skip to Main Content

CMMC Phase 2 Suspended: A Timing Reprieve, Not a Cybersecurity Repeal

The Department of War has paused mandatory third-party assessments—not the duty to protect federal data.

The Department of War’s July 13 announcement immediately suspends CMMC Phase II requirements, which had been scheduled to take effect November 10, 2026, and launches a 60-day review of the program. For defense contractors, that is welcome breathing room. It is not, however, a repeal of cybersecurity obligations—or a guaranteed 60-day postponement followed by an automatic return to the current schedule.

The Department made the central point unmistakably clear: “All Phase I self-assessment requirements remain firmly in place.” It also confirmed that contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012.

What remains in place

Phase I permits applicable solicitations and contracts to require either:

  • Level 1 self-assessment —based on the 15 basic safeguarding requirements in FAR 52.204-21 for systems handling Federal Contract Information (FCI); or
  • Level 2 self-assessment —based on the 110 security requirements in NIST SP 800-171 Rev. 2 for systems handling Controlled Unclassified Information (CUI).

The required CMMC status depends on the solicitation or contract. The Department says that, during the review, it will continue enforcing NIST SP 800-171 Rev. 2 through self-assessments and selected government-led assessments.

What the Phase II suspension changes

Phase II would have expanded the use of Level 2 certification assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs) for applicable contracts. A Level 2 C3PAO assessment evaluates the same 110 security requirements and 320 assessment objectives used for a Level 2 self-assessment. The difference is who performs the assessment—not the safeguards a contractor must implement.

The Department expects its review task force to deliver a report within 60 days. The announcement does not say that Phase II will automatically restart on day 61, or that it will return unchanged. Contractors therefore should not treat the announcement as a fixed 60-day extension. They should treat it as an opportunity to strengthen compliance while the government decides what comes next.

How RegDOX can help

RegDOX Solutions provides an integrated, out-of-the-box path to CMMC Level 2 readiness through:

  • Proven technology addressing 308 of the 320 Level 2 assessment objectives;
  • Policy templates designed to support the remaining 12 objectives; and
  • Targeted consulting to identify and close final gaps and prepare the evidence an assessment requires.

This combined approach substantially reduces the time, cost, and complexity of achieving and maintaining CMMC compliance. It gives contractors a substantial head start and a practical path to addressing all 320 Level 2 assessment objectives.

Use the suspension wisely

Companies that continue preparing now will be better positioned to compete—whatever form the revised CMMC program takes—and will avoid a last-minute scramble if mandatory C3PAO assessments resume.

Contact RegDOX to schedule a brief demonstration of how your organization can achieve CMMC readiness quickly and cost-effectively.

RegDOX Solutions Inc.

www.regdox.com  |  (800) 517-3171  |  info@regdox.com

Click to rate this post!
[Total: 0 Average: 0]

This Post Has 0 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top