ARTICLE
7 August 2026

U.S. Department Of War Pauses CMMC Phase II Program Requirements

D
Dechert

Contributor

Dechert is the law firm that helps business leaders lead. For more than 150 years, we have advised clients on critical issues – from high-stakes litigation to first-in-market transaction structures and complex regulatory matters. Our lawyers in commercial centers worldwide are immersed in the key sectors we serve – financial services, private capital, real estate, life sciences and technology. Dechert delivers unwavering partnership so our clients can achieve unprecedented results.
On July 13, 2026, the Department of War (“Department” or “DOW”) announced the immediate suspension of its Cybersecurity Maturity Model Certification (“CMMC”) Phase II requirements, which would have required most contractors handling Controlled Unclassified Information (“CUI”) to complete a third-party cybersecurity assessment by November 10, 2026.
United States Accounting and Audit
Dechert are most popular:
  • within Insurance and Antitrust/Competition Law topic(s)
  • in European Union
  • with readers working within the Technology industries
On July 13, 2026, the Department of War (“Department” or “DOW”) announced the immediate suspension of its Cybersecurity Maturity Model Certification (“CMMC”) Phase II requirements, which would have required most contractors handling Controlled Unclassified Information (“CUI”) to complete a third-party cybersecurity assessment by November 10, 2026. Phase 1 self-assessment requirements remain in place, but the Department is conducting a 60-day study of the CMMC program’s future, and all pending and future CMMC implementation milestones have been suspended in the interim.

DOW Chief Information Officer Kirsten A. Davies said the suspension and accompanying 60-day study were a response to concerns about burdening small and medium-sized businesses with regulatory and administrative requirements that could prevent innovative companies from participating in the defense industry. She added that “robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness” and that the Department believes the defense industrial base can achieve both while reducing unnecessary hurdles.

The Department is establishing a task force to conduct a review of the CMMC program based on industry feedback, with industry input due by August 14, 2026 and the task force’s final report set to be delivered to the Department’s CIO in mid-September. During the interim period, the Department indicated that it will continue enforcing cybersecurity compliance with the relevant NIST standards through self-assessments and select government-led assessments focused on meaningful cyber hygiene. The Department also emphasized that the CMMC suspension does not eliminate contractors’ and subcontractors’ underlying contractual obligations to safeguard covered defense information.

Takeaway: Federal contractors and subcontractors have received, at minimum, a temporary reprieve from CMMC’s burdensome third-party assessment requirement, though many have already invested the relevant time and resources to obtaining relevant certifications given the original November 2026 deadline. Ideally, whatever changes are made to CMMC based on the task force’s work will not require companies that have already obtained third-party certifications to re-complete the process. Companies in this space will want to consider whether to submit feedback to the task force prior to the August 14, 2026 deadline and will need to closely monitor the CMMC Reform Task Force’s public Request for Information process, as the resulting recommendations may determine the ultimate fate of CMMC Phase II.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More