Policy · 62 days ago
DoD is keeping the current supplier-security bar in place, but it is delaying the independent proof step that would have enforced it for more contractors. That leaves CUI-handing suppliers on self-attestation for longer, which is the easier path for smaller and nontraditional firms to stay in the defense market.
The Pentagon has suspended CMMC Phase II, which was due to start on November 10, 2026, and would have required Level 2 contractors to pass third-party assessments for NIST SP 800-171 controls. Officials launched a 60-day review and said they may scale the program back for small suppliers, while Phase I requirements and existing handling rules still remain.
For procurement and supplier-risk teams, the shift is timing, not removal. The near-term gate on DoD contract access stays lighter than planned, and the move extends reliance on self-attestation instead of independent verification for CUI protection.
2 sources covering this story
Pentagon Suspends CMMC Phase II Requirements for Defense Contractors
The US Department of Defense announced the immediate suspension of the CMMC Phase II requirements until further review
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
A new CMMC review and reform task force will conduct a comprehensive review of the program.
Part of the PlainSec briefing for 2026-07-15