×
Monday, August 31, 2026

Department of Defense Suspends CMMC Phase II: What You Need To Know Now - JD Supra

Key Takeaways:

  • Phase II relief is limited. Contractors may no longer face an immediate Level 2 certification requirement, but their existing cybersecurity obligations remain in force.
  • Self-assessments now matter even more. Contractors handling CUI must continue implementing NIST SP 800-171 controls, maintaining accurate documentation, submitting supportable assessments and making defensible compliance affirmations.
  • Enforcement risk is shifting, not disappearing. With DoD relying more heavily on contractor self-representations, inaccurate compliance statements may create post-award False Claims Act and cyber-fraud enforcement exposure.

The Department of Defense (DoD) has announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program and has launched a comprehensive review of the certification framework. Importantly, this is not a suspension of the requirements for protecting Controlled Unclassified Information (CUI) under DFARS 252.204-7012.

Under the announcement, DoD will continue to enforce Phase I requirements, including self-assessments and annual affirmations of compliance, while evaluating whether and how the broader CMMC program should continue. For defense contractors, the suspension alleviates the near-term burden of obtaining third-party CMMC certifications but leaves in place the existing obligation to self-assess and report compliance. False statements in these reports will continue to expose contractors to...



Read Full Story: https://news.google.com/rss/articles/CBMihAFBVV95cUxNVmwyR0FQRHJldnhPTnBpZXNP...