BakerHostetler·GOVERNMENT CONTRACTS / DEFENSE

DoD Suspends CMMC Phase II Rollout for Defense Contractors

Defense contractors and their subcontractors must monitor this suspension to align compliance plans with the DoD’s revised CMMC implementation timeline, which impacts contract eligibility.

The U.S. Department of Defense has paused the rollout of CMMC Phase II, the second tier of its Cybersecurity Maturity Model Certification program that would have required mandatory third-party cybersecurity validation for most defense contractors. The suspension delays previously scheduled implementation deadlines, and the DoD has stated it will revise the program’s requirements, scope, and enforcement timeline in the coming months. Contractors should pause planned Phase II compliance spending, monitor official DoD guidance for updates, and review existing contract clauses for temporary relief provisions tied to CMMC requirements.

cmmcdefense-contractorsdod-regulationscybersecurity-compliance
Read the original firm alert →Wednesday, July 15, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.