· CMMC  · 5 min read

Department of War Suspends CMMC Phase 2 and Opens a 60-Day Reform Review

On July 13, 2026 the Department of War suspended the November 2026 CMMC Phase 2 transition, restricted new procurements to Level 1 and Level 2 self-assessments, and launched a 60-day review of the certification program. DFARS 252.204-7012 remains in effect.

On July 13, 2026 the Department of War (DoW) suspended the upcoming November 2026 transition to CMMC Phase 2 and directed a 60-day, top-to-bottom review of the certification program. Chief Information Officer Kirsten A. Davies signed the CIO memorandum. Under Secretary of War Michael P. Duffey signed the accompanying implementation memorandum. Both memos take effect on July 13, 2026.

The bottom line for defense industrial base contractors: DFARS 252.204-7012 stays in force, and NIST SP 800-171 Rev 2 remains the baseline the DoW enforces through self-assessments and select government-led assessments. Any Level 2 (C3PAO) or Level 3 (DIBCAC) requirement on a current or future DoW solicitation is coming off. This post walks through what the memos say and what to do now.

The CIO memorandum

In the CIO memorandum, titled “Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of Cybersecurity Maturity Model Certification Requirements,” Davies directs an immediate suspension of the November 2026 Phase 2 transition. The DoW is holding all pending and future CMMC implementation milestones across DoW solicitations and contracts in abeyance until further notice. Program Managers and requiring activities may only include the need for CMMC Level 1 or Level 2 Self Assessments in procurement request and requirement documents. All other contractual cybersecurity clauses in contracts remain intact.

Davies also directs the establishment of a CMMC Reform Task Force that will conduct a 60-day, top-to-bottom review of the certification program. The Task Force will recommend a reformed cybersecurity and operational resilience framework that prioritizes speed to capability and lowers barriers for smaller and non-traditional businesses. That reformed framework would replace the current third-party assessment construct with what Davies calls scalable, realistic security measures.

The interim cyber posture during the suspension remains substantive. The DoW will continue to enforce baseline compliance with NIST SP 800-171 Rev 2 through DIB self-assessments and select government-led assessments. The cybersecurity requirements in DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect. The DoW Cyber Crime Center and the NSA Cybersecurity Collaboration Center continue as no-cost resources for the DIB, and Project Spectrum from the Office of Small Business Programs remains available.

Davies writes: “We will not defeat our adversaries with compliance checklists; we will defeat them by rapidly fielding superior capabilities produced by an expanded, resilient American industrial base.” Davies cites Small Business Administration reports as the evidence base and points to compliance costs and third-party assessment capacity constraints as the reasons smaller and non-traditional businesses have been opting out of DoW contracts.

Contracting instructions in the Under Secretary’s memo

Duffey’s implementation memo translates the CIO direction into contracting instructions for program offices. Attachment 1 to the memo lays out the operational procedures:

  • Only Level 1 (Self) or Level 2 (Self) may be designated during the suspension. Program Managers and requiring activities may not designate CMMC Level 2 (C3PAO) or CMMC Level 3 (DIBCAC) assessments.
  • Program Managers must amend current solicitations that already include a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement. The contracting officer must issue a corresponding solicitation amendment as soon as practicable.
  • Contracting officers must modify existing contracts that carry those requirements. The direction is to remove them prior to the exercise of the next option period or during the next scheduled administrative modification.
  • The DoW will not grant waivers during the review period.

Attachment 1 restates the substantive point verbatim: “The cybersecurity requirements outlined in the clause at DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect.”

Action items for DIB contractors

Nothing in either memo relaxes the baseline. Contractors’ obligations to protect Federal Contract Information and Controlled Unclassified Information stand. The reform posture rebalances the enforcement mechanisms.

  • Keep your NIST 800-171 Rev 2 self-assessment current. The baseline is the reference standard the DoW is enforcing through the suspension period.
  • Keep your SPRS score current. The scoring model tied to 800-171 Rev 2 remains the mechanism for demonstrating self-assessment posture. Our post on SPRS scoring under NIST 800-171 covers the point calculation.
  • Preserve your System Security Plan and POA&M discipline. Government-led assessments during the suspension will examine the same evidence a C3PAO would have.
  • Do not tear down assessment readiness work. The reform outcome is unknown, and a reformed framework may still expect the same technical controls that Level 2 assessed.
  • Watch for contract modifications. If a current solicitation or contract references Level 2 (C3PAO) or Level 3 (DIBCAC), expect a modification from your contracting officer to remove that specific requirement.
  • Keep DFARS 252.204-7012 obligations current. The 72-hour cyber incident reporting obligation is unchanged. Our post on DFARS 252.204-7012 requirements covers the mechanics.

If you were mid-preparation for a Level 2 C3PAO assessment scheduled after the suspension took effect, coordinate with your prime contractor and, where you were already engaged with a C3PAO, with the assessment organization on next steps. Under the current directive, DoW contracts will not designate the Level 2 (C3PAO) or Level 3 (DIBCAC) assessment requirement during the review.

Impact on Verasor engagements

Verasor’s engagement scope is unchanged. Readiness against NIST 800-171 Rev 2 remains the substantive floor for any contractor handling CUI. Our mock assessment service uses NIST SP 800-171A assessment objectives as its evaluation standard, and that standard is what the DoW continues to enforce through self-assessment and government-led assessments. The 60-day review may adjust the enforcement architecture around this floor. The technical baseline stands.

The DoW will publish further guidance at the conclusion of the CIO’s 60-day review. We will follow up when the Task Force publishes conclusions and the DoW issues further guidance.

Sources

Want a structured starting point?

Our 27-question CMMC technical readiness self-survey covers tenant, identity, endpoint, data protection, audit logging, documentation, and the 72-hour DFARS reporting plan. The score is produced in your browser from your answers alone. Nothing is verified or stored.

Back to Blog

Related Posts

View All Posts »
FedRAMP Equivalency for CMMC: What Cloud Providers Must Demonstrate

FedRAMP Equivalency for CMMC: What Cloud Providers Must Demonstrate

Contractors that place CUI in a cloud must require FedRAMP Moderate authorization or documented equivalency, and the provider must prove it with a FedRAMP-recognized 3PAO assessment, a complete Moderate baseline implementation, and a body of evidence that clarifies shared responsibility.