CMMC Phase II suspended: How contractors should respond now
The CMMC Phase II suspension changes timelines, not cybersecurity obligations. Learn what contractors should do now.
The Department of Defense's suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II rollout has created new uncertainty across the Defense Industrial Base (DIB). Phase II, which was scheduled to begin Nov. 10, 2026, would expand the use of CMMC Level 2 assessments by certified third-party assessment organizations (C3PAOs) for applicable contracts involving Controlled Unclassified Information (CUI). Contractors are now evaluating how the suspension may affect implementation timelines, certification planning and existing compliance obligations.
While the suspension delays the DoD's implementation of mandatory third-party assessments under Phase II, it does not eliminate CMMC Level 2 certification considerations for contractors. Prime contractors and other non-DoD entities may still require CMMC Level 2 certification, and existing contractual obligations to protect CUI and implement applicable security controls remain in effect. For contractors, the announcement represents a change in the DoD's certification rollout rather than a broader pause in cybersecurity or compliance expectations.
As the DoD evaluates potential changes to the program, distinguishing between changes to the certification process and existing cybersecurity obligations can help contractors understand what the suspension changes, what it does not change and how to respond while the review remains underway.
What the suspension actually changes
The suspension affects the DoD's implementation of the CMMC Phase II rollout, not the broader CMMC ecosystem or cybersecurity framework that supports it. The Phase II rollout plan is governed by Title 48 of the Code of Federal Regulations (48 CFR), and the pause concerns implementation by DoD contracting officers. Prime contractors and other non-DoD entities may still require CMMC Level 2 certification.
For contractors preparing for a C3PAO assessment, the suspension may provide additional time before certification becomes a DoD contractual requirement. It does not, however, mean contractors can assume certification will not be required during this period. Prime contractors may continue to establish CMMC Level 2 certification requirements for their subcontractors, independent of the DoD's Phase II rollout.
The review is focused on how the program is implemented rather than whether cybersecurity requirements should exist. While the outcome remains uncertain, contractors should view the suspension as a change to the DoD's implementation timeline, not as a reason to pause cybersecurity or CMMC readiness efforts.
What contractors should continue doing
Although the suspension affects the DoD's implementation of third-party assessment requirements under CMMC Phase II, it does not change the cybersecurity and compliance responsibilities organizations already have under existing contracts. Organizations that handle CUI remain responsible for meeting applicable contractual and regulatory requirements.
Existing responsibilities remain in effect, including:
- Protecting CUI in accordance with contract requirements.
- Implementing applicable NIST SP 800-171 Revision 2 security controls.
- Completing required CMMC Level 2 self-assessments and entering assessment scores in the Supplier Performance Risk System (SPRS), where applicable.
- Complying with existing DFARS cybersecurity requirements and other contractual obligations.
Contractors should continue to take Level 2 self-assessment requirements seriously during the suspension. For certain solicitations, contractors may need to complete a Level 2 self-assessment in SPRS to obtain the CMMC Level 2 unique identifier (UID) required to respond. The suspension of the DoD's Phase II rollout does not eliminate these current procurement considerations.
How organizations can use the additional time
For many contractors, the suspension creates additional time to continue preparing for CMMC Level 2. Organizations can use this period to address control gaps, strengthen documentation and prepare for certification requirements that may arise through DoD implementation, prime contractor expectations or other contractual requirements.
Maintaining momentum allows contractors to identify and remediate control gaps before they become contractual or operational challenges. Continuing implementation efforts can also strengthen compliance documentation and reduce the likelihood of compressed remediation efforts when certification requirements apply.
CMMC Level 2 certification may also provide benefits beyond meeting a DoD contractual requirement. Prime contractors may require certification from subcontractors, and independent verification by a C3PAO can provide customers, vendors and teaming partners with additional assurance regarding an organization's cybersecurity practices. Certification can also serve as a market differentiator and, in some cases, may support more favorable cyber insurance considerations.
Contractors should also consider how broader federal cybersecurity requirements are evolving. NIST SP 800-171 Revision 3 provides an updated framework for protecting CUI, while proposed changes to the Federal Acquisition Regulation (FAR) would expand related cybersecurity requirements across federal agencies. Although those FAR changes remain proposed, organizations can use this period to evaluate how emerging requirements may affect future compliance planning.
Contractors that continue strengthening cybersecurity capabilities, documenting compliance activities and preparing for certification can be better positioned to respond to DoD requirements, prime contractor expectations and broader federal cybersecurity developments.
For a deeper dive, watch our webinar: CMMC Phase II suspended: What organizations need to know now.
Editor's note: This webinar was recorded before the Department of Defense's subsequent announcement making the Phase II suspension permanent. While the webinar refers to the suspension as a temporary pause based on information available at the time, the permanent suspension does not change the analysis, guidance or recommendations discussed in the presentation. Organizations should continue to focus on protecting CUI, meeting existing contractual cybersecurity obligations and advancing CMMC readiness efforts as appropriate.
Related services
Our solutions are tailored to each client’s strategic business drivers, technologies, corporate structure, and culture.
Any advice contained in this communication, including attachments and enclosures, is not intended as a thorough, in-depth analysis of specific issues. Nor is it sufficient to avoid tax-related penalties. This has been prepared for information purposes and general guidance only and does not constitute legal or professional advice. You should not act upon the information contained in this publication without obtaining specific professional advice specific to, among other things, your individual facts, circumstances and jurisdiction. No representation or warranty (express or implied) is made as to the accuracy or completeness of the information contained in this publication, and CohnReznick, its partners, employees and agents accept no liability, and disclaim all responsibility, for the consequences of you or anyone else acting, or refraining to act, in reliance on the information contained in this publication or for any decision based on it.