The Cybersecurity Crossroads: Navigating the Department of War CMMC Phase 2 Suspension
- Dean Charlton
- 3 days ago
- 8 min read
On 13 July 2026, the Department of War, or DoW, sent shockwaves through the defence industrial base by announcing the immediate suspension of the Cybersecurity Maturity Model Certification, or CMMC, Phase 2 rollout. This critical phase, which was scheduled to take effect on 10 November 2026, would have mandated independent, third-party assessments conducted by Certified Third-Party Assessment Organisations, or C3PAOs, as a condition for contract awards. Instead, the DoW has paused these requirements and initiated a comprehensive, 60-day top-to-bottom review of the entire programme. Â
For many defence contractors, the initial reaction to this announcement was a sigh of relief. The looming November deadline had created immense pressure, particularly for small and medium-sized businesses grappling with high implementation costs and a severe shortage of accredited assessors. However, viewing this suspension as a green light to halt cybersecurity efforts is a dangerous misinterpretation of the Department's directive.
The reality of this announcement is far more nuanced. While the mandatory third-party verification has been paused, the underlying security obligations have not disappeared. Phase 1 remains fully in effect, meaning self-assessments and basic cyber hygiene are still mandatory requirements for staying in the defence supply chain. In this climate, stopping or delaying your compliance activities could leave your organisation exposed to immediate contractual disqualification, legal liabilities under the False Claims Act, and a massive bottleneck when structured assessments eventually return. Â
Understanding the Suspension: Why Did the Department of War Pause Phase 2?
To understand where the CMMC programme is heading, it's essential to examine why the DoW chose to pause Phase 2. The decision, memorialised in a memorandum signed by DoW Chief Information Officer Kirsten Davies, was not a retreat from cybersecurity, rather, it's an effort to align the compliance framework with broader acquisition reforms. Specifically, the suspension supports Secretary of War Pete Hegseth's Acquisition Transformation System directives, which prioritise speed to capability, agility, and the removal of bureaucratic barriers for small, medium, and non-traditional commercial innovators. Â
The original CMMC 2.0 framework, finalised after years of development, aimed to protect Controlled Unclassified Information, or CUI, across the vast defence supply chain. However, the rollout encountered significant structural obstacles: Â
Extreme Financial Strain on Small Businesses
Recent data from the Small Business Administration, or SBA, highlighted that CMMC compliance was forcing critical, innovative small businesses out of the defence industrial base. Preparing for a Level 2 third-party assessment frequently cost companies hundreds of thousands of dollars, with some estimates reaching up to $600,000. For a small manufacturer or niche software developer, these upfront and ongoing costs were simply untenable, threatening to choke off the flow of commercial innovation to the military. Â
Severe Assessor Deficits
The operational logistics of Phase 2 were heading toward a major bottleneck. The framework would have required over 120,000 small and medium-sized contractors to seek independent certification. Yet, by mid-2026, the ecosystem contained only about 100 fully accredited C3PAOs. If the November deadline had remained in place, thousands of qualified suppliers would have been locked out of contract competitions purely because they could not secure an assessment slot in time. Â
Administrative Overhead vs. Tangible Security
Industry feedback suggested that the compliance model had become overly bureaucratic, focusing more on documentation and administrative audits than on practical, active defence measures. Â
In response, the DoW established a dedicated CMMC Reform Task Force. This group has been given a strict 60-day window to evaluate the entire programme, review industry feedback via a public Request for Information, or RFI, and recommend realistic, scalable security measures that lower barriers without compromising national security. Â
The Foundations Still Standing: What Remains in Force?
While Phase 2 third-party assessments are on hold, the core security expectations for the defence supply chain have not changed. Contractors still bear a strict legal and operational responsibility to protect government data. Â

As the diagram illustrates, true compliance requires a continuous cycle of identification, protection, detection, response, and recovery. This lifecycle remains the standard, and several key pillars of the security regime remain fully active during this 60-day review period:
Phase 1 Self-Assessments are Still Mandatory
CMMC Phase 1 requirements have not been suspended. Every contractor handling Federal Contract Information, or FCI, must still perform a Level 1 self-assessment, which covers 17 basic cyber hygiene practices. Similarly, organisations handling Controlled Unclassified Information must continue to perform Level 2 self-assessments based on the 110 controls of National Institute of Standards and Technology Special Publication 800-171 Revision 2. Â
Submission to the Supplier Performance Risk System
Contractors must still post their self-assessment scores to the government's Supplier Performance Risk System, or SPRS. These scores must be accurate and updated regularly. Failing to post a score, or posting an inaccurate one, remains an immediate trigger for contract delays or disqualification. Â
DFARS 252.204-7012 is Unchanged
This defense federal acquisition regulation supplement clause remains the primary legal mechanism governing supply chain security. It mandates that contractors safeguard covered defence information, report cyber incidents to the DoW within 72 hours, and flow these security requirements down to all sub-tier contractors. The suspension of CMMC Phase 2 does not alter this contractual clause in any way. Â
Government-Led Audits Will Continue
The Defence Industrial Base Cybersecurity Assessment Center, or DIBCAC, retains its authority to conduct targeted, government-led audits. In early 2026, this authority was renumbered to DFARS 252.240-7997. While you may not need a C3PAO to visit your facility today, DIBCAC assessors can still choose to audit your organisation directly, particularly if you are bidding on high-priority contracts or if your SPRS score appears questionable. Â
The True Risks of Pausing Your Compliance Efforts
It's tempting to look at the 60-day review as a vacation from cybersecurity compliance, but doing so introduces severe operational and financial risks to your business.
1. The Fallacy of the Self-Assessment Safety Net
Without a third-party C3PAO checking your work, the legal and regulatory burden of proving compliance shifts entirely onto your organisation's shoulders. When you sign off on a self-assessment, you're making a formal, binding representation to the government that your security controls are fully implemented and functioning. If a breach occurs and investigations reveal that your self-assessment was inaccurate, your organisation can face catastrophic consequences. Â
The Department of Justice, or DOJ, has aggressively used the False Claims Act to target defence contractors that submit false SPRS scores or fail to maintain the NIST SP 800-171 controls they claimed to have in place. These actions have resulted in substantial civil penalties and, in some cases, the complete debarment of contractors from federal procurement. A self-attested score is not a shield, it's a legal commitment. Â
2. Supply Chain Pressure from Prime Contractors
Even if the DoW has suspended the immediate requirement for C3PAO certificates, prime contractors cannot afford to take risks with their supply chains. Primes are ultimately responsible for the security of the data they flow down to subcontractors. With third-party validation on hold, prime contractors are highly likely to increase their own oversight. Â
Many primes are already requiring their subcontractors to provide detailed evidence, system security plans, and proof of continuous monitoring before awarding subcontracts. If you pause your compliance efforts, you may find yourself dropped by your prime partners, who will prefer suppliers that can immediately prove their cyber hygiene without hesitation.
3. The Future Bottleneck is Inevitable
Cybersecurity is not going away. The DoW has made it clear that this review is intended to find more scalable, realistic ways to verify security, not to abandon it. Whether the task force recommends a modified assessment model, greater recognition of commercial security tools, or streamlined validation for small businesses, some form of verified compliance will emerge. Â
If you stop your compliance activities now, you will lose the progress you have made. When the new framework is finalised, you will have to restart your efforts alongside thousands of other contractors who also paused. This will trigger a massive rush for resources, leading to inflated consultant fees, a lack of available internal talent, and another severe queue for validation. Maintaining your momentum keeps you ahead of the curve, ensuring you are ready to pivot the moment the new rules are announced.
Actionable Steps: What Should Contractors Do During the 60-Day Review?
The 60-day suspension is a valuable window of opportunity. Instead of treating it as a period of inactivity, smart organisations will use this time to optimise their security postures, lower their overall compliance costs, and make their operations more resilient. Here is a practical roadmap for the weeks ahead: Â
Complete and Refine Your System Security Plan
Your System Security Plan, or SSP, is the foundational document of your entire cybersecurity programme. It defines the boundaries of your environment, describes how each of the NIST SP 800-171 controls is implemented, and outlines your Plan of Action and Milestones, or POA&M, for any gaps. If your SSP is out of date, or if you have been relying on a generic template, use this pause to conduct a thorough review. Ensure your documentation accurately reflects your live operational environment.
Address High-Impact NIST SP 800-171 Controls
Focus your remediation efforts on the core technical controls that deliver the most significant risk reduction and form the basis of effective cyber hygiene. These areas often include:
Multi-factor authentication, or MFA, across all corporate and administrative accounts.
Comprehensive access controls, ensuring users only have access to the specific data necessary for their roles. Â
Robust endpoint detection and response, or EDR, to monitor and block threats on company devices.
Continuous audit logging and monitoring to detect anomalous activities before they result in a major data breach.
By prioritizing these technical capabilities over administrative paperwork, you protect your business from real-world threats while aligning with the DoW's focus on tangible cyber hygiene. Â
Engage with the Public RFI Process
The CMMC Reform Task Force is actively seeking feedback from the industry, particularly regarding the primary cost drivers of compliance, unnecessary administrative burdens, and how commercial tools can be better integrated into the security framework. The public comment period is a rare opportunity to shape the future of defence cybersecurity. Â
If your organisation has struggled with the cost or complexity of specific CMMC requirements, document these challenges and submit constructive feedback before the RFI deadline. Advocating for practical, achievable standards helps the task force design a more realistic model that supports small businesses.
Audit and Manage Your Subcontractor Risk
If your organisation acts as a prime contractor, the suspension of Phase 2 makes your subcontractor risk management programme more critical than ever. Because you cannot rely on an official CMMC certification to verify a subcontractor's security, you must perform your own due diligence. Review the SPRS scores and System Security Plans of your key suppliers to ensure they are not introducing vulnerabilities into your contracts. Â
The Strategic Perspective: Compliance as an Operational Asset
It's easy to look at cybersecurity frameworks through a purely regulatory lens, viewing them as expensive administrative hurdles designed to complicate procurement. But in the modern threat landscape, that perspective is outdated. Cyber espionage and supply chain disruptions are active, daily threats to the defence industrial base.
A robust cybersecurity posture is a fundamental operational asset. When you secure your systems, you are not just checking boxes to satisfy a government auditor, you're protecting your intellectual property, safeguarding your employees' identities, and ensuring your business can continue to operate in the face of a cyberattack. Â
The Department of War's 60-day review is a welcome effort to cut red tape and reduce the financial burden on small and medium-sized businesses. However, the core requirement to keep defence data secure is here to stay.Â
By maintaining your compliance momentum, refining your security practices, and participating in the reform process, your organisation will be uniquely positioned to thrive, regardless of the specific rules that emerge from the task force's review. Treat this suspension not as a pause in your security journey, but as an opportunity to build a stronger, more resilient business. Â
Looking to stay one step ahead ahead of your CMMC compliance? Reach out to Risk Cognizance today to discuss how their GRC platform can support your business.
