Select Page

DoW Suspends CMMC Phase 2 Requirements

DoW Suspends CMMC

 
On July 13, 2026, the Department of War (DoW) announced a 60-day suspension of the Cybersecurity Maturity Model Certification (CMMC) phase 2 requirements, effective immediately. This directly impacts all businesses that are part of the Defense Industrial Base (DIB) and are seeking certification to CMMC, are in the process of CMMC compliance, or have achieved CMMC compliance. 

The core of the DoD statement is that the third-party certification requirement for CMMC Level 2 is waived during this 60-day interim period, and any future milestones are on hold for at least 60 days (CMMC Phase II requirements were originally scheduled to take effect on November 10, 2026). During the 60-day period, companies are still required to comply with NIST 800-171 standards through self-assessment.

While we don’t know what the future holds for the CMMC program, we can move forward with the understanding that all defense contractors and subcontractors are still required to comply with NIST SP 800-171 Rev 2 standard through self-assessments. 

“We’re not relaxing any standards by any means. We expect businesses to adhere to the standards that NIST has outlined. What we’re removing is the bureaucracy of the third-party assessment,” Michael Duffey, Undersecretary of Defense for Acquisition and Sustainment, told reporters.

Industry Extension Services will continue to monitor federal government updates and share information as we learn more. If you have any questions about CMMC, please contact the IES Regional Manager in your area for assistance.