# U.S. DoD suspends CMMC Phase II

> Live situation record from CLSTR: https://clstr.news/situations/us-dod-suspends-cmmc-phase-ii
> Updated: 2026-08-04T09:37:21.000Z. Sources: 25. Developments: 4.

On 13 July 2026 the Department of Defense announced an immediate suspension of the CMMC Phase II third‑party assessment requirement for Level 2 contracts. The pause removes the Certified Third‑Party Assessor Organization (C3PAO) audit while leaving Phase I self‑assessment, DFARS 252.204‑7012, NIST SP 800‑171 Rev 2 controls, 72‑hour incident reporting, annual SPRS updates and false‑claim liability in force. Program managers were directed to amend or delete the suspended clauses from active solicitations.

A clarification on 28 July reiterated that only the external‑auditor step is on hold and confirmed a 60‑day review task force aimed at aligning CMMC with the DoD’s acquisition transformation goals. The same week, analysts noted that managed service providers must continue remediation work, validate SPRS submissions and preserve audit evidence, and that regulatory uncertainty is spurring interest in AI‑driven compliance tools.

DoD officials, including CIO Kirsten Davies and Undersecretary Michael Duffey, highlighted the high compliance cost—estimated at $7 billion annually for roughly 100,000 firms—and pledged a mid‑September task‑force review that could reshape the third‑party model. Security advisers warned contractors and MSPs not to pause their NIST 800‑171 programs, noting that inaccurate self‑assessments can still trigger False Claims Act penalties of $14,308‑$28,619 per claim plus treble damages.

## Timeline

### 2026-08-04: U.S. Department of Defense Suspends CMMC Phase 2, Contractors Urged to Keep Security Programs

The U.S. DoD suspended CMMC Phase 2 third‑party assessments on July 13 2026, but all NIST 800‑171 and DFARS security obligations stay in force; contractors are urged to keep building compliance programs amid a

3 sources. https://clstr.news/cluster/us-department-of-defense-suspends-cmmc-phase-2-contractors-urged-to-keep-security-programs

### 2026-07-31: DoD pauses CMMC Phase II, security obligations for contractors remain

The Department of Defense has suspended CMMC Phase II certification, but contractors must still meet NIST SP 800‑171, DFARS, SPRS reporting and protect CUI, keeping compliance burdens unchanged.

4 sources. https://clstr.news/cluster/dod-pauses-cmmc-phase-ii-security-obligations-for-contractors-remain

### 2026-07-28: U.S. Department of Defense pauses CMMC Phase II third‑party assessments

The U.S. Defense Department halted the CMMC Phase II third‑party audit requirement for Level 2 contracts on July 13, 2026, keeping all other cybersecurity obligations unchanged while reviewing the program’scost

6 sources. https://clstr.news/cluster/us-department-of-defense-pauses-cmmc-phase-ii-thirdparty-assessments

### 2026-07-13: Pentagon suspends CMMC Phase II requirements for defense contractors

The Pentagon halted the CMMC Phase II rollout, citing heavy compliance costs and assessor shortages, while keeping Phase I requirements and ordering contract revisions.

13 sources. https://clstr.news/cluster/pentagon-halts-phase-2-of-defense-cybersecurity-certification

---
Cite as: U.S. DoD suspends CMMC Phase II. CLSTR, https://clstr.news/situations/us-dod-suspends-cmmc-phase-ii
