loading min read

CMMC Phase II suspended: How contractors should respond now

The CMMC Phase II suspension changes timelines, not cybersecurity obligations. Learn what contractors should do now.

The Department of Defense's suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II rollout has created new uncertainty across the Defense Industrial Base (DIB). Phase II, which was scheduled to begin Nov. 10, 2026, would expand the use of CMMC Level 2 assessments by certified third-party assessment organizations (C3PAOs) for applicable contracts involving Controlled Unclassified Information (CUI). Contractors are now evaluating how the suspension may affect implementation timelines, certification planning and existing compliance obligations.

While the suspension delays the DoD's implementation of mandatory third-party assessments under Phase II, it does not eliminate CMMC Level 2 certification considerations for contractors. Prime contractors and other non-DoD entities may still require CMMC Level 2 certification, and existing contractual obligations to protect CUI and implement applicable security controls remain in effect. For contractors, the announcement represents a change in the DoD's certification rollout rather than a broader pause in cybersecurity or compliance expectations.

As the DoD evaluates potential changes to the program, distinguishing between changes to the certification process and existing cybersecurity obligations can help contractors understand what the suspension changes, what it does not change and how to respond while the review remains underway.

What the suspension actually changes

The suspension affects the DoD's implementation of the CMMC Phase II rollout, not the broader CMMC ecosystem or cybersecurity framework that supports it. The Phase II rollout plan is governed by Title 48 of the Code of Federal Regulations (48 CFR), and the pause concerns implementation by DoD contracting officers. Prime contractors and other non-DoD entities may still require CMMC Level 2 certification.

For contractors preparing for a C3PAO assessment, the suspension may provide additional time before certification becomes a DoD contractual requirement. It does not, however, mean contractors can assume certification will not be required during this period. Prime contractors may continue to establish CMMC Level 2 certification requirements for their subcontractors, independent of the DoD's Phase II rollout.

The review is focused on how the program is implemented rather than whether cybersecurity requirements should exist. While the outcome remains uncertain, contractors should view the suspension as a change to the DoD's implementation timeline, not as a reason to pause cybersecurity or CMMC readiness efforts.

What contractors should continue doing

Although the suspension affects the DoD's implementation of third-party assessment requirements under CMMC Phase II, it does not change the cybersecurity and compliance responsibilities organizations already have under existing contracts. Organizations that handle CUI remain responsible for meeting applicable contractual and regulatory requirements.

Existing responsibilities remain in effect, including:

  • Protecting CUI in accordance with contract requirements.
  • Implementing applicable NIST SP 800-171 Revision 2 security controls.
  • Completing required CMMC Level 2 self-assessments and entering assessment scores in the Supplier Performance Risk System (SPRS), where applicable.
  • Complying with existing DFARS cybersecurity requirements and other contractual obligations.

Contractors should continue to take Level 2 self-assessment requirements seriously during the suspension. For certain solicitations, contractors may need to complete a Level 2 self-assessment in SPRS to obtain the CMMC Level 2 unique identifier (UID) required to respond. The suspension of the DoD's Phase II rollout does not eliminate these current procurement considerations.

How organizations can use the additional time

For many contractors, the suspension creates additional time to continue preparing for CMMC Level 2. Organizations can use this period to address control gaps, strengthen documentation and prepare for certification requirements that may arise through DoD implementation, prime contractor expectations or other contractual requirements.

Maintaining momentum allows contractors to identify and remediate control gaps before they become contractual or operational challenges. Continuing implementation efforts can also strengthen compliance documentation and reduce the likelihood of compressed remediation efforts when certification requirements apply.

CMMC Level 2 certification may also provide benefits beyond meeting a DoD contractual requirement. Prime contractors may require certification from subcontractors, and independent verification by a C3PAO can provide customers, vendors and teaming partners with additional assurance regarding an organization's cybersecurity practices. Certification can also serve as a market differentiator and, in some cases, may support more favorable cyber insurance considerations.

Contractors should also consider how broader federal cybersecurity requirements are evolving. NIST SP 800-171 Revision 3 provides an updated framework for protecting CUI, while proposed changes to the Federal Acquisition Regulation (FAR) would expand related cybersecurity requirements across federal agencies. Although those FAR changes remain proposed, organizations can use this period to evaluate how emerging requirements may affect future compliance planning.

Contractors that continue strengthening cybersecurity capabilities, documenting compliance activities and preparing for certification can be better positioned to respond to DoD requirements, prime contractor expectations and broader federal cybersecurity developments.

For a deeper dive, watch our webinar: CMMC Phase II suspended: What organizations need to know now

Editor's note: This webinar was recorded before the Department of Defense's subsequent announcement making the Phase II suspension permanent. While the webinar refers to the suspension as a temporary pause based on information available at the time, the permanent suspension does not change the analysis, guidance or recommendations discussed in the presentation. Organizations should continue to focus on protecting CUI, meeting existing contractual cybersecurity obligations and advancing CMMC readiness efforts as appropriate.

INSIGHTS
Discover More Assets

Related services

Our solutions are tailored to each client’s strategic business drivers, technologies, corporate structure, and culture.

Receive CohnReznick insights and event invitations on topics relevant to your business and role.
Subscribe

Any advice contained in this communication, including attachments and enclosures, is not intended as a thorough, in-depth analysis of specific issues. Nor is it sufficient to avoid tax-related penalties. This has been prepared for information purposes and general guidance only and does not constitute legal or professional advice. You should not act upon the information contained in this publication without obtaining specific professional advice specific to, among other things, your individual facts, circumstances and jurisdiction. No representation or warranty (express or implied) is made as to the accuracy or completeness of the information contained in this publication, and CohnReznick, its partners, employees and agents accept no liability, and disclaim all responsibility, for the consequences of you or anyone else acting, or refraining to act, in reliance on the information contained in this publication or for any decision based on it.

"CohnReznick" is the brand name under which CohnReznick LLP and CohnReznick Advisory LLC and their respective subsidiaries provide professional services. CohnReznick LLP and CohnReznick Advisory LLC (and their respective subsidiaries) practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CohnReznick LLP is a licensed CPA firm that provides attest services to its clients. CohnReznick Advisory LLC provides tax and business consulting services to its clients. CohnReznick Advisory LLC and its subsidiaries are not licensed CPA firms.

member of nexia

CohnReznick is a member of Nexia, a leading, global network of independent accounting and consulting firms. Please see the “Member firm disclaimer (Opens a new window)” for further details.

© 2026 CohnReznick Advisory LLC, All Rights Reserved.