< Back to all clusters
[BUSINESS] · United States · 3 sources

U.S. Department of Defense Suspends CMMC Phase 2, Contractors Urged to Keep Security Programs

On July 13, 2026 the U.S. Department of Defense (DoD) suspended the Cybersecurity Maturity Model Certification (CMMC) Phase 2 third‑party assessment requirement. The pause removes the Certified Third‑Party Assessor Organization (C3PAO) audit for Level 2 contracts, but all other obligations remain unchanged. Contractors must still comply with DFARS 252.204‑7012, implement NIST SP 800‑171 Rev 2 controls, submit self‑assessment scores, and meet the 72‑hour cyber‑incident reporting rule.

DoD CIO Kirsten Davies noted the suspension reflects the high compliance cost—estimated at $7 billion annually—for roughly 100,000 firms in the defense industrial base. A task‑force review is slated for mid‑September and could reshape the third‑party model.

Cyber‑security advisers at Echelon Risk + Cyber warned defense contractors and managed service providers (MSPs) not to pause their security work. They urged continued development of NIST 800‑171 programs, keeping System Security Plans current, and redirecting budget from pending C3PAO assessments to remediation. Failure to maintain accurate self‑assessments can still trigger False Claims Act liability, with civil penalties of $14,308‑$28,619 per false claim plus treble damages.

Entities: Defense contractors · Echelon Risk + Cyber · Kirsten Davies · Managed service providers · U.S. Department of Defense