Quality, Expert-Derived Cybersecurity Documentation To Keep Organizations Secure, Compliant & Resilient - No AI Slop!
ComplianceForge

Department of War Suspends CMMC Phase II: What the Self-Assessment Pivot Means for Your Contracts

CMMC
ComplianceForge Support
July 15, 2026
Department of War Suspends CMMC Phase II: What the Self-Assessment Pivot Means for Your Contracts

Editorial note: This article summarizes the Department of War announcement dated July 13, 2026 and is informational, not legal or compliance advice. CMMC policy is moving quickly right now, and the announcement launched a 60 day review that could change requirements again. Confirm the current contractual requirements in your specific solicitations and contracts with a qualified attorney or CMMC and DFARS advisor before making decisions.

The short version is this. On July 13, 2026, the Department of War announced the immediate suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements that were scheduled to take effect on November 10, 2026. During the interim period the Department will enforce cybersecurity compliance against the NIST SP 800-171 Rev 2 standard through self-assessments and select government led assessments. This is a meaningful change in how compliance is verified, but it is not a break from the requirement to protect Controlled Unclassified Information (CUI). DFARS clause 252.204-7012 still applies, and Phase I self-assessment requirements remain in place.

If your near term worry was standing in line for a CMMC Third-Party Assessment Organization (C3PAO) certification, that pressure has eased for now. The work of actually being compliant with NIST 800-171 has not.

Key Takeaways

• CMMC Phase II requirements are suspended effective immediately, and the November 10, 2026 transition to Phase II is on hold.

• Phase I self-assessment requirements remain in place, so self-attestation of NIST 800-171 compliance is still expected.

• During the interim, the Department will use NIST SP 800-171 Rev 2 self-assessments and select government led assessments rather than requiring C3PAO certifications.

• The Department opened a 60 day study through a new CMMC Reform Task Force, so the model could change again.

• DFARS 252.204-7012 and the obligation to safeguard covered defense information are unchanged.

• The internal self-assessment is now the near term path, which raises the value of accurate, assessment ready documentation.

What the Department of War Actually Announced

The announcement suspends the transition to Phase II of CMMC along with pending and future CMMC implementation milestones across Department of War solicitations and contracts. The stated reason is cost and burden. The Department pointed to feedback, including data cited from the Small Business Administration, that CMMC compliance costs were pushing innovative companies out of the Defense Industrial Base (DIB).

To review the program, the Department created a CMMC Reform Task Force to run a top to bottom review and to gather industry feedback through a public Request for Information (RFI). The task force is expected to deliver its report to the Department of War Chief Information Officer within 60 days. That timeline tells you something important. This is a review, not a repeal, and the outcome is not yet written.

What Did Not Change

It is easy to read a headline about suspended requirements and assume the whole obligation went away. It did not. Three things are worth stating plainly.

First, DFARS 252.204-7012 still requires contractors and subcontractors to safeguard covered defense information and to report cyber incidents. That clause lives in existing contracts regardless of the CMMC timeline.

Second, NIST 800-171 is still the standard. The interim guidance points specifically to NIST SP 800-171 Rev 2, assessed through self-assessment and select government led assessments. Contractors are still expected to implement the controls and to be able to show it.

Third, government led assessments did not disappear. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) has conducted government assessments of contractor NIST 800-171 implementation for years, and "select government led assessments" means a subset of contractors can still expect a review that is more rigorous than a self-attestation.

Why the Self-Assessment Now Matters More, Not Less

There is a common misread of a moment like this, which is to treat a paused certification requirement as a reason to slow down. The opposite is true for most contractors.

A self-assessment is a claim you are making to the government about your own compliance. When a C3PAO is in the loop, a third party stands between your claim and your contract. When you self-assess, you are the assessor of record, and your NIST 800-171 self-assessment score, your System Security Plan (SSP), and your Plan of Action and Milestones (POA&M) are the artifacts that carry the weight. If a government led assessment or a False Claims Act inquiry ever looks back at your self-attestation, the quality of that documentation is what protects you.

In other words, the bar for being able to prove compliance did not drop. The party responsible for proving it just shifted back to you.

How the NIST 800-171 Compliance Program (NCP) Helps

This is where getting your documentation right stops being abstract. The NIST 800-171 Compliance Program (NCP) from ComplianceForge is built for exactly this situation, where you own the self-assessment and you need documentation that would survive a harder look.

The NCP is an editable set of Microsoft Word, Excel and PowerPoint templates that includes policies, standards, procedures, an SSP, a POA&M, third party risk management and supply chain risk management content, and supporting templates aligned to NIST 800-171 and CMMC 2.0. It is what ComplianceForge calls DIBCAC battle tested, meaning clients have used this documentation to pass DIBCAC and C3PAO assessments. It is designed to get an organization roughly 80 to 90 percent of the way to a complete documentation set, where the remaining work is the tailoring only you can do, such as naming your systems, assigning your people, and describing your environment.

The NCP also ships in three versions in a single purchase: a Rev 2 only version, a Rev 3 only version, and a combined Rev 2 and Rev 3 version. That matters during a period when the interim guidance names NIST 800-171 Rev 2 but the underlying standard has already moved to NIST 800-171 Rev 3. You are not betting on one revision and hoping the policy lands your way.

What To Do This Quarter

Treat the pause as time you were given back, not time off. A practical sequence looks like this. Confirm the CUI and covered defense information in your environment and your DFARS 252.204-7012 obligations. Run or refresh your NIST 800-171 Rev 2 self-assessment and record an honest score. Build or update your SSP and POA&M so they reflect reality. Then watch for the CMMC Reform Task Force output, because the 60 day study will shape what comes next.

If you want a running start on the documentation, start with the NCP so your self-assessment rests on policies, standards, procedures and plans that were written to hold up under assessment.

Frequently Asked Questions

Did the Department of War cancel CMMC? No. It suspended the Phase II requirements and opened a 60 day review. Phase I self-assessment requirements remain, and the standard being enforced in the interim is NIST SP 800-171 Rev 2.

Do I still need a C3PAO assessment? For the interim period described in the announcement, compliance is verified through self-assessment and select government led assessments rather than a required C3PAO certification. This could change based on the task force review, so verify your specific contract requirements.

Is DFARS 252.204-7012 still in effect? Yes. The announcement is explicit that contractors and subcontractors remain obligated to safeguard covered defense information under DFARS 252.204-7012.

Which NIST 800-171 version should I use? The interim guidance names NIST 800-171 Rev 2. The broader standard has moved to NIST 800-171 Rev 3, so many contractors are preparing for both. Our related article on Rev 2 versus Rev 3 covers how to decide.

Sources: Department of War release, "Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements," July 13, 2026, at war.gov. Product details are from the ComplianceForge NIST 800-171 Compliance Program (NCP) product page. Verify current CMMC and DFARS requirements directly, since the 60 day review may change them.