Last year, we noted in a couple posts that the federal government had finally began implementation of its Cybersecurity Maturity Model Certification (CMMC) Program. Apparently, however, the government has concluded that a pause is needed on further implementation due to what it describes as structural issues with the program. On July 13, 2026, the Department of War (DoW)[1] announced that it is suspending the introduction of Phase Two of the Cybersecurity Maturity Model Certification (CMMC) Program. We explore that decision in this post.
As provided in 32 C.F.R. § 170.3, implementation of the CMMC Program is (or, at least for now, was) to occur in four separate phases. Phase 1 began on the effective date of the Department’s final rule amending DFARS to incorporate the program, which was November 10, 2025. With Phase 1, the requirements for CMMC Level 1 status and Level 2 (Self)[2] status was to be added where applicable for any new DoW contracts, and it permitted the agency to require CMMC Level 2 (C3PAO) instead of Level 2 (Self) at its discretion where CMMC Level 2 (Self) where, in future phases, Level 2 (C3PAO) would apply.
Phase 2 was to begin one calendar year from the start of Phase 1, meaning November 2026. With this Phase, where CMMC Level 2 (C3PAO) would otherwise be required for a contract or solicitation, it must be required going forward for all such new contracts and solicitations. Note, this phase permitted DoW to hold off on requiring that Level 2 (C3PAO) status until the beginning of an option period at DoW’s discretion. Furthermore, it permitted DoW to require CMMC Level 3 (DIBCAC) in new solicitations and contracts where it would otherwise be applicable in future phases.
On July 13, 2026, plans changed. DoW announced that it was going to pause further implementation of the CMMC Program and do some review of the same. In its memorandum, the DoW states that it found the CMMC Program, as currently set up, as having some significant issues. To quote: “The combination of prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines is actively forcing innovative new entrants and small businesses to opt out of DoW contracts and freezing critical suppliers out of the market.” In other words, the current and future phases impose too many costs and complexities on small businesses, and there’s not enough third-party assessors lining up to carry out the assessments for CMMC Level 2 (C3PAO) and above.
As such, the implementation of Phase 2 is now suspended until further notice, along with Phases 3 and 4. Furthermore, DoW contracts shall only include the need for CMMC Level 1 and Level 2 (Self) assessments for the time being. DoW is also setting up a “CMMC Reform Task Force” to conduct a thorough review of the CMMC Program over a 60-day period. This task force will, as the name suggests, recommend reforms to the Program to make it more efficient, with an eye towards helping smaller businesses. The memorandum also observes that compliance with NIST SP 800-171 Revision 2 will continue to be enforced and that DFARS 252.204-7012 shall remain in effect, so contractors should not treat this as an abandonment of cybersecurity by any means.
So, what does this all mean for you, the contractor? Well, it’s important to emphasize that this doesn’t mean that the government is scrapping the CMMC Program. It’s suspending the implementation of Phases 2 through 4, not getting rid of the whole thing. That said, if you were working towards meeting the requirements of Level 2 (C3PAO) or higher, you now have some more time to reach that goal. How long the suspension will be is anyone’s guess, but it feels reasonable to assume that it won’t be just for a few weeks. We think, with the 60-day review, a duration of at least a couple months is likely.
As for what might be the outcome of this review, it would seem that the government is looking to make compliance with the CMMC Program easier on small businesses. What that might entail is a difficult question to predict. For its part, SBA has noted its approval of this suspension, and its observations provide some clues on what might be addressed. In a statement published the same day as the suspension, SBA Administrator Kelly Loeffler noted that compliance with the CMMC Program was potentially going to cost up to $600,000 for businesses endeavoring to meet the Level 2 (C3PAO) requirements. No doubt such would be very difficult for many small businesses. Furthermore, the statement indicates that there are only roughly 100 approved third-party assessors for what would be over 120,000 small business entities seeking assessment. It is not difficult to see the bottleneck that such a situation would produce.
With these observations, it seems that this pause is a reasonable course of action. Again, it is important to note this does not mean that Level 1 (Self) and Level 2 (Self) requirements are being put on pause as well. The CMMC Program is still active; it just isn’t going to be implemented in full as quickly. This is not a time for DoW contractors to rest on their laurels. They should still be reviewing compliance requirements. But it may be reasonable to pause implementing the requirements of the higher levels a little, while we wait on the government to update the CMMC Program.
Questions about this post? Or need government contracting legal assistance? Email us.Looking for the latest government contracting legal news? Sign up for our free monthly newsletter, and follow us on LinkedIn, Twitter and Facebook.
[1] The memorandum comes from the DoW, and so we are utilizing that. You should read “DoW” and “DoD” as interchangeable in the regulations and any other documents.
[2] Note, “Self” means self-assessment, whereas “C3PAO” and “DIBCAC” refer to outside party assessments.
