DoD Suspends CMMC Third Party Certification, Orders 60-Day Review To Assess Future of Cybersecurity Program

by Roger V. Abbott, Adam A. Bartolanzo on July 14, 2026
Share This Page:

The Department of Defense (DoD) just announced the “immediate suspension” of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program and ordered a “comprehensive review” of how CMMC is implemented across the Defense Industrial Base (DIB). In the meantime, “all Phase I self-assessment requirements remain firmly in place.” In explaining the move, DoD leadership expressed concerns about “unnecessary government red tape” and signaled a renewed focus on “removing paralyzing costs and keeping innovators and competition growing in the defense supply chain.” At the same time, DoD maintained that the cybersecurity of the defense industrial base remains a top priority that can be achieved without imposing prohibitive costs on industry. The Department also reiterated that, during the 60-day review period, it “will enforce cybersecurity compliance with the NIST SP 800-171 Rev 2 standard through self-assessments and select government-led assessments,” and that “[a]ll defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012.”

Return to Self-Assessments?

As discussed in earlier blog posts, DoD established the CMMC program to set up a framework to require contractors to have their cyber compliance assessed by a Certified Third-Party Assessor Organization (C3PAO) before they could handle Controlled Unclassified Information (CUI) in their information systems. The decision to impose this costly requirement was driven by concerns about rampant exfiltration of data from the DIB and widespread non-compliance by contractors with existing requirements. DoD launched Phase I of the CMMC Program on November 10, 2025, and was set to begin Phase II on November 10, 2026. Phase I centers on Level 1 and Level 2 self‑assessments and senior official affirmations, with C3PAO‑assessed Level 2 required only in limited, high‑priority cases. The DoD announcement states that “all Phase I self-assessment requirements remain in place.” It is unclear whether DoD will amend contracts that already require C3PAO assessments to remove these requirements or leave them in place.

Phase II would have pushed a much larger share of solicitations to require C3PAO‑assessed Level 2 certification at award, effectively turning third‑party audits into a widespread gating requirement for tens of thousands of DoD contractors. One likely reason DoD concluded that this timeline “was not going to work” is simple math: the Cyber AB informed industry in a town hall held in May 2026 that a total of 1,391 CMMC Level 2 Final Certifications had been issued so far. This figure is less than 2% of the 76,598 contractors that DoD expected would need to achieve third party certification.

Impact on Industry of The Suspension of CMMC Phase II

For industry, the suspension of Phase II will come as a source of both relief and frustration. Small and mid‑sized contractors struggling to absorb the “paralyzing costs” of third-party certification may well welcome the breathing room this pause provides. At the same time, the announcement upsets the expectations of companies that have invested heavily—and in good faith—in C3PAO assessments, remediation projects, and Level 2 certification. The CMMC Ecosystem—the web of assessors, training providers, and consulting firms that have invested time and resources into obtaining official approval from the Cyber AB to service the DIB on CMMC readiness—will be particularly concerned about the 60-day review because of its potential to upend the very cyber compliance paradigm they’ve spent years becoming experts in and building their businesses around.

The pause also raises broader questions about the trajectory of federal cyber and supply‑chain policy beyond DoD: for example, FAR Council rulemaking on safeguarding CUI appeared to be converging toward the CMMC model in important respects, but it is now unclear whether those proposals will be recalibrated to reflect DoD’s course correction—or move ahead on a different path altogether.

Actions Contractors Should Consider Taking Now

To begin with, the DoD announcement does not make law or change existing contract requirements. If a contract already requires C3PAO assessment, that requirement remains in place until DoD takes further action to suspend or remove that requirement.

In the meantime, defense contractors, now more than ever, need to track developments coming from DoD’s Chief Information Officer like a hawk. Expect updates throughout the entirety of the 60-day review period. Indeed, the Department already has issued a public Request for Information (RFI) regarding compliance challenges that the CMMC Reform Task Force will use to develop a final report. So mark your calendars for August 14, 2026, the deadline to respond to the RFI, and let your opinion about the program (whether positive or negative) be known to the powers that be.  And mark your calendars for September 11, 2026—60 days from July 13 and the deadline by which the task force must provide the Chief Information Officer with their report.

Will this latest review result in the total elimination of C3PAO assessment requirements? Perhaps, but perhaps not. Section 1648 of the National Defense Authorization Act for Fiscal Year 2020 still contemplates some role for third-party certifications, although that role is not clearly defined by the statute. Further, elimination of C3PAOs technically should require promulgation of new rulemaking to undo the updates to 32 C.F.R. Part 170 made in October 2024 to implement the CMMC program. DoD cited as a major contributing factor for the suspension of CMMC Phase II the need to “lower barriers for small, medium, and non-traditional businesses,” so the review could just eliminate C3PAO assessments for all but large, traditional defense contractors.

What is likely to result then is yet another iteration of the program, similar to CMMC 2.0 when the Biden Administration conducted its own suspension pending review five years ago. Like before, this new iteration may have a more scaled down version of the certification requirement. So is CMMC 3.0 forthcoming? Only time will tell!

Miles & Stockbridge’s Government Contracts attorneys will continue to monitor developments affecting CMMC in the days and months to come. Anyone with questions about these developments or cyber obligations in government contracting in general should contact a member of our Cybersecurity, Emerging Technologies & Government Contracts Compliance team.  

Opinions and conclusions in this post are solely those of the authors unless otherwise indicated. The information contained in this blog is general in nature and is not offered, and cannot be considered, as legal advice for any particular situation. The authors have provided the links referenced above for information purposes only and, by doing so, do not adopt or incorporate the contents. Any federal tax advice provided in this communication is not intended or written by the authors to be used, and cannot be used, by the recipient for the purpose of avoiding penalties which may be imposed on the recipient by the IRS. Please contact the authors if you would like to receive written advice in a format which complies with IRS rules and may be relied upon to avoid penalties.

Roger Abbott is smiling and wearing a dark suit with a white shirt multi-colored striped tie. Close-up on face.
Principal
202 465-8401
Email
Portrait of Adam  A. Bartolanzo
Principal
202 465-8388
Email
Related Industries: Government Contracting
File under: Government Contracts (Department of Defense, Contractors, Cybersecurity Maturity Model Certification, DFARS, Compliance, Cybersecurity, Subcontractors)