The Department of War suspended CMMC Phase II effective July 13, 2026, while it conducts a 60-day review. Phase I remains in force. Contracting officers may still require Level 1 Self or Level 2 Self, and existing DFARS cybersecurity, assessment, incident-reporting, and data-protection duties continue independently of the Phase II pause.
On July 13, 2026, the Department of War announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification program until further notice. The official announcement says the Department is using a 60-day period to review the program and reduce unnecessary barriers while preserving protection for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). That 60-day period is a review and reporting timeline, not a promised end date or restart date for the suspension.
Phase II had originally been scheduled to begin on November 10, 2026. The suspension changes what CMMC status a contracting officer may designate during the review; it does not repeal the CMMC rules or erase contract clauses already in effect. The official implementation memorandum directs acquisition teams how to implement that distinction.
During the suspension, new or amended solicitations and contracts may designate only:
The implementation memorandum directs contracting officers to remove or amend designations for:
This is a pause in Phase II assessment designations. It is not a general suspension of all CMMC activity, does not itself invalidate an existing C3PAO certificate, and does not prohibit voluntary preparation. Existing solicitations and contracts change through formal amendments or modifications. Contractors should follow the operative contract and contracting officer instructions until such a change is issued.
Phase I self-assessment designations remain available. The updated official CMMC overview continues to describe the phased program and the assessment requirements attached to each level.
Separate contractual duties also remain relevant:
The practical rule is simple: determine obligations from the current solicitation, award, clauses, data handled, systems in scope, and flowdowns—not from a headline about Phase II alone.
Level 1 Self remains available during the suspension. It applies where contractor information systems process, store, or transmit FCI and requires an annual self-assessment against the 15 safeguarding requirements in FAR 52.204-21, followed by an annual affirmation.
Level 1 does not permit plans of action and milestones (POA&Ms). Every applicable requirement must be met for the required Level 1 status. Organizations should keep the assessment scope, results, affirmation, and supporting evidence aligned with the systems that actually handle FCI.
Level 2 Self may still be designated. It is based on the 110 security requirements in NIST SP 800-171 Revision 2, with reassessment every three years and an annual affirmation.
Limited POA&Ms are permitted only under the CMMC rules' conditions. Items placed on a permitted POA&M must be closed within 180 days and cannot include requirements excluded from POA&M use. A Level 2 Self designation therefore remains a substantive evidence exercise, not a registration step.
Level 2 C3PAO designations are the portion suspended. Contractors should not assume that past preparation is wasted: the same CUI boundary, NIST SP 800-171 implementation, evidence quality, supplier controls, and incident processes underpin current contractual compliance and any later assessment.
A dedicated CMMC Level 2 requirements guide with a structured control-by-control view is planned.
CMMC scope follows US government contract clauses, the information handled, the systems that process, store, or transmit that information, and subcontract flowdowns—not the supplier's country. A German or European company can therefore be in scope when a prime contract or subcontract requires CMMC and its own systems handle FCI or CUI.
Conversely, the 2025 DFARS final rule explains that a subcontractor working only inside the prime contractor's systems, without processing, storing, or transmitting FCI or CUI on its own systems, would not need a separate CMMC assessment for those systems. The actual architecture and contract language must support that conclusion.
European suppliers should map the US contractual boundary separately from GDPR, NIS2, ISO 27001, or national security requirements. Those regimes may overlap operationally, but none substitutes automatically for a required CMMC status or DFARS obligation. A dedicated CMMC overview and checker for structuring an initial applicability review are planned.
This article provides general information, not legal advice. Contract-specific questions should be resolved with the contracting officer, prime contractor, and qualified counsel.
No. The Department suspended Phase II, not the CMMC program. Phase I self-assessment designations remain available, and underlying FAR and DFARS obligations continue where included in the contract.
The implementation memorandum directs contracting officers to remove or amend CMMC Level 2 C3PAO designations during the Phase II suspension. Confirm the operative solicitation or contract language with the responsible contracting authority.
Yes. Level 2 Self may still be designated during the suspension. It requires assessment against all 110 NIST SP 800-171 Revision 2 requirements, subject only to the CMMC rules' limited POA&M provisions, plus triennial reassessment and annual affirmation.
No. Safeguarding, cyber-incident reporting, preservation, access, and flowdown duties under DFARS 252.204-7012 continue when that clause applies.
No geographic exemption should be assumed. Applicability depends on the contract and flowdowns, the information involved, and whether the supplier's systems process, store, or transmit FCI or CUI.
The Department has not provided a basis for predicting the outcome of the review. Organizations should make a risk-based decision while continuing to meet current contract requirements and protect FCI and CUI.
Secani connects scopes, evidence, tasks, and AI agents in one shared workspace.
Only about a third of affected companies registered with the BSI on time. Until the end of July 2026 this can be fixed – after that, it gets expensive.
Fewer job postings, restructuring at large consultancies and more visible solo consultants: what the data reveals about the cybersecurity consulting market.
Seven practical questions reveal whether a platform can connect obligations, controls, evidence, risk, and professional judgment in a repeatable system.