cmmcindependentNewsThe Broadside2 min read

DoD Suspends CMMC Phase 2, Launches Reform Review

The second major pause in four years signals structural rethinking (not a tweak) with the scope of review spanning OT, cloud, MSPs, and supply chain obligations.


TL;DR

The Department of Defense suspended CMMC Phase 2 on July 13, 2026, four months before its scheduled November 10 start. Phase 2 would have mandated third-party C3PAO assessments and Level 2 certifications as conditions of award for contracts involving CUI. A Reform Task Force convened in early September to review more than 1,100 RFI comments on assessment scope, cloud and MSP treatment, supply-chain reach, and operational technology applicability. Its report was due to the DoD CIO on September 11 but hasn't been made public. Phase 1 self-assessment requirements and underlying NIST SP 800-171 obligations remain in effect.

DoD Suspends CMMC Phase 2, Launches Reform Review
Editorial illustration · drawn by The Broadside

On July 13, 2026, DoD suspended CMMC Phase 2 (the third-party assessment mandate scheduled to take effect November 10) and established a Reform Task Force to reconsider the program's structure. This is the second major pause since the program was first announced. The first, under the Biden administration, produced "CMMC 2.0." This one reads as more fundamental.

The RFI that accompanied the suspension memorandum didn't limit itself to assessment costs and C3PAO availability. It asked about assessment scope, how cloud and managed service providers fit into the model, what CMMC means for subcontractors down the supply chain, and whether the program should reach operational technology and other specialized environments. That's a wider aperture than you'd open for incremental reform. More than 1,100 comments came in. The task force met in early September to review them, and its report was due to DoD CIO Kirsten Davies on September 11. No public release yet.

What Davies said, and didn't say

Davies spoke at the Billington Cybersecurity Summit on September 9. Press reports quote her saying more than half the comments supported the suspension. She also flagged concerns from the assessor community about how DoD would verify compliance with federal cybersecurity requirements absent the CMMC framework, and noted a parallel review of the Risk Management Framework.

The OT angle is worth watching. The RFI's explicit mention of operational technology environments, combined with Davies's remarks on cybersecurity risks to manufacturing and operational technology, suggests DoD is considering not just rolling back requirements but potentially extending the program into domains it previously didn't touch. That would be expansion, not contraction, and it'd create an entirely new set of compliance burdens for contractors whose factory floors and control systems were never in scope before.

What stays in place

None of this suspends the underlying obligations. DFARS 252.204-7012 remains in effect, including cloud security requirements, incident reporting, and media preservation. Contractors must still maintain current self-assessments in SPRS, affirm ongoing compliance with NIST SP 800-171 Rev. 2 controls, and meet CMMC Level 1 and Level 2 self-assessment requirements under Phase 1. DoD has said it will enforce these through self-assessments and selected government-led assessments during the suspension.

Contractors who rushed to schedule C3PAO assessments ahead of the November deadline are now in a holding pattern. Those assessments may still carry value (a completed third-party review demonstrates due diligence and could satisfy customer pressure) but whether they'll map onto whatever framework emerges from the task force is anyone's guess. Primes, subs, MSPs, and the assessor ecosystem are all waiting on a report that could reshape the program's architecture rather than adjust its dials.


Published ·Deep Fathom