Breaking News: Department of War Suspends CMMC Phase II, Launches Reform Review (2026)

The recent suspension of the Department of War's (DoW) CMMC Phase II requirements has sparked a wave of discussions and interpretations. This move, announced by the DoW, aims to address concerns over compliance costs and bureaucratic complexities.

Understanding CMMC and its Phases

CMMC, or Cybersecurity Maturity Model Certification, is an initiative designed to ensure that the Defense Industrial Base adheres to cybersecurity controls, safeguarding Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). The program was planned as a four-phase rollout, with Phase I already in effect since November 2025, focusing on contractor self-assessments.

The Suspension and Its Implications

The suspension of Phase II, originally scheduled for November 2026, is a significant development. The DoW cites the high costs and bureaucratic challenges associated with the implementation as the primary reasons for this decision. This move aligns with Secretary Hegseth's efforts to streamline the acquisition process, indicating a shift towards a more efficient and cost-effective approach.

During this suspension period, the DoW will continue to enforce cybersecurity compliance using the NIST SP 800-171 Rev 2 standard, relying on self-assessments and select government-led assessments.

Unchanged Obligations and Contractor Responsibilities

Despite the suspension, defense contractors and subcontractors remain contractually bound to protect covered defense information under DFARS 252.204-7012. The DoW emphasizes that CMMC Phase I self-assessment requirements are still in place, including Level 1 and Level 2 certifications and attestations.

Contractors should be aware that while Phase II is on hold, their existing compliance obligations remain active. This includes implementing NIST SP 800-171 to safeguard DoW CUI and being prepared for government scrutiny. The Department of Justice's Civil Cyber-Fraud Initiative also remains active, investigating noncompliance with DFARS regulations, and could potentially expand its focus to CMMC self-assessments.

A Step Towards Reform

The DoW's Chief Information Officer has established a CMMC Reform Task Force to conduct a comprehensive review of the certification program. This task force will gather industry feedback and deliver a report within 60 days, potentially leading to significant reforms.

This review period offers an opportunity for defense contractors to provide valuable insights and feedback, shaping the future of CMMC requirements. It is a critical time for the industry to engage with the DoW and influence the direction of cybersecurity compliance.

Conclusion

The suspension of CMMC Phase II is a bold move by the DoW, reflecting a commitment to address industry concerns. While the future of CMMC remains uncertain, the DoW's proactive approach to reform and its continued focus on cybersecurity compliance are encouraging signs. This development highlights the complex interplay between national security, industry practices, and the evolving landscape of cybersecurity. It is a fascinating example of how policy and practice can adapt to meet the challenges of our digital age.

Breaking News: Department of War Suspends CMMC Phase II, Launches Reform Review (2026)

References

Top Articles
Latest Posts
Recommended Articles
Article information

Author: Eusebia Nader

Last Updated:

Views: 5934

Rating: 5 / 5 (60 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Eusebia Nader

Birthday: 1994-11-11

Address: Apt. 721 977 Ebert Meadows, Jereville, GA 73618-6603

Phone: +2316203969400

Job: International Farming Consultant

Hobby: Reading, Photography, Shooting, Singing, Magic, Kayaking, Mushroom hunting

Introduction: My name is Eusebia Nader, I am a encouraging, brainy, lively, nice, famous, healthy, clever person who loves writing and wants to share my knowledge and understanding with you.