Troutman Pepper Locke·GOVERNMENT CONTRACTS / DEFENSE

DoD Halts CMMC Phase II Rollout, Keeps Baseline Cyber Obligations in Force

Defense contractors and subcontractors must continue self-assessing against existing NIST SP 800-171 controls while awaiting DoD's revised CMMC framework.

On July 13, 2026, DoD/W suspended Phase II of the Cybersecurity Maturity Model Certification program, halting third-party assessments that were scheduled to expand across the DIB. The agency cited the need to reassess implementation timelines and reduce contractor burden, but expressly preserved all baseline safeguarding requirements under NIST SP 800-171 and the existing DFARS 252.204-7012 clause. Contractors cannot pause cyber hygiene work: SPRS score submissions, system security plans, and Plan of Action & Milestones remain mandatory for any award, option, or subcontract flow-down. Prime contractors should revalidate subcontractor attestations and confirm that pending awards still require current self-assessment scores. Companies previously preparing for Level 2 certification audits should pause external assessment spending and monitor DoD guidance for the revised phased approach expected later this year.

cmmcdod-cybersecuritynist-800-171dfarsdefense-contractors

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.