Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Years in the Making, Suspended in a Day: DoD/W Halts CMMC Phase II but Keeps Baseline Cybersecurity Obligations

By Michael Barnicle, Hilary Cairnie, Peter Jeydel, Lu Reyes, Bryan Williamson, Bonnie Gill, Anthony Pappas & Trey Smith on July 16, 2026
Email this postTweet this postLike this postShare this post on LinkedIn

Table of Contents

  • Key Points
  • 1. Key Takeaways for Defense Contractors
  • 2. Why DoD/W Acted
  • 3. The CMMC Reform Task Force and What Comes Next
  • 4. Practical Guidance and Recommendations

Link to Key Points Key Points

  • DoD suspended CMMC Phase II on July 13, 2026, halting the November 10, 2026, deadline and all related implementation milestones pending a comprehensive reform review by a newly established CMMC Reform Task Force. 
  • CMMC Level 2 (C3PAO) and Level 3 (DIBCAC) third-party assessment requirements are suspended, and active solicitations and contracts must be amended to remove those designations during the suspension period. 
  • Core cybersecurity obligations remain enforceable: DFARS 252.204-7012, NIST SP 800-171 Rev. 2 compliance, cloud security requirements, and cyber incident reporting duties are all still in effect. 
  • The SBA estimates CMMC third-party certification costs can reach approximately $593,800 per small firm, a burden cited as a key driver of the suspension and of small contractor attrition from the defense industrial base. 
  • Defense contractors have until August 14, 2026, to submit RFI responses and directly influence the design of the reformed CMMC program. 

On July 13, 2026, the U.S. Department of Defense/War (DoD/W) announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements — scheduled to take effect on November 10, 2026 — pending a top-to-bottom review by a newly established CMMC Reform Task Force. The announcement, formally titled “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of Cybersecurity Maturity Model Certification Requirements,” came as a surprise reversal after years of rulemaking activity stretching back to 2019. In addition to the announcement, DoD/W published an implementation memo outlining the procedural rollout of the CMMC suspension. For defense contractors and their compliance teams, the suspension raises immediate practical questions about what changes, what remains, and what comes next.

Link to 1. Key Takeaways for Defense Contractors 1. Key Takeaways for Defense Contractors

  • Phase II is suspended immediately. The November 2026 deadline for CMMC Phase II transition is suspended, and all pending and future CMMC implementation milestones across DoD/W solicitations and contracts are held in abeyance until further notice. 
  • Phase I and II self-assessment requirements remain in effect. CMMC Level 1 (Self) and Level 2 (Self) assessments are still required. Program managers and requiring activities may only designate these two assessment types in solicitations and contracts going forward. 
  • Third-party certification requirements are off the table for now. CMMC Level 2 (C3PAO) and Level 3 (DIBCAC) assessments may not be designated during the suspension period. Active solicitations and contracts containing these requirements must be amended or modified to remove them. 
  • Core DFARS cybersecurity obligations remain. The suspension does not affect contractors’ foundational cybersecurity obligations. DoD/W will continue enforcing baseline compliance with NIST SP 800-171 Rev. 2. Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, is still in effect, as are NIST SP 800-171 Rev. 2 compliance requirements, cloud security obligations, and cyber incident reporting duties. 
  • Industry has a 60-day window to shape the future program. DoD/W has issued a request for information (RFI) seeking industry feedback on reforming CMMC by utilizing existing commercial cybersecurity capabilities, optimizing self-attestation capabilities, and streamlining cybersecurity compliance requirements. Responses are due August 14, 2026. 

Link to 2. Why DoD/W Acted 2. Why DoD/W Acted

The suspension reflects mounting pressure from small business stakeholders, the Small Business Administration (SBA), and the Defense Industrial Base (DIB) at large. DoD/W’s announcement cited “prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines” as structural incompatibilities with its goal to rapidly expand the defense industrial base. The SBA, which issued its own commendation of the suspension, estimates that CMMC compliance costs can reach approximately $593,800 per certification for small firms requiring third-party assessment, and approximately $388,600 for firms eligible for self-assessment — burdens the SBA states have caused many small contractors to exit or consider exiting defense work entirely.

Link to 3. The CMMC Reform Task Force and What Comes Next 3. The CMMC Reform Task Force and What Comes Next

DoD/W’s chief information officer is immediately establishing a CMMC Reform Task Force charged with conducting a 60-day comprehensive review of the certification program. Its mandate: recommend a reformed cybersecurity framework that accelerates capability, reduces barriers for small and nontraditional businesses, and replaces costly third-party compliance models with scalable security measures.

Link to 4. Practical Guidance and Recommendations 4. Practical Guidance and Recommendations

  • Do not stand down on cybersecurity compliance. DFARS 252.204-7012 obligations, NIST SP 800-171 Rev. 2 requirements, and Level 1 and 2 self-assessment requirements remain intact and enforceable. 
  • Review active solicitations and contracts. If your solicitation or contract currently requires CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) certification, expect — and monitor for — amendments and modifications from the contracting activity removing those requirements. 
  • Consider participating in the RFI. The DoD/W RFI (Notice ID: DoDCIOReformingCMMCforDIB001, due August 14, 2026) presents a direct opportunity for contractors to influence how the reformed CMMC program is designed. 
  • Stay alert to Task Force recommendations. The Task Force’s 60-day review will conclude with reform recommendations that could significantly reshape CMMC requirements. Contractors should monitor announcements closely and be prepared to adapt compliance strategies accordingly. 

This article is intended for general informational purposes only and does not constitute legal advice. Receipt of this article does not establish an attorney-client relationship. Defense contractors should consult with qualified legal counsel regarding their specific CMMC and DFARS compliance obligations. For more information, please contact the authors.

© 2026 Troutman Pepper Locke LLP. All rights reserved.

Photo of Michael Barnicle Michael Barnicle

Michael offers litigation, compliance, and corporate transactional services across government contracting and international trade, including national security and cybersecurity. His understanding of federal contracting and global commerce enables him to help clients anticipate issues, mitigate risk, and achieve business objectives.

Read more about Michael BarnicleEmail
Photo of Hilary Cairnie Hilary Cairnie

An experienced and sought-after strategist, Hilary Cairnie counsels clients in nearly all types of government contracting matters.

Read more about Hilary CairnieEmailHilary's Linkedin Profile
Photo of Peter Jeydel Peter Jeydel

Pete helps clients navigate today’s increasingly complex regulatory and enforcement environment at the intersection of national security, international trade, finance, and technology. He works with clients to identify innovative solutions to business problems arising from these often daunting and highly technical regulations, based

…

Pete helps clients navigate today’s increasingly complex regulatory and enforcement environment at the intersection of national security, international trade, finance, and technology. He works with clients to identify innovative solutions to business problems arising from these often daunting and highly technical regulations, based on a clear understanding of the government’s expectations and priorities.

Read more about Peter JeydelEmail
Show more Show less
Photo of Lu Reyes Lu Reyes
Email
Photo of Bryan Williamson Bryan Williamson

Bryan advises clients on a range of complex government contracts and national security matters. His experience as a government contracts litigation attorney in the U.S. Army Judge Advocate General’s (JAG) Corps gives him unique perspective on navigating the complexities of doing business with…

Bryan advises clients on a range of complex government contracts and national security matters. His experience as a government contracts litigation attorney in the U.S. Army Judge Advocate General’s (JAG) Corps gives him unique perspective on navigating the complexities of doing business with the government.

Read more about Bryan WilliamsonEmail
Show more Show less
Photo of Bonnie Gill Bonnie Gill

Bonnie is an associate in the firm’s Regulatory Investigations, Strategy + Enforcement Practice Group, where she counsels clients in all stages of federal and state enforcement actions, related civil litigation, corporate compliance, and internal investigations. She also handles matters before state regulatory bodies.

Read more about Bonnie GillEmailBonnie's Linkedin Profile
Photo of Anthony Pappas Anthony Pappas

Tony is an associate in the firm’s Regulatory Investigations, Strategy + Enforcement practice. He received his J.D. from the William & Mary Law School, where he served as a staff member for the William & Mary Bill of Rights Journal.

Read more about Anthony PappasEmail
Photo of Trey Smith Trey Smith

Trey is an associate in the firm’s Regulatory Investigations, Strategy + Enforcement Practice. He focuses his practice on helping financial institutions and consumer facing companies navigate regulatory investigations and resulting litigation. He has experience litigating the Consumer Financial Protection Act, the FTC Act…

Trey is an associate in the firm’s Regulatory Investigations, Strategy + Enforcement Practice. He focuses his practice on helping financial institutions and consumer facing companies navigate regulatory investigations and resulting litigation. He has experience litigating the Consumer Financial Protection Act, the FTC Act, the Truth in Lending Act, state UDAAP statutes, and other consumer protection laws.

Read more about Trey SmithEmail
Show more Show less
  • Posted in:
    Corporate Governance and Compliance
  • Blog:
    Regulatory Oversight
  • Organization:
    Troutman Pepper Locke
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo