CMMC Phase II Suspended: Contractual Cybersecurity Obligations Remain in Force

July 22, 2026

The Department of War has paused the third-party assessment requirement scheduled for November 2026, but self-assessment obligations and underlying contract clauses remain active. Contractors should treat the pause as a shift in enforcement mechanics, not a suspension of their compliance duties.

What Happened

On July 13, 2026, the Department of War (formerly the Department of Defense) suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. Phase II, originally set to take effect on November 10, 2026, would have required many contractors handling controlled unclassified information (CUI) to obtain a Level 2 assessment from a Certified Third-Party Assessment Organization (C3PAO) as a condition of contract award. The Department cited the cost of compliance and a shortage of qualified assessors as reasons for the pause and directed a Reform Task Force to complete a top-to-bottom review of the program within 60 days, informed in part by public comment collected through a Request for Information (RFI). Comments to that RFI are due by 12:00 p.m. ET on August 14, 2026.

The suspension also holds Phase III and Phase IV in abeyance, along with any implementation milestones tied to those later phases. Officials have been clear that the pause is aimed at the third-party audit mechanism, not at the underlying security standards; contractors should not read it as a signal that cybersecurity expectations for federal work are being relaxed.

What Remains in Effect

Three sets of obligations are unaffected by the July 13 announcement:

  • Phase I self-assessment requirements, including Level 1 self-assessments for contractors handling federal contract information (FCI) and Level 2 self-assessments for contractors handling CUI, continue to apply.
  • The safeguarding clause at DFARS 252.204-7012 continues to bind defense contractors and subcontractors handling covered defense information, independent of where CMMC implementation stands.
  • Basic safeguarding obligations under FAR 52.204-21, including its 15 specified security controls for protecting FCI, remain a baseline requirement across covered federal contracts and are untouched by a Department of War policy action.

This last point is worth emphasizing given how the suspension has been discussed publicly: the Department of War can pause its own acquisition milestones, but it cannot unilaterally amend the FAR. Any broader change to CUI safeguarding duties across the federal (not just defense) contracting base would need to move through the FAR Council’s own rulemaking process. Notably, that process is already active on a separate track: on June 23, 2026, the FAR Council proposed a government-wide rule addressing CUI safeguarding and incident reporting that would extend obligations historically limited to defense contracts to civilian-agency contracts as well, with the comment period closing July 23, 2026. Clients should track that rulemaking independently of the CMMC review.

Why the Distinction Matters

Pausing the mandatory C3PAO assessment requirement does not remove the underlying duty to protect federal information, nor does it reduce potential exposure under the False Claims Act. Contractors remain responsible for the accuracy of any self-assessment scores and annual affirmations they submit. An independent third-party readiness assessment can provide additional confidence that representations made to the government are accurate and supported.

This change makes it clear that while the required C3PAO certification has been paused, independent third-party assessments remain a valuable risk mitigation tool.

Recommended Next Steps

# Recommended Action
1 Keep self-assessment programs running. Continue current NIST SP 800-171 implementation, SPRS score submissions, and annual affirmations as though Phase II had never been announced. None of that work is optional under the pause.
2 Review open solicitations and active contracts for stray Phase II language. Some contracting offices had already begun inserting third-party assessment requirements ahead of the original deadline. Confirm that any such clauses in your pipeline have been or will be corrected, rather than assuming it will happen automatically.
3 Strengthen support for your self-assessment. Whether performed internally or with the assistance of an independent third party, organizations should maintain sufficient evidence to support NIST SP 800-171 compliance, SPRS submissions, and annual affirmations. An external assessment can provide additional assurance that compliance claims are accurate and defensible should questions arise later.
4 Consider participating in the RFI process. Contractors with firsthand experience of assessment bottlenecks, control duplication, or subcontractor flow-down friction have a window through August 14, 2026, to shape the eventual reform.
5 Monitor the FAR Council's CUI rulemaking separately from the CMMC review. The two processes are related but distinct, and the FAR-level rule is the one most likely to expand obligations beyond the defense sector.
6 Treat this as a pause, not a resolution. The Reform Task Force's 60-day review is scheduled to conclude in mid-September 2026, and the Department has not committed to any particular outcome, including a permanent end to third-party assessments.

How GRF Can Help

Although mandatory C3PAO assessments have been paused, organizations should continue preparing for compliance and validating their cybersecurity programs. GRF can perform independent NIST SP 800-171 readiness assessments, targeted control testing, documentation reviews, and third-party compliance assessments to help organizations identify gaps, strengthen evidence supporting self-assessments, and reduce regulatory and False Claims Act risk.

Looking Ahead

We expect the Reform Task Force’s review, the RFI comment record, and the FAR Council’s parallel CUI rulemaking to together determine what a revised CMMC framework looks like heading into 2027. We will continue to monitor both processes and will issue a further alert when the Task Force reports out or when the FAR Council takes further action.

Contact Us

GRF continues to monitor the paused the third-party assessment requirement, and our Government Contracting team will provide updates as more information becomes available. Use the contact below for any questions or further clarification.

Contact Us

 

This alert is provided for general informational purposes and does not constitute legal advice. Please contact one of the attorneys listed above to discuss how these developments may affect your organization.