Photo of Kate GrowleyPhoto of Nkechi KanuPhoto of Jessica ChaoPhoto of Jacob HarrisonPhoto of Ajan JayantPhoto of Bryan DewanPhoto of Caitlyn Weeks

The Department of War (DoW) is immediately suspending Cybersecurity Maturity Model Certification (CMMC) Phase II requirements, which had been scheduled to take effect on November 10, 2026.

What is CMMC, and What is Phase II?

DoW’s CMMC program is a certification initiative to verify that the Defense Industrial Base is consistently implementing mandatory cybersecurity controls to protect Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). DoW had planned for CMMC to take effect over a four-phase rollout. Phase I took effect on November 10, 2025, and focused on contractor self-assessment requirements. Phase II, which had been expected to take effect on November 10, 2026, would see the inclusion of third-party assessment requirements in DoW contracts.

What Happened?

Citing prohibitive compliance costs and bureaucratic burdens, the DoW announced the suspension of Phase II in alignment with Secretary Hegseth’s initiatives to streamline the acquisition process.  The DoW specified that it is suspending the transition to Phase II requirements of CMMC, as well as pending and future CMMC implementation milestones across the Department of War solicitations and contracts.

The DoW’s Chief Information Officier is establishing a CMMC Reform Task Force to conduct a comprehensive top-to-bottom review of the certification program, synthesizing industry feedback obtained through a public Request for Information and delivering a final report within 60 days.

During this review period, DoW will continue to enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard via self-assessments and select government-led assessments.

What Remains Unchanged?

As DoW notes, this action does not eliminate other contractual requirements to protect federal data. Importantly, all defense contractors and subcontractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012.  Additionally, DoW noted that CMMC Phase I self-assessment requirements “remain firmly in place.”  These include Level 1 self-assessed certifications and attestations to protect FCI, as well as Level 2 self-assessments and attestations to protect CUI. The DoW did not explicitly reference the discretion that Phase 1 provided the DoW to require C3PAO assessments on a case-by-case basis before Phase 2. 

UPDATE July 14, 2026.  DoW has clarified in a memo accompanying the Phase II suspension press release that any active solicitations and contracts, which already include CMMC Level 2 C3PAO or CMMC Level 3 assessment requirements, must be amended to remove those requirements.  Solicitations must be amended “as soon as practicable” while the memo directs contracting officers to amend existing contracts “prior to the exercise of the next option period or during the next scheduled administrative modification.”

What This Means for Contractors?

Defense contractors should continue to maintain robust cybersecurity practices under existing DFARS obligations, monitor for opportunities to submit feedback to the Reform Task Force, and track the 60-day review for guidance on revised CMMC requirements.

Defense contractors should be aware that while the Phase II rollout is paused, existing compliance obligations, particularly DFARS 252.204-7012 and CMMC Phase I requirements, remain in force. Whether or not CMMC certification obligations change, contractors will need to implement NIST SP 800-171 to safeguard DoW CUI and ensure they can defend their practices under government scrutiny. The Department of Justice remains vigilant about leveraging the False Claims Act to investigate alleged noncompliance with DFARS 252.204-7012 and 252.204-7020 under its Civil Cyber-Fraud Initiative, and could expand its focus to false or inaccurate CMMC Phase I self-assessments in the future.

For more information, please contact the Crowell & Moring Government Contracts and Privacy and Cybersecurity Groups.

Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Kate Growley Kate Growley

Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy…

Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy and regulatory environment for some of the most complex data issues facing multinational companies, including cybersecurity, privacy, and digital transformation. Kate has worked with clients across every major sector, with particular experience in technology, health care, manufacturing, and aerospace and defense. Kate is a Certified Information Privacy Professional (CIPP) in both the U.S. private and government sectors by the International Association of Privacy Professionals (IAPP). She is also a Registered Practitioner with the U.S. Cybersecurity Maturity Model Certification (CMMC) Cyber Accreditation Body (AB).

Photo of Nkechi Kanu Nkechi Kanu

Nkechi A. Kanu is a counsel in the Washington, D.C. office of Crowell & Moring, where she is a member of the firm’s Government Contracts Group.

Nkechi’s practice focuses on False Claims Act investigations and litigation. Nkechi has significant experience assisting companies with…

Nkechi A. Kanu is a counsel in the Washington, D.C. office of Crowell & Moring, where she is a member of the firm’s Government Contracts Group.

Nkechi’s practice focuses on False Claims Act investigations and litigation. Nkechi has significant experience assisting companies with complex internal investigations and represents clients in government investigations involving allegations of fraud. She also focuses on assisting clients with investigations relating to cybersecurity and information security compliance. Her complementary litigation practice involves defending companies in government-facing litigation arising under the FCA, resulting in the dismissal of qui tam complaints and successful settlements of FCA claims with DOJ.

Photo of Jacob Harrison Jacob Harrison

Jacob Harrison helps his clients navigate both domestic and international legal challenges.

Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including

Jacob Harrison helps his clients navigate both domestic and international legal challenges.

Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including for cybersecurity compliance reviews, risk assessments, and data breaches.

In his international practice, Jake represents foreign and domestic clients in Foreign Sovereign Immunities Act and Anti-Terrorism Act litigation. He also has experience advising clients involved in cross-border commercial arbitration proceedings.

During law school, Jake served as an associate editor of the Emory Law Journal and interned at the Supreme Court of Georgia and the Georgia House Democratic Caucus. Before attending law school, Jake worked in politics and state government.