DoW Suspends CMMC Phase II Third-Party Assessments, Launches 60-Day Reform Review
Defense contractors and primes must maintain NIST SP 800-171 self-assessments and DFARS 252.204-7012 safeguards while the Pentagon reconsiders third-party certification requirements.
On July 13, 2026, the Department of War suspended CMMC Phase II, halting the November 10, 2026 rollout that would have required C3PAO third-party assessments for many contract awards. All pending and future CMMC milestones are held in abeyance; acquisition officials may now include only Level 1 or Level 2 self-assessment requirements in solicitations. A new CMMC Reform Task Force will conduct a 60-day review focused on reducing compliance costs, addressing C3PAO capacity shortages, and lowering barriers for small and nontraditional suppliers, with an RFI open to industry input. Phase I self-assessments and DFARS 252.204-7012 obligations remain fully enforceable, and DOJ's Civil Cyber-Fraud Initiative continues. Primes lose independent validation of subcontractor cybersecurity posture and must strengthen internal supplier risk programs. Contractors should document current NIST SP 800-171 controls, monitor the RFI, and prepare for a potentially restructured CMMC 3.0 framework.