Schneider Downs
CMMC Phase II Suspension Announcement
Pages
5
Time to read
5 mins
Publication
Language
English
Pages
5
Time to read
5 mins
Publication
Language
English
This document is a technical report detailing the suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II implementation requirements as announced by the Department of Defense (DoD) on July 13, 2026. The suspension affects contractors handling Controlled Unclassified Information (CUI), who will no longer need to obtain certification from a Certified Third-Party Assessment Organization (C3PAO) as previously required. The DoD has initiated a 60-day CMMC Reform Task Force to review the program and recommend changes. Despite the suspension of third-party assessments, contractors remain obligated to comply with existing cybersecurity requirements under DFARS and NIST SP 800-171. The report outlines what remains required of contractors, including self-assessments and maintaining necessary documentation. It also discusses the uncertainty surrounding future third-party certification and the potential changes to the CMMC framework. Contractors are advised to continue their cybersecurity efforts and monitor updates from the DoD.