Facade of US Government Cybersecurity Center at night.

On July 13, 2026, the Department of Defense (DoD) issued a series of memoranda that introduced a significant pivot for the Cybersecurity Maturity Model Certification (CMMC) program. In an unexpected move, the Department announced an immediate suspension of CMMC Phase II requirements. This action effectively halts the mandatory transition to third-party assessments for Level 2 certification that was originally scheduled to begin on November 10, 2026.

While this announcement has caused a ripple effect across the Defense Industrial Base (DIB), it is essential to distinguish between what has been paused and what remains mandatory. This article provides a factual breakdown of the current landscape, the objectives of the newly formed CMMC Reform Task Force, and the immediate obligations that defense contractors must continue to meet.

What is the CMMC Phase II Suspension?

The suspension announced on July 13 focuses specifically on the “Phase II” rollout of the CMMC program. Under the previous timeline, November 10, 2026, was set as the critical threshold where CMMC Level 2 certification: verified by a Certified Third-Party Assessment Organization (C3PAO): would begin appearing as a requirement in select solicitations.

Key Facts of the Suspension:

  • Immediate Abeyance: All pending and future CMMC implementation milestones related to Phase II are held “until further notice.”
  • Delay of the November 10 Deadline: The requirement for C3PAO assessments for Level 2 is no longer expected to be enforced this coming November.
  • Third-Party Audits Paused: For organizations currently in the queue for a C3PAO assessment to satisfy Phase II requirements, the regulatory pressure to achieve that certification by the end of the year has been lifted.

This decision does not represent a repeal of the CMMC framework but rather a strategic pause to evaluate the program’s impact on acquisition speed and industry accessibility.

A tablet device depicting an enterprise security architecture on the screen

The 60-Day CMMC Reform Task Force

Concurrent with the suspension, DoD Chief Information Officer (CIO) Kirsten A. Davies announced the formation of a CMMC Reform Task Force. This body is charged with a comprehensive, “top-to-bottom” 60-day review of the program’s current structure.

The Task Force is operating under directives from the Secretary of War/DoD acquisition transformation office. The review’s primary objectives are centered on three pillars:

  1. Speed to Capability: Ensuring that cybersecurity compliance does not inadvertently slow down the procurement of mission-critical technologies.
  2. Lowering Barriers: Identifying and removing obstacles that prevent small, medium, and non-traditional businesses from participating in the defense supply chain due to high compliance costs.
  3. Scalable Resilience: Replacing prescriptive, bureaucratic compliance hurdles with more agile and resilient cybersecurity measures that provide tangible security outcomes.

At the conclusion of this 60-day window, the Task Force will deliver formal implementation recommendations to the Department CIO. These recommendations will likely define the “reformed” version of CMMC that will move forward in late 2026 or 2027.

Industry Input: The August 14 RFI

To inform the Task Force’s review, the DoD has issued a Request for Information (RFI) seeking direct feedback from the industry. The deadline for submission is August 14, 2026.

The Department is specifically looking for data on:

  • The actual costs and administrative burdens associated with achieving CMMC compliance.
  • The readiness of the DIB to meet technical security requirements.
  • The effectiveness of specific security controls in preventing real-world cyber threats.
  • The availability and utility of commercial cybersecurity solutions to meet government standards.

This RFI provides a critical window for defense contractors to voice concerns and provide evidence-based suggestions for program improvement. Organizations that have already invested heavily in CMMC preparation are being encouraged to share their experiences to ensure that future reforms are grounded in practical reality.

What Has NOT Changed: The Compliance Baseline

One of the most critical takeaways from the July 13 announcement is the emphasis on what remains in full force. The DoD was explicit: the suspension of Phase II third-party assessments is not a suspension of cybersecurity obligations.

Phase I Self-Assessments Still Apply

CMMC Phase I, which involves self-assessments for Level 1 and certain Level 2 requirements, remains mandatory. Contractors are still required to perform these self-assessments and report their findings via the Supplier Performance Risk System (SPRS).

NIST SP 800-171 Rev. 2 and DFARS 252.204-7012

external hardware with indicator lights show various statusesThe fundamental requirement to protect Controlled Unclassified Information (CUI) has not changed. The baseline cybersecurity obligations mandated by DFARS 252.204-7012 remain the law of the land. This includes:

  • The full implementation of all 110 controls found in NIST SP 800-171 Rev. 2.
  • The requirement to have a System Security Plan (SSP) and a Plan of Action and Milestones (POA&M) for any unimplemented controls.
  • Incident reporting requirements for cyber-related events affecting CUI.

In short, the technical standard (NIST 800-171) is active; only the mechanism of third-party verification (C3PAO audits) for Phase II has been paused. Contractors are still legally liable for the accuracy of their self-attestations and the protection of government data.

To Wait or To Drive Forward?

We are currently seeing a split in how the Defense Industrial Base is reacting to this news.

The Case for Delaying:

Some companies have chosen to pause their scheduled C3PAO assessments immediately. The rationale is often financial: avoiding the high cost of a third-party audit until the Task Force confirms the final “look and feel” of the reformed program. For organizations with tight margins, this provides temporary budgetary relief.

The Case for Driving Forward:

Other organizations are maintaining their momentum. These companies view the suspension as a temporary administrative delay rather than a change in technical requirements. By continuing with their assessment schedules, they aim to:

  • Validate their security posture against the current 800-171 standard.
  • Maintain a competitive advantage if the 60-day review results in a quick resumption of Phase II.
  • Ensure they are meeting the expectations of prime contractors who may still require third-party validation as part of their own risk management protocols.

Furthermore, government-led assessments, such as those conducted by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC), are preserved and may still be used to validate contractor compliance during this interim period.

Lunarline’s Commitment to Government Security

In this period of regulatory transition, stability and commitment are paramount. Lunarline, a wholly owned subsidiary of Motorola and a C3PAO listed on the Cyber AB, remains steadfast in its mission.

As a C3PAO and an organization deeply embedded in the defense ecosystem, Lunarline is committed to securing our government’s Controlled Unclassified Information (CUI). This commitment is dual-faceted: it applies to our own internal organizational security as well as our role as an authorized assessment body. Regardless of the administrative changes to the CMMC rollout, our focus remains on the tangible protection of federal data and the resilience of the supply chain.

Conclusion: Next Steps for Contractors

The 60-day review period marks a pivotal moment for the future of defense acquisitions. While the suspension of Phase II provides immediate relief from audit deadlines, the underlying technical requirements of NIST 800-171 and DFARS 252.204-7012 remain the governing standard.

Contractors should take the following actions:

Submit RFI Responses: Ensure your voice is heard by the Task Force before the August 14 deadline.

  1. Maintain Phase I Compliance: Continue performing and reporting self-assessments accurately.
  2. Implement NIST 800-171: Focus on technical security implementation rather than administrative certification.
  3. Monitor the Task Force: Stay tuned for the implementation recommendations expected in mid-September 2026.

For those seeking more information on how to navigate these changes or to manage their current cybersecurity posture, please contact us.