READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

The Pentagon Paused CMMC Phase II. The Cybersecurity Obligation Did Not Pause.

The Pentagon Paused CMMC Phase II. The Cybersecurity Obligation Did Not Pause.
The Department of War suspended CMMC Phase II and launched a 60-day reform review, citing cost, assessor capacity, and barriers for smaller defense suppliers. The third-party certification timetable changed; contractors' underlying duty to protect Controlled Unclassified Information did not.

The Department of War has suspended the next stage of its Cybersecurity Maturity Model Certification rollout, delaying a broad expansion of third-party assessments that was scheduled for November. The move gives contractors relief from an approaching certification deadline, but it does not remove their existing duty to protect Controlled Unclassified Information.

On July 13, the Department of War announced that it was immediately suspending CMMC Phase II, which was scheduled to begin November 10, 2026. Phase II would have expanded the use of CMMC Level 2 certifications performed by Certified Third-Party Assessment Organizations, or C3PAOs, in applicable solicitations and contracts.

The department also put pending and future CMMC implementation milestones on hold and created a reform task force to report within 60 days. Its stated reasons were cost, limited third-party assessment capacity, regulatory complexity, and concern that the existing approach was pushing small, medium-sized, and nontraditional companies out of the Defense Industrial Base.

That is a significant policy change. It is not a suspension of defense-contractor cybersecurity.

What CMMC was designed to do

CMMC is an assessment and verification framework for cybersecurity requirements that already apply to much of the defense supply chain. Contractors that handle Federal Contract Information or Controlled Unclassified Information are subject to safeguarding clauses in federal contracts. For many companies handling CUI, that includes the 110 security requirements in NIST Special Publication 800-171, incorporated through DFARS 252.204-7012.

The phased CMMC rollout was intended to give the government stronger evidence that contractors were meeting those obligations. Phase I relies primarily on self-assessments for many contracts, while allowing the department to require third-party assessments selectively. Phase II would have made C3PAO certification a more common condition of award for contracts involving CUI.

According to the Department of War's updated CMMC guidance, Phase I self-assessment requirements remain in place during the pause. The department says it will continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments. Other contractual cybersecurity clauses also remain intact.

In practical terms, a contractor may have more time before it must present a C3PAO certificate for a new award. It does not have permission to stop implementing access controls, managing vulnerabilities, reporting covered cyber incidents, or protecting CUI.

Why the department hit pause

The department's announcement frames the pause as an acquisition reform measure. It says the current certification model created prohibitive costs and bureaucratic burdens, particularly for smaller companies, and cited Small Business Administration reporting that compliance pressure was driving innovative firms away from defense work.

Assessment capacity was another concern. Phase II would have sharply increased demand for third-party reviews across a supply chain that includes more than 220,000 organizations. Industry observers have warned that a limited pool of authorized assessors could turn certification scheduling, rather than security performance, into a barrier to competition.

The reform task force now has to reconcile two goals that are both real: reducing the cost and friction of proving compliance, and giving the government credible assurance that sensitive defense information is protected.

Supporters of the pause argue that the existing model asked too many small businesses to fund complex, customized compliance programs or compete for scarce assessment slots. Critics warn that weakening independent verification could recreate the problem CMMC was meant to address: years of uneven self-attestation across a heavily targeted supply chain. The threat environment has not become less serious because the certification calendar changed.

What the pause means for contractors

For organizations already deep into remediation or preparing for an assessment, the immediate decision is not simply whether to continue or stop. It is which work remains valuable even if the certification mechanism changes.

Security improvements tied directly to the handling of CUI remain durable investments: multifactor authentication, least-privilege access, asset and data inventories, secure configuration, incident response, logging, vulnerability remediation, and documented control ownership. Those measures reduce operational risk and support existing contractual obligations regardless of how the department redesigns CMMC.

Spending that exists only to satisfy a particular assessment artifact may deserve closer review until the task force reports. Contractors should also check the actual clauses in each solicitation and contract rather than relying on a general announcement; the pause does not rewrite every existing agreement or remove requirements imposed through other authorities.

CloudFit Software, the sponsor of this article and a provider of CMMC-related services, argues that the distinction between security and certification should guide the response. In its public statement on the pause, the company wrote that "the objective has always been bigger than CMMC. The objective is securing the DIB."

CloudFit describes the pause as an opportunity to move away from treating CMMC as a checkbox and toward scalable security outcomes. It also argues that the prevailing choice facing many smaller contractors—pay for an expensive custom compliance build, delay investment, or manage the work alone—does not scale across a 220,000-plus-organization industrial base. CloudFit offers easyCMMC as one managed approach in this market, but its broader recommendation is that contractors continue investing in real cyber defense while the policy is under review.

That view is directionally consistent with guidance from government-contracting attorneys and assessment firms since the announcement: the certification timetable changed, but underlying FAR and DFARS duties did not.

The next 60 days matter

The reform task force's recommendations will determine whether Phase II returns in modified form, whether third-party assessments are targeted more narrowly, or whether the department adopts a different way to verify security at scale. Key questions include how to preserve independent assurance, how to prevent assessment scarcity from excluding capable suppliers, and how to make compliance affordable without turning it into self-attestation alone.

For contractors, the safest reading of the pause is narrow. The deadline for a broader third-party certification regime has moved. The obligation to secure government information has not. Organizations that use the review period to strengthen controls, document evidence, and reduce the real pathways by which CUI can be exposed will be better positioned under almost any replacement framework.

This article is general informational content and does not constitute legal or compliance advice. Requirements depend on contract language and organizational circumstances.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

industry
National DefensePentagon's CMMC Pause Draws Praise, Criticism from Industry
legal analysis
Morgan LewisDepartment of War Suspends CMMC Phase II Requirements, but Cybersecurity Obligations Remain
primary
Department of WarForging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements
sponsor viewpoint
CloudFit SoftwareCloudFit's Perspective on the Recent CMMC Phase II Pause