U.S. Department of Defense pauses CMMC Phase II third‑party assessments
On July 13, 2026 the U.S. Department of Defense (DoD) suspended the Phase II requirement of the Cybersecurity Maturity Model Certification (CMMC) that mandates third‑party assessments for Level 2 contracts. The pause applies only to the external auditor step; all other CMMC obligations, including self‑assessment, DFARS 252.204‑7012 compliance with NIST SP 800‑171, and incident‑reporting within 72 hours, remain in force. The DoD cited the high cost and bottlenecks faced by more than 100,000 small and medium‑size defense contractors, with certification expenses approaching $600,000 per firm. A 60‑day review task force will evaluate the program to align it with the Secretary’s acquisition transformation strategy. Contractors must continue to post and maintain their SPRS scores and remain liable for any false‑claim representations, even though the third‑party verification mechanism is temporarily halted.
Entities: Cybersecurity Maturity Model Certification (CMMC) · U.S. Department of Defense