On July 13th, the U.S. Department of Defense Chief Information Officer Kirsten Davies signed out a memo to suspend the November 10, 2026, deadline for Phase 2 of the Department’s Cybersecurity Maturity Model Certification (CMMC) program and initiated a 60-day “top-to-bottom” review of the certification program itself. For years, government contractors have been preparing for this next phase and the Department’s pause of aspects of CMMC Phase 2 have generated a mix of relief, frustration, and uncertainty throughout the contractor community.
The reality is that this development does not signal a retreat from existing cybersecurity requirements for federal contractors and subcontractors. Instead, it reflects the government's ongoing effort to balance the need for national cybersecurity protections across the defense supply chain with the practical challenges facing defense contractors, especially for small, medium-sized, and non-traditional contractors.
What is CMMC Phase 2?
CMMC Phase 2 expanded the use of formal third-party assessments for contractors handling sensitive information and Controlled Unclassified Information (CIU). For many contractors, this would have marked a shift from self-assessment toward third-party certifications of compliance with NIST SP 800-171 security requirements.
Key Takeaway
The suspension affects the timing and scope of future CMMC implementation, but it does not suspend current contractual, regulatory, or flow-down cybersecurity obligations. Phase 1 self-assessment requirements remain relevant, and contractors should maintain documentation to show accurate Supplier Performance Risk System (SPRS) submissions, compliance with applicable FAR and DFARS safeguarding clauses, current System Security Plans (SSPs), proper tracking of remediation through Plans of Action and Milestones (POA&Ms), and flow-down obligations across subcontractor and supplier relationships.
Bottom Line
The suspension of CMMC Phase 2 is a regulatory recalibration rather than a policy reversal. Federal contractors that continue to build and document a practical cybersecurity program will be better positioned for future contract awards and any revised CMMC framework that follows the Department’s review.
If you have questions or need guidance navigating the CMMC review and its implications for your contracts and security program, contact the Boon Group at solutions@boongroup.com — our team is ready to help you assess risk, update controls, and stay positioned for compliance.
On March 26, 2026, Executive Order 14398 (Addressing DEI Discrimination by Federal Contractors) marked a meaningful shift in how compliance is evaluated in federal procurement. Together with new...
On March 26, 2026, Executive Order 14398 (Addressing DEI Discrimination by Federal Contractors) marked a meaningful shift in how compliance is evaluated in federal procurement. Together with new...
In the dynamic world of government contracting, understanding local regulations is essential for success. This month, we spotlight a pivotal law that impacts contractors operating in San Francisco:...