Arnold & Porter·GOVERNMENT CONTRACTS / DEFENSE

DOD Suspends CMMC Phase II, Core DFARS Obligations Remain

U.S. defense contractors and their in-house counsel must monitor pending DOD reforms, as all existing mandatory cybersecurity and reporting obligations under DFARS and NIST remain fully enforceable.

The U.S. Department of Defense has paused CMMC Phase II implementation for a 60-day review, citing excessive compliance costs, insufficient third-party assessor capacity, and disproportionate harm to small and mid-sized defense industrial base firms. The suspension halts upcoming third-party certification requirements for CMMC Level 2 and higher tiers, but does not eliminate any existing mandatory compliance duties. Defense contractors must continue adhering to current DFARS safeguarding and incident reporting rules, NIST SP 800-171 security requirements, and CMMC Level 1 self-assessment mandates, while tracking forthcoming DOD guidance to adjust long-term compliance roadmaps.

cmmcdod-defense-contractingdfars-cybersecuritynist-sp-800-171defense-industrial-base
Read the original firm alert →Wednesday, July 15, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.