DoD Suspends Implementation of CMMC Phase 2 Requirements
The Department of Defense has suspended CMMC Phase 2 requirements pending a review, while Phase 1 remains enforced. Contractors must navigate ongoing obligations under DFARS 7012 and stay informed on current solicitation clauses as the dynamics of compliance evolve in the near term.
Key Signals
- DoD suspends CMMC Phase 2 requirements pending reform review
- Contractors must continue compliance with DFARS 7012 and Phase 1
- Level 3 assessments investment needs to be reconsidered under current guidance
"CMMC Phase 2 is suspended, not gone. DFARS 7012, the SPRS score and Phase 1 self-assessments still apply."
On July 13, 2026, the Department of Defense (DoD) announced the suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements, which were initially set to commence on November 10, 2026. This decision to halt the rollout is positioned as a move to allow for a comprehensive review of the reforms associated with CMMC. As it stands, the existing Phase 1 requirements not only remain in effect but form the fundamental framework that contractors must still adhere to during this interim period.
The implications of this suspension are significant for defense contractors across the board. While the announcement raises questions about the status of Level 3 assessments, it clearly delineates that contractors are still required to fulfill obligations associated with Phase 1. It is important for companies in the defense sector to maintain compliance with Defense Federal Acquisition Regulation Supplement (DFARS) 7012, which outlines the necessary cybersecurity practices that protect sensitive unclassified information on contractors’ systems.
A key element of navigating this suspension involves the Supplier Performance Risk System (SPRS) scores, which contractors must maintain accurately alongside their annual affirmative assessments. The prospect of inflated SPRS scores during this delayed transition could result in heightened vulnerability to false claims, potentially incurring severe penalties. Therefore, companies must not take the enforcement of cybersecurity measures lightly, even with the halt of Phase 2 implementation.
Moreover, the contract landscape is shifting in light of these developments. Contractors who may have been preparing for the investment in a Level 3 assessment are advised to reassess their strategies, as it may not be necessary under the current conditions. Instead of rushing into evaluations that are not mandated, a thorough review of ongoing solicitation clauses and forthcoming guidance from the DoD should be a primary focus.
While this suspension fundamentally alters the immediate compliance and assessment obligations for contractors, it does not eliminate the essential requirements embedded in DFARS 7012 as well as the guiding principles of CMMC Phase 1. As defense contractors adapt to this new regulatory environment, they should remain vigilant in executing the compliance measures that are still in place and be prepared for possible future changes to evaluation structures as the DoD completes its comprehensive review.
In summary, the suspension of CMMC Phase 2 highlights the ongoing need for robust cybersecurity practices in the defense contracting domain. Firms must maintain compliance commitments, prepare for unexpected shifts in regulation, and stay informed about the evolving landscape of cybersecurity requirements as they pertain to federal contracts. This period provides an opportunity for contractors to streamline their cybersecurity frameworks without the immediate pressure of new assessment requirements, while they continue to uphold the necessary standards that protect sensitive information and systems.
- Contractors must continue Phase 1 self-assessments, maintain accurate SPRS scores, submit annual affirmations, and apply required flow-down clauses.
- Inflated SPRS scores may create false-claims exposure even while Phase 2 is suspended.
- Before committing to Level 3 assessment investments, verify current solicitation clauses and agency guidance.
- The suspension adjusts the near-term compliance landscape but does not negate DFARS 7012 obligations.
- A thorough review of ongoing solicitation clauses is essential for contractors amid these changes.
- Companies should be prepared for possible future adjustments as the DoD completes its evaluation of CMMC reforms.
Agencies
- Department of Defense
- National Institute of Standards and Technology
- Defense Information Systems Agency
- Defense Cyber Crime Center
Sources
- Has anyone started or passed a Level 3 assessment?reddit-cmmc · Oct 03
- CMMC Phase 2 is suspended, not gone. DFARS 7012, the SPRS score and Phase 1 self-assessments still apply. 12-tab workbook: 110 practices, SPRS weights, POA&M tracker. https://t.co/pBB038IvMW #CMMC #CyberCompliance https://t.co/fdkHzB28iytwitter-regulatory · Sep 29