Key Points

  • DoD suspended CMMC Phase II on July 13, 2026, halting the November 10, 2026, deadline and all related implementation milestones pending a comprehensive reform review by a newly established CMMC Reform Task Force. 
  • CMMC Level 2 (C3PAO) and Level 3 (DIBCAC) third-party assessment requirements are suspended, and active solicitations and contracts must be amended to remove those designations during the suspension period. 
  • Core cybersecurity obligations remain enforceable: DFARS 252.204-7012, NIST SP 800-171 Rev. 2 compliance, cloud security requirements, and cyber incident reporting duties are all still in effect. 
  • The SBA estimates CMMC third-party certification costs can reach approximately $593,800 per small firm, a burden cited as a key driver of the suspension and of small contractor attrition from the defense industrial base. 
  • Defense contractors have until August 14, 2026, to submit RFI responses and directly influence the design of the reformed CMMC program. 

On July 13, 2026, the U.S. Department of Defense/War (DoD/W) announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements — scheduled to take effect on November 10, 2026 — pending a top-to-bottom review by a newly established CMMC Reform Task Force. The announcement, formally titled “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of Cybersecurity Maturity Model Certification Requirements,” came as a surprise reversal after years of rulemaking activity stretching back to 2019. In addition to the announcement, DoD/W published an implementation memo outlining the procedural rollout of the CMMC suspension. For defense contractors and their compliance teams, the suspension raises immediate practical questions about what changes, what remains, and what comes next.

1. Key Takeaways for Defense Contractors

  • Phase II is suspended immediately. The November 2026 deadline for CMMC Phase II transition is suspended, and all pending and future CMMC implementation milestones across DoD/W solicitations and contracts are held in abeyance until further notice. 
  • Phase I and II self-assessment requirements remain in effect. CMMC Level 1 (Self) and Level 2 (Self) assessments are still required. Program managers and requiring activities may only designate these two assessment types in solicitations and contracts going forward. 
  • Third-party certification requirements are off the table for now. CMMC Level 2 (C3PAO) and Level 3 (DIBCAC) assessments may not be designated during the suspension period. Active solicitations and contracts containing these requirements must be amended or modified to remove them. 
  • Core DFARS cybersecurity obligations remain. The suspension does not affect contractors’ foundational cybersecurity obligations. DoD/W will continue enforcing baseline compliance with NIST SP 800-171 Rev. 2. Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, is still in effect, as are NIST SP 800-171 Rev. 2 compliance requirements, cloud security obligations, and cyber incident reporting duties. 
  • Industry has a 60-day window to shape the future program. DoD/W has issued a request for information (RFI) seeking industry feedback on reforming CMMC by utilizing existing commercial cybersecurity capabilities, optimizing self-attestation capabilities, and streamlining cybersecurity compliance requirements. Responses are due August 14, 2026. 

2. Why DoD/W Acted

The suspension reflects mounting pressure from small business stakeholders, the Small Business Administration (SBA), and the Defense Industrial Base (DIB) at large. DoD/W’s announcement cited “prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines” as structural incompatibilities with its goal to rapidly expand the defense industrial base. The SBA, which issued its own commendation of the suspension, estimates that CMMC compliance costs can reach approximately $593,800 per certification for small firms requiring third-party assessment, and approximately $388,600 for firms eligible for self-assessment — burdens the SBA states have caused many small contractors to exit or consider exiting defense work entirely.

3. The CMMC Reform Task Force and What Comes Next

DoD/W’s chief information officer is immediately establishing a CMMC Reform Task Force charged with conducting a 60-day comprehensive review of the certification program. Its mandate: recommend a reformed cybersecurity framework that accelerates capability, reduces barriers for small and nontraditional businesses, and replaces costly third-party compliance models with scalable security measures.

4. Practical Guidance and Recommendations

  • Do not stand down on cybersecurity compliance. DFARS 252.204-7012 obligations, NIST SP 800-171 Rev. 2 requirements, and Level 1 and 2 self-assessment requirements remain intact and enforceable. 
  • Review active solicitations and contracts. If your solicitation or contract currently requires CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) certification, expect — and monitor for — amendments and modifications from the contracting activity removing those requirements. 
  • Consider participating in the RFI. The DoD/W RFI (Notice ID: DoDCIOReformingCMMCforDIB001, due August 14, 2026) presents a direct opportunity for contractors to influence how the reformed CMMC program is designed. 
  • Stay alert to Task Force recommendations. The Task Force’s 60-day review will conclude with reform recommendations that could significantly reshape CMMC requirements. Contractors should monitor announcements closely and be prepared to adapt compliance strategies accordingly. 

This article is intended for general informational purposes only and does not constitute legal advice. Receipt of this article does not establish an attorney-client relationship. Defense contractors should consult with qualified legal counsel regarding their specific CMMC and DFARS compliance obligations. For more information, please contact the authors.

© 2026 Troutman Pepper Locke LLP. All rights reserved.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Michael Barnicle Michael Barnicle

Michael offers litigation, compliance, and corporate transactional services across government contracting and international trade, including national security and cybersecurity. His understanding of federal contracting and global commerce enables him to help clients anticipate issues, mitigate risk, and achieve business objectives.

Photo of Hilary Cairnie Hilary Cairnie

An experienced and sought-after strategist, Hilary Cairnie counsels clients in nearly all types of government contracting matters.

Photo of Peter Jeydel Peter Jeydel

Pete helps clients navigate today’s increasingly complex regulatory and enforcement environment at the intersection of national security, international trade, finance, and technology. He works with clients to identify innovative solutions to business problems arising from these often daunting and highly technical regulations, based

Pete helps clients navigate today’s increasingly complex regulatory and enforcement environment at the intersection of national security, international trade, finance, and technology. He works with clients to identify innovative solutions to business problems arising from these often daunting and highly technical regulations, based on a clear understanding of the government’s expectations and priorities.

Photo of Lu Reyes Lu Reyes

Lu is a former senior U.S. government official with a wealth of experience advising U.S. and international clients with complex regulatory and enforcement challenges. He has extensive experience representing clients facing state or federal government investigations and enforcement actions, conducting internal investigations, and…

Lu is a former senior U.S. government official with a wealth of experience advising U.S. and international clients with complex regulatory and enforcement challenges. He has extensive experience representing clients facing state or federal government investigations and enforcement actions, conducting internal investigations, and advising corporate clients on regulatory compliance practices and in crisis response scenarios. As an accomplished legal strategist, Lu provides counsel to CEOs, CLO’s, and other executives, as well as boards of directors across various industries on a myriad of complex issues.

Photo of Bryan Williamson Bryan Williamson

Bryan advises clients on a range of complex government contracts and national security matters. His experience as a government contracts litigation attorney in the U.S. Army Judge Advocate General’s (JAG) Corps gives him unique perspective on navigating the complexities of doing business with…

Bryan advises clients on a range of complex government contracts and national security matters. His experience as a government contracts litigation attorney in the U.S. Army Judge Advocate General’s (JAG) Corps gives him unique perspective on navigating the complexities of doing business with the government.

Photo of Bonnie Gill Bonnie Gill

Bonnie is an associate in the firm’s Regulatory Investigations, Strategy + Enforcement Practice Group, where she counsels clients in all stages of federal and state enforcement actions, related civil litigation, corporate compliance, and internal investigations. She also handles matters before state regulatory bodies.

Photo of Anthony Pappas Anthony Pappas

Tony is an associate in the firm’s Regulatory Investigations, Strategy + Enforcement practice. He received his J.D. from the William & Mary Law School, where he served as a staff member for the William & Mary Bill of Rights Journal.

Photo of Trey Smith Trey Smith

Trey is an associate in the firm’s Regulatory Investigations, Strategy + Enforcement Practice. He focuses his practice on helping financial institutions and consumer facing companies navigate regulatory investigations and resulting litigation. He has experience litigating the Consumer Financial Protection Act, the FTC Act…

Trey is an associate in the firm’s Regulatory Investigations, Strategy + Enforcement Practice. He focuses his practice on helping financial institutions and consumer facing companies navigate regulatory investigations and resulting litigation. He has experience litigating the Consumer Financial Protection Act, the FTC Act, the Truth in Lending Act, state UDAAP statutes, and other consumer protection laws.