
The Department of War’s decision to suspend Phase II of the Cybersecurity Maturity Model Certification program has created both relief and confusion across the Defense Industrial Base.
On July 13, 2026, the Department announced that CMMC Phase II requirements, which were scheduled to take effect on November 10, 2026, would be suspended while a CMMC Reform Task Force conducts a comprehensive review of the program. The review is intended to identify ways to reduce compliance costs and administrative burdens while maintaining adequate cybersecurity protections.
However, contractors should not interpret the announcement as the end of CMMC or as permission to pause their cybersecurity preparations.
Phase II has been suspended. CMMC Level 2 has not.
The government also continues to enforce existing DFARS and NIST SP 800-171 requirements, prime contractors may continue imposing their own cybersecurity expectations, and the Defense Industrial Base Cybersecurity Assessment Center, or DIBCAC, can still select companies for government-led assessments.
Here is what defense contractors need to understand and what they should be doing now.
Phase II Is Suspended, but Level 2 Is Not
One of the most important distinctions in the recent announcement is the difference between a CMMC implementation phase and a CMMC security level.
CMMC Phase II refers to the second stage of the government’s planned rollout. It would have expanded the use of CMMC requirements in solicitations and contracts, including mandatory third-party assessments for many contractors that handle Controlled Unclassified Information, or CUI.
CMMC Level 2, however, is the security level based on the 110 requirements of NIST SP 800-171. It applies to organizations that store, process, or transmit CUI.
The Department suspended the transition to Phase II. It did not eliminate the Level 2 security requirements or contractors’ underlying obligations to protect federal information.
In its announcement, the Department made several points clear:
- All Phase I self-assessment requirements remain in effect.
- Cybersecurity compliance will continue to be enforced through self-assessments and selected government-led assessments.
- Defense contractors and subcontractors remain contractually obligated to safeguard Covered Defense Information under DFARS 252.204-7012.
- NIST SP 800-171 Revision 2 remains the standard used during the interim period.
This means contractors may still need to perform a NIST SP 800-171 self-assessment, maintain an accurate score in the Supplier Performance Risk System, and continue addressing weaknesses identified in their System Security Plan and Plan of Action and Milestones.
The pause changes the timing of the government’s broader rollout. It does not remove the cybersecurity baseline.
Prime Contractors May Not Be Pausing
Even if the government pauses certain CMMC implementation milestones, prime contractors do not necessarily have to pause their own supplier requirements.
Prime contractors are responsible for managing cybersecurity risk throughout their supply chains. Many have invested significant time and resources in preparing their suppliers for CMMC and strengthening protections for CUI. They may be unwilling to reverse course simply because the government is reconsidering aspects of the program.
A prime contractor may continue to require subcontractors to:
- Provide a current SPRS score
- Demonstrate compliance with NIST SP 800-171
- Complete a cybersecurity questionnaire
- Submit evidence supporting claimed security practices
- Provide an updated System Security Plan
- Maintain an active POA&M
- Obtain a CMMC Level 2 certification
- Meet cybersecurity requirements as a condition of receiving or retaining work
Prime contractors may include these requirements in supplier agreements, purchase orders, subcontract terms, or internal vendor qualification programs. In some cases, a prime may impose standards that are more demanding than the government’s current minimum requirements.
Existing DFARS obligations also continue to flow down through the supply chain. DFARS 252.204-7020 generally prohibits a contractor from awarding a covered subcontract unless the subcontractor has a current NIST SP 800-171 DoD Assessment posted in SPRS for the systems relevant to the work.
For subcontractors, the practical question is therefore not only, “What is the government requiring today?” It is also, “What will our prime contractors require before they continue doing business with us?”
Waiting for the government’s reform process to conclude could leave a company unprepared for a customer request, supplier review, proposal deadline, or contract requirement.
DIBCAC Assessments Are Still Happening
The CMMC Phase II suspension does not prevent the government from conducting NIST SP 800-171 assessments.
DIBCAC leads the government’s assessment of defense contractors’ compliance with DFARS 252.204-7012, NIST SP 800-171, and DFARS 252.204-7020. The Department’s Phase II announcement specifically stated that it would continue enforcing cybersecurity compliance through self-assessments and selected government-led assessments.
These DIBCAC assessments are not necessarily voluntary.
Under DFARS 252.204-7020, contractors must provide government assessors with access to the facilities, systems, and personnel necessary to conduct a Medium or High NIST SP 800-171 DoD Assessment when required.
A Medium Assessment can include a review of the contractor’s Basic Assessment, a thorough review of its documentation, and discussions with personnel. A High Assessment goes further by requiring assessors to verify, examine, and observe whether the security requirements described in the contractor’s System Security Plan have actually been implemented.
In other words, a submitted SPRS score is not always the final word. The government may independently evaluate whether the score is supported by documentation and operational evidence.
Your SPRS Score May Attract Scrutiny
DIBCAC can review the scores contractors have submitted to SPRS when selecting organizations for assessment. Contractors reporting high scores should not assume they are less likely to be reviewed.
A high SPRS score communicates that most or all applicable NIST SP 800-171 requirements have been implemented. If selected for an assessment, the contractor must be able to substantiate that claim with current documentation, technical evidence, interviews, and demonstrations of how its controls operate.
Recent industry data illustrates why reported scores may receive greater scrutiny. The average self-reported SPRS score has increased, while contractors’ confidence in the accuracy of their own scores has declined. This gap between reported compliance and confidence may make verification increasingly important.
Contractors should also be prepared for short notice. Some organizations selected for government-led assessments reportedly receive approximately two weeks to assemble documentation, coordinate personnel, and prepare for the assessment process. That is not enough time to build a compliant environment or recreate months of missing evidence.
Contractors should also distinguish that reported preparation window from the formal rebuttal period. Under DFARS 252.204-7020, after a Medium or High Assessment is completed, a contractor generally has 14 business days to submit additional information or rebut findings before the final score is posted in SPRS.
The safest approach is to operate as though an assessment notification could arrive at any time.
What Contractors Should Do During the Pause
The Phase II suspension provides additional time, but that time should be used to strengthen readiness rather than stop progress.
1. Confirm that your SPRS score is accurate
Review how the score was calculated and verify that every claimed requirement is supported by evidence. Do not submit an aspirational score based on controls that are planned but not fully implemented.
An inaccurate or unsupported score can create contractual, financial, and legal exposure. Claims about cybersecurity compliance may also be examined under the False Claims Act when the government believes a contractor knowingly misrepresented its compliance.
2. Review your System Security Plan
Your SSP should accurately describe the current system environment, security boundaries, technologies, responsibilities, and implementation of each applicable NIST SP 800-171 requirement.
An outdated or generic SSP can undermine an otherwise strong security program because assessors use it as a central roadmap during their review.
3. Update and actively manage your POA&M
Any requirement that has not been fully implemented should be documented in the Plan of Action and Milestones, when permitted. Each item should have a responsible owner, planned remediation steps, necessary resources, and a realistic completion date.
A POA&M should be an active management tool, not a list that is created and then ignored.
4. Organize assessment evidence now
Contractors should maintain an evidence repository containing items such as:
- Security policies and procedures
- Network and data-flow diagrams
- System configurations
- Access-control records
- Multifactor authentication evidence
- Security awareness and role-based training records
- Vulnerability scan and remediation records
- Incident-response plans and test results
- Audit logs and monitoring records
- Risk assessments
- Configuration management records
- Screenshots, reports, and other technical artifacts
Evidence should demonstrate that controls are implemented and operating consistently, not simply that a policy exists.
5. Prepare employees for assessor interviews
DIBCAC assessments can involve discussions with technical personnel, managers, security staff, and system users. Employees should understand their responsibilities and be able to accurately explain how the organization performs required security activities.
6. Ask prime contractors what they expect
Do not assume your customers have adopted the government’s pause. Contact relevant prime contractors and ask whether their supplier cybersecurity requirements, certification deadlines, or procurement standards have changed.
Obtain expectations in writing whenever possible.
7. Continue preparing for Level 2
CMMC may be restructured, simplified, or phased in differently following the government’s review. However, the need to protect CUI and demonstrate compliance with NIST SP 800-171 is unlikely to disappear.
Organizations that continue preparing will be better positioned for future CMMC requirements, DIBCAC assessments, prime contractor requests, and new contract opportunities.
A Pause Is Not a Safe Harbor
The CMMC reform process may eventually reduce costs, change assessment requirements, or create a more scalable compliance model for small and midsized contractors. Until the government publishes those changes, however, contractors should avoid making decisions based on speculation.
The key facts remain:
- Phase II is suspended, but CMMC Level 2 has not been eliminated.
- Phase I self-assessment requirements remain in effect.
- DFARS and NIST SP 800-171 obligations continue.
- Prime contractors can continue requiring cybersecurity evidence or certification.
- DIBCAC can select contractors for nonvoluntary government-led assessments.
- A high SPRS score must be supported by documentation and operational evidence.
- Contractors may have very little time to prepare after receiving an assessment notice.
The organizations in the strongest position will be those that use the pause to validate their claims, correct weaknesses, organize evidence, and prepare for scrutiny.
SME, Inc. helps defense contractors evaluate their current cybersecurity posture, prepare accurate SPRS assessments, address NIST SP 800-171 requirements, and build the documentation and evidence needed for CMMC and DIBCAC readiness.
Do not wait for an assessment notice or a prime contractor deadline. Contact SME, Inc. to determine where your organization stands and what steps you should take next.



