Insight

CMMC Phase II Requirements Are Suspended: What Defense Contractors Need to Know

Client Alerts

On July 13, 2026, the Department of War (DoW) announced that it was immediately suspending Phase II of its Cybersecurity Maturity Model Certification (CMMC) program, citing concerns about the program’s impact on small, medium, and non-traditional defense contractors and their ability to deliver critical capabilities to DoW. The decision marks a significant change of direction from DoW’s years-long effort to launch CMMC as a means of replacing self-assessments of cybersecurity compliance with a third-party verification system. While the suspension of the CMMC verification requirements signals a potential easing of compliance burdens for defense contractors, they should remain aware that the underlying cybersecurity requirements have not changed, thereby presenting continuing compliance challenges and the significant risk of False Claims Act (FCA) enforcement.

In this alert, we provide a summary of DoW’s decision to suspend, for now, the requirement for assessments by CMMC Third-Party Assessment Organizations (C3PAOs) and the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) as prerequisites to contract awards while DoW conducts a 60-day review to determine the future of the CMMC program.

Background on CMMC and the Phased Rollout

As discussed in a prior update,1 the CMMC program established a certification framework requiring defense contractors to demonstrate cybersecurity compliance at three levels:

  1. Level 1 requires implementation of 15 basic security practices to protect Federal Contract Information (FCI), with contractor self-assessment.
  2. Level 2 requires implementation of 110 security controls under National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 to protect FCI and Controlled Unclassified Information (CUI), with self-assessment or C3PAO certification.
  3. Level 3 requires implementation of all Level 2 controls plus 24 enhanced requirements under NIST SP 800-172, with government-led assessment.

Requirements for Level 1 or Level 2 self-assessments (CMMC Phase I) went into effect on November 10, 2025. The next implementation phase (CMMC Phase II) to require mandatory Level 2 C3PAO certifications was set to begin on November 10, 2026, although some procuring activities had already begun to include Phase II requirements in solicitations.

The small business community, among other stakeholders, has long raised concerns about the cost and compliance burdens on companies associated with performing self-assessments and obtaining third-party assessments. In addition, the limited number of approved C3PAOs was notably hindering the ability for contractors to obtain the required third-party assessment that would be required to proceed with winning new contracts after the Phase II rollout. Thus, with the deadline for Phase II implementation looming, there was a real risk that numerous current DoW contractors would no longer be eligible to compete for and win new contracts upon the implementation of the third-party attestation requirements.

DoW’s Decision to Suspend Phase II Requirements

On July 13, 2026, the DoW Chief Information Office (CIO) issued a memorandum suspending implementation efforts for C3PAO and certain government-led assessments immediately, pending a 60-day strategic review of the CMMC program.2 DoW justified the suspension and review by citing compliance costs for small businesses, insufficient C3PAO capacity to assess thousands of contractors, and complex regulatory timelines pushing nontraditional defense contractors out of the defense industrial base.

As a part of the 60-day CMMC review, DoW also published a request for information inviting defense contractors to provide feedback regarding the 110 NIST SP 800-171 controls that comprise the underlying CMMC Level 2 standards against which contractors are assessed. Responses are due on August 14, 2026.

Following the suspension announcement, the Under Secretary of War for Acquisition and Sustainment approved the public release of a memorandum for DoW acquisition personnel.3 Significantly, the memorandum directs program offices and requiring activities to include only CMMC Level 1 and Level 2 self-assessment requirements in future solicitations and to amend already-issued solicitations to remove Level 2 C3PAO or Level 3 government-led assessment requirements. Of particular note, the memorandum directed Contracting Officers to remove any Level 2 C3PAO or Level 3 government-led assessment requirements from existing contracts via contract modification prior to the next option period or during the next scheduled administrative modification.

Remaining Cybersecurity Obligations

Contractors should take note of what the CMMC suspension does and does not do. DoW has (for now) suspended the third-party assessment requirements as a prerequisite to being awarded new contracts; but DoW has not eliminated defense contractors’ existing obligation to substantively comply with the NIST 800 171 v2 cybersecurity controls. The following provisions remain firmly in place and binding on contractors:

  • DFARS 252.204-7012: Under this clause, which is required to be incorporated in all DoW contracts involving CUI, defense contractors must safeguard defense-related CUI, by implementing the 110 security controls in NIST SP 800-171 v2 and report cyber incidents within 72 hours.
  • SPRS Scoring and Annual Affirmation: Defense contractors must maintain current cybersecurity assessment scores in the Supplier Performance Risk System (SPRS) and submit annual affirmations of compliance with the cybersecurity requirements.
  • FedRAMP Requirements: Cloud service providers handling CUI must continue to meet FedRAMP Moderate baseline requirements, and defense contractors handling CUI must utilize compliant cloud services.
  • CMMC Self-Assessment Requirements: Level 1 and Level 2 self-assessment requirements remain in place. Defense contractors must continue to conduct self-assessments and maintain current scores.

Continued Cybersecurity Enforcement

The DoW CIO memorandum confirms that DoW will continue to exercise its separate authority to conduct cybersecurity compliance verification assessments of contractors. The suspension removes government-led assessments only as a contract award condition, and DoW has not curtailed the standing authority of DIBCAC to audit any defense contractor’s implementation of NIST SP 800-171 controls as part of ongoing contract administration and enforcement.

Further, the suspension of CMMC implementation does not diminish the ongoing risks of potential liability for cybersecurity non-compliance under the FCA. Alleged misrepresentations related to cybersecurity and compliance with applicable contract requirements are an ongoing area of focus for the Department of Justice (DOJ) and qui tam whistleblowers known as relators. DOJ is actively pursuing FCA investigations involving alleged misrepresentations of cybersecurity compliance status, which may be discovered through a DIBCAC cybersecurity audit.4 Without C3PAO certifications, self-assessment certifications and SPRS score submissions will continue to be an area of potential exposure for companies, as evidenced by recent DOJ settlements. Defense contractors must ensure that their self-certified cybersecurity submissions accurately reflect their actual compliance status.

Government-Wide Priority on Cybersecurity and Information Protection

Despite the 60-day suspension of CMMC implementation, cybersecurity and information protection remains a Government priority. On June 23, 2026, as part of the Revolutionary FAR Overhaul, the FAR Council published a proposed rule that would establish Government-wide safeguarding requirements for CUI. If finalized, the rule would require all federal contractors handling CUI to implement NIST SP 800-171 v3 security controls.5 The proposed rule would also harmonize CUI incident reporting at 72 hours across the federal Government, aligning with the existing DFARS standard. Thus, even if the cybersecurity compliance certification regime under CMMC changes as a result of DoW’s strategic review, CUI protection obligations are poised to expand beyond DoW to all federal agencies, reinforcing the importance of maintaining robust cybersecurity programs.

Conclusion

DoW’s decision to suspend CMMC is, as of now, a temporary step, but it signals a potential reversion to the self-assessment regime that CMMC was supposed to replace. The cybersecurity threats facing the Government and the Defense Industrial Base continue to expand, and companies will be expected to comply with existing cybersecurity requirements and to combat new threats to the disclosure of sensitive Government information as they arise. The suspension provides a 60-day reprieve from third-party and government-led assessment requirements as contractual prerequisites, but it does not diminish the substantive cybersecurity compliance obligations that defense contractors must satisfy. Moreover, cybersecurity remains a Government priority, as evidenced by the recently proposed FAR amendment to expand CUI protection requirements Government-wide, signaling that certain cybersecurity compliance obligations and compliance with existing NIST 800-171 standards may expand in scope regardless of CMMC’s fate. Defense contractors should continue to review the cybersecurity requirements in their existing contracts, ensure their self-certifications accurately reflect their compliance posture, and monitor developments on CMMC reform.


1 https://www.velaw.com/insights/dod-releases-final-cmmc-program-rule-formally-initiating-its-cybersecurity-program/

2 https://dodcio.defense.gov/Portals/0/Documents/Library/CMMC-ReformMemo.pdf

3 https://dodcio.defense.gov/Portals/0/Documents/Library/ImplementingSuspensionCMMC-PhaseII.pdf

4 https://www.justice.gov/opa/pr/false-claims-act-settlements-and-judgments-exceed-68b-fiscal-year-2025

5 https://www.federalregister.gov/documents/2026/06/23/2026-12559/federal-acquisition-regulation-revolutionary-federal-acquisition-regulation-overhaul-parts-1-2-4-33


This information is provided by Vinson & Elkins LLP for educational and informational purposes only and is not intended, nor should it be construed, as legal advice.

Discover our latest:

Insights

CLE Events

Texas Reincorporation 101: Recent Developments and Key Considerations for Boards

Join Vinson & Elkins and FTI Consulting for a webinar on the growing trend of companies reincorporating to Texas.

October 1, 2026

October 1, 2026 • 1-minute read

CLE Events

Financing and Bankability of Data Center Projects

This program will examine the key legal and commercial considerations for financing data center projects, with a focus on what makes these projects bankable for lenders and investors.

September 29, 2026

September 29, 2026 • 1-minute read

Events

Paige Anderson to Speak on BARBRI Webinar

Partner Paige Anderson will speak on BARBRI’s live video CLE program, “Mastering Public and Private REITs: Key Tax, Structuring, Financing, …

September 22, 2026

September 22, 2026 • 1-minute read

Events

Paige Anderson and Vinay Prabhakar to Present on REIT Tax and Data Centers in Upcoming myLawCLE Webinar

Partners Paige Anderson and Vinay Prabhakar will present on myLawCLE’s live CLE program, “REIT Tax in the Data Center Era: …

September 18, 2026

September 18, 2026 • 1-minute read

Articles

Four Antitrust Pathways to AI Lab Coordination

The debate over AI lab coordination has collapsed into a false binary. There are at least four paths forward. In …

September 17, 2026

September 17, 2026 • 8-minute read

News & Achievements
V&E

Get in Touch

Thoughts or questions? Send us a note, and we’ll connect you with the right person.

The ESG GC: How Your Role as Chief Legal Officer is Integral To Your Company’s ESG Efforts Background Image