CMMC Phase II Paused, but Data Security Obligations Persist

On July 13, 2026, the Department of Defense (DoD) announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program, which was set to require third-party assessments for defense contractors starting November 10, 2026. This decision has led to questions within the Defense Industrial Base (DIB) regarding compliance timelines and security investments.

Despite the pause in the certification process, the fundamental security requirements that necessitated the creation of CMMC remain unchanged. The DoD continues to rely on contractors to safeguard Controlled Unclassified Information (CUI). Adversaries persist in targeting defense contractors, supply chains, and critical technology providers, making the protection of sensitive data as crucial as ever.

Understanding the Implications of the Suspension

It’s essential to recognize that CMMC is built upon existing frameworks, notably the National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171), which outlines security requirements for protecting CUI in non-federal systems. Many defense contractors are contractually obligated under the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012 to adhere to these security requirements, including incident reporting obligations and broader federal cybersecurity expectations. These obligations remain in effect regardless of changes to CMMC implementation timelines.

Therefore, interpreting the pause in certification activities as a suspension of security responsibilities is a misconception. Organizations that delay cybersecurity enhancements based solely on certification timing may find themselves at a disadvantage when assessments resume and may face increased operational and contractual risks during the interim.

The Risk of Viewing Compliance as a One-Time Event

A common pitfall for organizations is treating compliance as a project with a fixed timeline rather than an ongoing capability. This approach often leads to resource allocation that aligns with external deadlines, with resources being reallocated elsewhere when timelines shift. However, adversaries do not operate on compliance schedules. The sensitive data that will eventually be assessed under CMMC remains valuable to nation-state actors and cybercriminal organizations today. Delaying readiness efforts can inadvertently create gaps in critical areas such as access controls, privileged account management, multifactor authentication, data protection, audit logging, asset visibility, security documentation, and evidence collection. These are not merely audit concerns but foundational security capabilities.

Many organizations struggle not with understanding the importance of security but with identifying where sensitive information resides and how it moves within their systems. Common readiness gaps include broad access management, insufficient privileged account controls, and inadequate data protection measures. Addressing these issues requires a proactive approach to cybersecurity that goes beyond compliance checkboxes.

In light of the CMMC Phase II suspension, defense contractors should view this period as an opportunity to strengthen their cybersecurity posture. By focusing on the continuous improvement of security practices and ensuring compliance with existing obligations under NIST SP 800-171 and DFARS 252.204-7012, organizations can better protect sensitive information and position themselves favorably for future assessments. This proactive stance not only mitigates current risks but also prepares contractors for any forthcoming changes in the CMMC program.