DoW Suspends CMMC Phase II for 60 Days: What It Really Means for OSCs

The Department of War has announced the immediate suspension of CMMC Phase II requirements and launched a 60-day review of the program. For many organizations seeking certification, the announcement created a wave of confusion, speculation, and more than a few celebratory LinkedIn posts. Because apparently no defense industry news cycle is complete without a collective overreaction.
So what does this announcement actually mean for Organizations Seeking Certification (OSCs)? Let’s separate fact from fiction.
FAQ: The DoW Suspends CMMC Phase II
What exactly did the DoW announce?
The DoW announced that it is suspending the transition to CMMC Phase II requirements, which were scheduled to take effect on November 10, 2026. The department is also conducting a comprehensive 60-day review of the entire program through a newly established CMMC Reform Task Force.
The stated goal is to reduce compliance burdens on small and medium-sized defense contractors while maintaining strong cybersecurity protections.
Does this mean CMMC is dead?
Short answer is a resounding NO. CMMC is alive and well.
Despite some headlines and social media commentary, the DoW has not canceled CMMC. It has suspended Phase II implementation while it reviews the program and evaluates potential reforms. The department has repeatedly stated that cybersecurity remains a critical requirement for the Defense Industrial Base (DIB).
The review could result in modifications to CMMC, changes to assessment requirements, or adjustments to implementation timelines. However, changes to the core of the rule would have to be adjusted the rule making process. There has been no indication that the government intends to eliminate the CMMC program.
What requirements remain in effect today?
This is the most important question.
Several key requirements remain unchanged:
- DFARS 252.204-7012 still applies.
- Contractors must still protect Controlled Unclassified Information (CUI).
- NIST SP 800-171 requirements remain in place.
- Phase I self-assessment requirements remain active.
- The DoW may continue conducting government-led assessments where applicable.
- Prime contracting officers are still allowed to require subcontractors to meet CMMC requirements.
In other words, the cybersecurity obligations themselves have not disappeared.
Are C3PAO certifications still required?
Maybe.
The suspension specifically impacts the planned rollout of Phase II specifically addressing DoW contracts, Which would have required many contractors to obtain third-party certifications through Certified Third-Party Assessment Organizations (C3PAOs). Those requirements have been paused pending the outcome of the review.
However, contract officers can still put the requirement for their subcontractors. Organizations that have already invested in preparation should not assume those assessments will never return.
Should OSCs stop their CMMC preparation efforts?
For organizations that handle CUI, the answer is no.
If your organization handles CUI, your contractual obligations to protect that information remain intact. The controls required by NIST 800-171 still represent the baseline security expectations for defense contractors.
The companies that continue improving security, documenting processes, implementing MFA, strengthening endpoint protection, and validating backups will be in a much stronger position regardless of what the final version of CMMC looks like.
Cybersecurity maturity is still valuable even if compliance requirements evolve.
What is the DoW concerned about?
According to the announcement, the department believes the current CMMC implementation created excessive costs and administrative burdens, particularly for small and non-traditional defense contractors. Officials expressed concern that some companies were leaving the Defense Industrial Base due to compliance costs and complexity.
The review will focus on finding ways of meeting the requirements of DFARS 7012 clause while reducing unnecessary bureaucracy.
Could the requirements become easier?
Possibly.
The 60-day review may result in:
- Streamlined assessment processes
- Alternative validation methods
- Greater reliance on self-assessments
- Modified certification timelines
At this stage, however, these are possibilities rather than confirmed outcomes. The DoW has not yet released recommendations from the review process.
What should OSCs do during the 60-day review period?
Rather than hitting the pause button, organizations should focus on the fundamentals:
- Continue NIST 800-171 implementation efforts.
- Address known security gaps.
- Maintain accurate SSPs and POA&Ms.
- Strengthen identity and access management.
- Validate backup and recovery processes (not required but highly recommended)
- Improve endpoint detection and response capabilities
- Continue security awareness training
These investments improve security regardless of the eventual CMMC outcome.
What is the biggest mistake contractors could make right now?
Assuming cybersecurity no longer matters.
The suspension affects certification requirements, not the obligation to protect federal information. Organizations that stop investing in cybersecurity may find themselves scrambling if a revised CMMC program returns with new deadlines or requirements. Worse, they remain vulnerable to cyberattacks in the meantime.
How Summit Can Help
While the future of CMMC is being reviewed, one thing remains clear: defense contractors must continue protecting sensitive data and demonstrating sound cybersecurity practices.
Summit Business Technologies helps organizations build practical security programs that support both compliance and operational resilience. Through our vCSO program we help, organizations prepare for CMMC level 2 certification. Providing policy writing and recommendations on the right tools to help you meet the compliance requirements of NIST 800-171. In addition our expert team works with you as the CMMC program and your organization evolves, helping ensure you maintain said compliance.
Whether CMMC ultimately returns in its current form or evolves into something new, organizations that invest in strong cybersecurity today will be better positioned for whatever comes next.



