The Department of Defense suspended CMMC Phase II enforcement, but that doesn't mean defense contractors can ignore cybersecurity — compliance expectations haven't disappeared, and the risks remain real.
On July 13, 2026, the Department of Defense announced that it had suspended the implementation of CMMC Phase II, which had been scheduled to take effect November 10, 2026. A reform task force was established to review the program. The review is intended to reduce unnecessary complexity, lower barriers for small and midsize businesses, and develop more scalable cybersecurity measures. If you're trying to understand who CMMC applies to and what to do first, that foundation remains unchanged despite the suspension.
Many defense contractors have heard 'CMMC Phase II suspended' and assumed the program is cancelled or that compliance work can stop. That belief is outdated — and expensive.
The certification timeline changed. The responsibility to protect defense information did not. CMMC has not been cancelled. Implementation remains paused in Phase I, and Phase I self-assessment requirements remain in place. The Department plans to continue enforcing NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments.
Existing obligations to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) have not disappeared. Applicable requirements under FAR 52.204-21 and DFARS 252.204-7012 remain important. The suspension is a programmatic delay, not permission to abandon cybersecurity or compliance work.
Defense contractors handling FCI or CUI remain subject to existing Federal Acquisition Regulation and Defense Federal Acquisition Regulation Supplement clauses. FAR 52.204-21 establishes baseline requirements for protecting FCI. DFARS 252.204-7012 requires contractors handling CUI to implement the security controls in NIST SP 800-171 Revision 2 and to report their compliance status through self-assessments. For a deeper look at how IT providers support the full CMMC and compliance journey, including how these regulatory clauses translate into operational requirements, that resource covers the lifecycle from scoping through ongoing maintenance.
These requirements predate CMMC and remain enforceable regardless of the Phase II suspension. Contractors who handle FCI must implement basic safeguarding measures. Contractors who handle CUI must implement the 110 security controls outlined in NIST SP 800-171 Revision 2, document their implementation, and assess their own compliance annually.
For contractors pursuing Level 1 certification, requirements generally apply to organizations handling FCI. This includes basic safeguarding practices such as access control, awareness training, system identification, and media protection. Self-assessments documenting these practices remain a contractual obligation.
For contractors pursuing Level 2 certification, requirements generally apply to organizations handling CUI. This includes the full scope of NIST SP 800-171 controls across 14 security domains: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.
The pause does not change these obligations. It delays the transition from self-assessment to third-party certification. That distinction matters.
Most small and midsize defense contractors we speak with believe they are compliant because they have not received a deficiency notice. That assumption is risky. Self-assessments are attestations. Contractors who submit inaccurate assessments or who overstate their compliance posture face contractual, regulatory, and legal risk.
The 110 controls in NIST SP 800-171 are specific and measurable. They include requirements such as implementing multi-factor authentication for all users, encrypting CUI at rest and in transit, logging and reviewing security events, restricting administrative privileges, conducting vulnerability scans, maintaining system inventories, and training personnel on insider threat indicators.
Organizations cannot protect assets they have not identified. They cannot prioritize risks they have not measured. Most SMBs don't find out they have a security gap until after a breach. Not because the gap was hidden. Because no one was looking. Understanding how to build a comprehensive risk management framework is the first step toward changing that.
A mature cybersecurity strategy begins with visibility. That includes understanding which devices are on your network, which systems process CUI, where configuration weaknesses exist, how access is controlled, whether patches are applied consistently, and how incidents are detected and reported. Without this visibility, self-assessments are guesswork. Tools and frameworks focused on exposure management and risk-based vulnerability prioritization can help SMBs move from reactive guesswork to structured, measurable security programs.
Even with the suspension of CMMC Phase II, defense contractors face enforcement pressure from other sources. Cyber insurance carriers have tightened underwriting requirements significantly. Policies now require documented evidence of multi-factor authentication, endpoint detection and response, email filtering, offsite backups, incident response plans, and regular security training. Carriers are denying claims when they determine that policyholders misrepresented their security posture during the application process. For a detailed breakdown of what cyber insurance underwriters actually require in 2026, including how to avoid claim denials, that resource covers the full scope of current carrier expectations.
Prime contractors are also raising the bar. Many are requiring subcontractors to demonstrate NIST SP 800-171 compliance before awarding contracts or renewing relationships. Some are conducting their own assessments or requiring third-party validation. Others are incorporating cybersecurity requirements into supplier agreements and master service agreements.
The Department of Defense Inspector General continues to conduct audits of contractor compliance with DFARS 252.204-7012. Contractors found to be noncompliant face corrective action plans, contract modifications, or suspension of payments. In some cases, repeated or willful noncompliance has resulted in debarment.
The suspension of Phase II does not reduce any of these pressures. If anything, it increases the importance of proactive compliance. Contractors who wait for formal CMMC certification requirements to resume will find themselves unprepared when prime contractors, insurers, or auditors ask for evidence of their security program. Understanding which MSPs actually help businesses qualify and renew cyber insurance — and how they maintain continuous evidence of controls — is directly relevant to staying prepared during this window.
Contractors who treat the suspension as an opportunity to delay compliance work are making a strategic mistake. The pause provides time to build a defensible security program without the immediate pressure of third-party certification. Organizations that use this window to close gaps, document controls, and establish consistent processes will be in a stronger position when enforcement resumes. Understanding what cybersecurity compliance services include for SMBs — from gap analysis and risk assessments to policy development and audit preparation — can help contractors make the most of this time.
Audit-ready documentation includes system security plans, policies and procedures, network diagrams, asset inventories, risk assessments, incident response plans, training records, and evidence of control implementation. These artifacts are required for CMMC certification, but they are also valuable for responding to prime contractor questionnaires, cyber insurance applications, and government audits.
Start with a structured risk assessment. Identify which systems handle FCI or CUI. Map those systems to the NIST SP 800-171 controls. Document which controls are fully implemented, which are partially implemented, and which have not been addressed. For each gap, develop a corrective action plan with specific timelines and responsible parties.
From there, you can make decisions based on your actual risk profile, not on what a vendor is trying to sell you. The goal isn't to build an impenetrable wall. The goal is to make your environment hard enough to breach that attackers move on — and to demonstrate to auditors, primes, and insurers that you take the protection of defense information seriously.
The organizations that thrive in the coming years will not be those that react fastest after an incident occurs. They will be the organizations that build visibility, reduce risk proactively, and treat cybersecurity as an essential part of business strategy. That's the difference between managing technology and managing risk.