CMMC Phase II on Pause. Here’s What Defense Contractors Should Do Next

July 15, 2026

Written by:

Brad Lyons
Professionals in Discussion in a private office with multiple security screens in view
  • The Department of War suspended CMMC Phase II requirements immediately on July 13, 2026, ahead of their planned November 10, 2026 start date. 
  • Phase I self-assessment requirements and DFARS clause 252.204-7012 obligations remain fully in effect. 
  • A new CMMC Reform Task Force will review industry feedback and report recommendations to the DoW CIO within 60 days. 
  • Contractors should use the pause to strengthen NIST SP 800-171 compliance and close Phase I gaps rather than wait out the review. 

The Department of War announced an immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements on July 13, 2026. Phase II was originally set to take effect on November 10, 2026. The pause gives the Department 60 days to review the program. 

DoW Chief Information Officer Kirsten A. Davies framed the move as part of a broader push to cut compliance costs for small and medium businesses in the Defense Industrial Base (DIB), while still protecting sensitive data. A new CMMC Reform Task Force will review industry feedback and deliver recommendations within 60 days.  

HERE’S WHAT STAYS THE SAME

Phase I self-assessment requirements remain in effect. Contractors and subcontractors still have to protect covered defense information under DFARS clause 252.204-7012. And during the review period, the Department will keep enforcing cybersecurity through NIST SP 800-171 Rev 2, using self-assessments and select government-led reviews. 

For contractors mid-implementation, this is a good moment to keep momentum rather than lose it. Use the pause to close out any Phase I gaps, document your NIST SP 800-171 posture, and stay close to how the task force’s recommendations develop over the next two months. Contractors who keep building through the pause will be in a stronger position once Phase II requirements resume. 

360 Advanced helps defense contractors and subcontractors build cybersecurity programs that hold up under CMMC and NIST SP 800-171 requirements.