are navigating a sudden shift. Their primary line of business (mandatory third-party assessments) went on hold overnight, as did their revenue from it. So it’s understandable that the reaction across the assessor community has been one of uncertainty.  As one expert for National Defense Magazine highlighted, “If I’m a C3PAO, I’m probably very nervous today.”

The pause will likely reshape the assessor market, with some providers consolidating or adjusting their focus.

That said, the need for assessors hasn’t disappeared. Assessors continue to advise clients that certification remains a sound strategic move, and many firms preparing for future prime flow-down demands still have real reasons to pursue it. The volume of voluntary audits may slow while the mandate is paused. But demand tied to specific business relationships and future readiness is likely to continue.

Compliance Consultants and GovCon Lawyers – A Wash

This one is a bit of a mixed bag. The suspension has understandably created some uncertainty. So compliance experts and lawyers may see increased interest from contractors simply looking to understand “what does this mean for me, and what should I be doing now?”

Self-attestation also carries more weight for False Claims Act liability during the pause, so many contractors will benefit from expert guidance to navigate that responsibly.

Longer term? The picture could shift. Because if the 60-day review simplifies the program, or the pause extends well beyond its initial window, the role these advisors play may evolve alongside it.

DoW’s Broader Security Posture – At Risk 

The pause creates a real security gap. Third-party verification, whatever its cost burden, provided a minimum standard check that self-assessments have historically struggled to match. With that check removed, DoW is relying more heavily on self-reported data it can’t independently confirm. 

DoW is trading some supply chain security assurance for speed, at least until the review concludes. Whether the tradeoff pays off depends entirely on what the Reform Task Force builds next.

DoW’s Research & Development Initiatives – More Room to Innovate 

R&D efforts benefit from the same thing that new suppliers do: lower barriers for more innovation.

While protecting R&D data still remains a contractual obligation under DFARS 7012, the compliance overhead is reduced. Non-traditional innovators can prioritize mission-critical work until a new decision is made.

War Fighters / End Users – Toss-Up

We don’t know what the future holds for the end-using war fighters. If they can gain faster access to cutting-edge technology and capabilities, the U.S. armed forces will continue to leap ahead of adversaries.

But if less-secure suppliers are compromised, the integrity of the defense supply chain is at risk.

Only time will tell if the tradeoff pays off. 

With MathCraft, Protect What Matters, Pause or No Pause 

CMMC Phase II is suspended, not canceled. While it’s still under the 60-day review, it does provide some breathing room for contractors.

The news came fast and took some by surprise. MathCraft Security Technologies is here to keep you updated and navigate the changing terrain:

CMMC Phase 2 FAQs

Is CMMC Phase 2 canceled or just paused?

CMMC Phase II requirements are paused, not canceled. The DoW announced an immediate 60-day suspension of Phase II third-party assessment requirements while its Reform Task Force conducts a review.

Does CMMC suspension mean I don’t have to comply with CMMC?

No, the suspension only affects who verifies your compliance (the third-party audit). It does not suspend your obligation to substantively comply with NIST SP 800-171 Rev 2 or DFARS 252.204-7012 .

Do I still need a self-assessment?

Yes. Phase I self-assessment requirements remain active. So contractors must still complete Level 1 or Level 2 self-assessments and submit scores to the Supplier Performance Risk System (SPRS).

What do I still need to comply with?

Everything, excluding the Phase II third-party audit, remains in full force. You still need to comply with DFARS clause 252.204-7012, NIST SP 800-171 Rev 2, CMMC Phase I self-assessments (Level 1 and Level 2), and SPRS reporting. DoW can also still audit your firm directly.

Scroll to Top