
CMMC Phase 2 Paused: Which Cybersecurity Requirements Still Apply to Defense Contractors?
Last updated: July 14, 2026. We'll update this article as the DoW issues new guidance.
On July 13, 2026, the Department of War (DoW) paused the transition to CMMC Phase 2 requirements, which were scheduled to take effect on November 10, 2026.
While the transition to Phase 2 third-party assessment requirements has been paused and a task force is taking 60 days to review the CMMC program and deliver a report, Phase 1 self-assessment requirements remain firmly in place. During this interim period, defense contractors and subcontractors must continue to comply with cybersecurity requirements to protect federal data, including CMMC and DFARS 7012.
Below, we unpack what this announcement changes, what it doesn't, and what defense contractors should do during the 60-day review period.

What the DoW announced is changing about CMMC
The first announcement came from the Department’s Chief Information Officer Kirsten A. Davies: "In support of Secretary Pete Hegseth's directive to reduce compliance barriers for small and medium-sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program."
The Department’s stated reasoning is lack of scalability. According to the release, the current CMMC program was designed to enhance DIB cybersecurity but instead created prohibitive compliance costs and unnecessary bureaucracy. The memo mentioned that recent data showed the burden of CMMC compliance was forcing companies out of the Defense Industrial Base (DIB), specifically referencing Small Business Administration reports.
However, a second DoW release emphasized that investing in and dynamically maintaining robust cybersecurity is still a priority for DIB organizations that want to do business with the Department.
Here's what to know about this CMMC update and the implementing memo (26-P-1023):
- The CMMC phased rollout is now paused, but Phase 1 requirements remain in effect
- A 60-day review of the CMMC program is underway, and industry feedback is being gathered through a public request for information that will culminate in a final report recommending “scalable, resilient cybersecurity measures”
- New solicitations can only require CMMC Level 1 or CMMC Level 2 self-assessments
- CMMC Level 2 (C3PAO) requirements that require a third-party assessment are being removed from active solicitations and existing contracts
- CMMC waiver procedures are also paused for the duration of the review period
What is not changing about DoW cybersecurity requirements
While the announcement paused the transition to Phase 2 requirements, the DoW did not cancel the CMMC program or the underlying rules to protect federal data.
Here is what that means at a glance:
- DFARS 252.204-7012 and CMMC Level 1 and Level 2 (Self) requirements remain in effect.
- NIST SP 800-171 Rev 2 will still be enforced by the DoW through self-assessments and select government-led assessments.
- Accurate CMMC self-assessment results and scores, along with an annual affirmation signed by a named senior executive, must still be submitted to SPRS.
- Contractors that misrepresent NIST 800-171 compliance still face False Claims Act risk.
- Primes will still flow down CMMC requirements and ask suppliers for assurance of NIST 800-171 Rev 2 compliance.
What happens next
The DoW has said further guidance will come after the taskforce’s 60-day review and report is delivered, which is expected around mid-September 2026.
However, enhancing DIB cybersecurity and operational resilience remains a critical, non-negotiable priority for the Department, so your immediate next steps are still the same:
1. Scope your CUI
- Identify all locations where CUI enters, is stored, processed, or transmitted to determine scope
- Evaluate whether an enterprise or enclave approach would best meet your needs
- Define your CMMC assessment scope and document it in your SSP
2. Stand up a compliant environment
- Confirm all cloud service providers processing CUI are FedRAMP Moderate Authorized or equivalent
- Stop using Microsoft 365 Commercial or any other non-compliant cloud offering for CUI
- Migrate to and configure GCC High or Google Workspace to secure CUI
- Implement FIPS 140-2 validated cryptography for CUI in transit
- Apply MFA to all endpoints, cloud services, firewalls, and servers that process or provide security protection for CUI
3. Implement and document your controls
- Conduct a CMMC gap analysis to understand how your current cybersecurity implementation compares to NIST 800-171 Rev 2
- Create and maintain all the required policies and procedures
- Implement cyber-incident reporting requirements in DFARS 7012
- Document NIST 800-171 implementation in your SSP
4. Assess and affirm
- Conduct a self-assessment using NIST SP 800-171A (not just 800-171)
- Identify and document any gaps in POA&Ms with remediation timelines
- Submit supported and accurate self-assessment results and score in SPRS
- Designate the senior official who will affirm compliance and submit in SPRS
In other words, the work that determines whether you can demonstrate your ability to securely handle sensitive government information and do business with the DoW is still implementing and maintaining NIST 800-171.
What now
Secureframe Defense was purpose-built to reduce the cost and complexity of doing that exact work, not just assessing and documenting it.
Step 1: Deploy
The platform automatically provisions a CMMC-compliant cloud environment in Microsoft GCC High or Google Workspace and devices, configured with the access control, logging, monitoring, security event notifications, and segmentation required by NIST 800-171 R2 to securely store and access CUI.
Step 2: Implement and document
Defense Navigator turns the 110 requirements into a guided implementation workflow to get you to 100% ready, automatically generating and maintaining your SSP, implementation statements, and policies from your actual configured environment rather than templates.
Step 3: Get and stay compliant
Secureframe Defense continuously collects evidence, monitors your controls, and enforces other operational guardrails like risk assessments and vendor tracking to prevent quiet compliance drift. That means your SPRS score always reflects your real-time cybersecurity posture, and the senior official signing your annual affirmation has support evidence behind it.
The Secureframe team is available to help your organization navigate the sudden changes to CMMC and will help you scope out your CMMC & NIST 800-171 cybersecurity program. Schedule time to talk to our team.