top of page

Manufacturing

Public·4 members

Jake Geier
Jake Geier

Pentagon Hits Pause on CMMC Phase II: What Contractors Need to Know


What:

  • The DoD suspended CMMC Phase II requirements until it reviews the program to allow for more innovation in the US defense industrial base infosecurity-magazine

  • Phase II was originally scheduled to come into effect on November 10, 2026, requiring contractors handling CUI to transition from basic self-attestations to mandatory, independent assessments led by Certified Third-Party Assessment Organizations (C3PAOs) against the 110 NIST SP 800-171 controls infosecurity-magazineinfosecurity-magazine

  • The DoD will stand up a 'CMMC Reform Task Force' to conduct a 60-day, top-to-bottom review of the program infosecurity-magazine

  • During the interim, the DoD will enforce compliance via NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments infosecurity-magazine

  • CMMC Level 1 self-assessment requirements remain in place, per DoD's announcement


⚠️Impact:

  • Roughly 80,000 companies were expected to require CMMC Phase II out of an estimated 220,000 and 300,000 companies in the defense industrial base infosecurity-magazineinfosecurity-magazine

  • A 2025 industry survey found only 1% of defense contractors felt fully prepared for CMMC Phase II audits, suggesting widespread non-readiness may have driven the suspension infosecurity-magazine

  • Phase III (level 3 DoD-led audits) and Phase IV (full compliance for all contractors), originally slated for 2027 and 2028, are now in question

  • The DoD justified the move by arguing the program had created "prohibitive compliance costs and bureaucratic burdens" and was pushing innovative firms out of the DIB infosecurity-magazine


💡Recommendations:

  • Contractors should not treat this as a reason to relax cybersecurity practices — experts caution the suspension is not the time to step back but time to ensure compliance is done right infosecurity-magazine

  • Continue meeting CMMC Level 1 self-assessment obligations, which remain mandatory

  • Keep progressing on NIST SP 800-171 Rev 2 alignment, since self-assessments and select government-led reviews will continue during the interim

  • Monitor outcomes of the 60-day Reform Task Force review, as future enforcement could resume with revised requirements

Read the full story HERE

8 Views
bottom of page