Akin Gump·CYBERSECURITY

DoW Suspends CMMC Phase II Third-Party Assessments, Launches 60-Day Reform Review

Defense contractors and primes must maintain NIST SP 800-171 self-assessments and DFARS 252.204-7012 safeguards while the Pentagon reconsiders third-party certification requirements.

On July 13, 2026, the Department of War suspended CMMC Phase II, halting the November 10, 2026 rollout that would have required C3PAO third-party assessments for many contract awards. All pending and future CMMC milestones are held in abeyance; acquisition officials may now include only Level 1 or Level 2 self-assessment requirements in solicitations. A new CMMC Reform Task Force will conduct a 60-day review focused on reducing compliance costs, addressing C3PAO capacity shortages, and lowering barriers for small and nontraditional suppliers, with an RFI open to industry input. Phase I self-assessments and DFARS 252.204-7012 obligations remain fully enforceable, and DOJ's Civil Cyber-Fraud Initiative continues. Primes lose independent validation of subcontractor cybersecurity posture and must strengthen internal supplier risk programs. Contractors should document current NIST SP 800-171 controls, monitor the RFI, and prepare for a potentially restructured CMMC 3.0 framework.

cmmcdefense-industrial-basenist-800-171dfarscivil-cyber-fraud
Read the original firm alert →Wednesday, July 15, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.