DoD Suspends CMMC Phase II Rollout for Defense Contractors
Defense contractors and their subcontractors must monitor this suspension to align compliance plans with the DoD’s revised CMMC implementation timeline, which impacts contract eligibility.
The U.S. Department of Defense has paused the rollout of CMMC Phase II, the second tier of its Cybersecurity Maturity Model Certification program that would have required mandatory third-party cybersecurity validation for most defense contractors. The suspension delays previously scheduled implementation deadlines, and the DoD has stated it will revise the program’s requirements, scope, and enforcement timeline in the coming months. Contractors should pause planned Phase II compliance spending, monitor official DoD guidance for updates, and review existing contract clauses for temporary relief provisions tied to CMMC requirements.