The Department of Defense has suspended Cybersecurity Maturity Model Certification (CMMC) Phase II requirements that were scheduled to take effect November 10, 2026, while a reform task force reviews the program, according to an August 31, 2026 report from Security Info Watch. Phase I self-assessments and current NIST SP 800-171 Revision 2 obligations remain in effect for defense contractors.
What’s Paused, What Isn’t
Level 1 self-assessments covering 15 safeguarding requirements from FAR clause 52.204-21 continue on their annual cycle, and Level 2 self-assessments against the 110 security requirements in NIST SP 800-171 Rev. 2 continue every three years with annual affirmation, with results still required in the Supplier Performance Risk System (SPRS). For contracts under DFARS clause 252.204-7012, contracting officers must still verify a current SPRS assessment score before certain awards, extensions or option exercises. Only the timing of third-party CMMC Phase II assessments has changed, not the underlying obligation to safeguard Controlled Unclassified Information, Bill Osborne, vice president of Defense Sector Services at Magna5, told the publication.
Why It Matters
The pause gives contractors more time to fix gaps in scope, documentation and System Security Plans before a Third-Party Assessment Organization is engaged, rather than a reason to slow readiness work altogether. Compliance requirements of this kind sit alongside physical protections for critical infrastructure and defense-linked targets that state-linked threat actors continue to probe.




