Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

The Information Highway

The Information Highway

Font size: +
9 minutes reading time (1816 words)
Featured

CMMC Level 2 Is on Hold: What Defense Contractors Need to Know

If you've been preparing your company for a CMMC Level 2 certification assessment, you may have heard some confusing news: the federal government has put CMMC Phase II on hold.

That part is true.

What isn't true is that CMMC has disappeared.

On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II, which had been scheduled to begin November 10, 2026. At the same time, officials launched a 60-day review of the program. Phase I self-assessment requirements remain in place.

TL;DR

  • CMMC has not been canceled.
  • The planned November 10, 2026 start of Phase II has been suspended.
  • That pauses the broader rollout of mandatory third-party Level 2 certification assessments.
  • Phase I self-assessments remain active.
  • Existing contractual cybersecurity requirements for protecting Controlled Unclassified Information have not simply vanished.
  • Companies that stopped preparing altogether could find themselves scrambling when the government announces what comes next.

Cybersecurity operations supporting protection of defense information

 Here's what all of that means without the alphabet soup.


What exactly happened to CMMC Level 2?

The government suspended the transition to CMMC Phase II while it conducts a review of the program. Phase II had been scheduled to begin November 10, 2026 and would have expanded the use of Level 2 certification assessments performed by Certified Third-Party Assessment Organizations, better known as C3PAOs.

This distinction matters because headlines like "CMMC suspended" make it sound as though someone unplugged the entire program.

They didn't.

Think of it more like road construction where the next major section has been temporarily closed while engineers reconsider the design. The road behind you is still there. The rules already applying to your business don't evaporate because the next stage is being reconsidered.

The Department says it is reviewing CMMC with an eye toward reducing compliance barriers, particularly for small, medium-sized and nontraditional businesses, while maintaining cybersecurity protections.

Why did the government put Phase II on hold?

Cost and complexity are a major part of the story.

In announcing the suspension, the Department said the existing approach had created significant compliance costs and bureaucratic burdens that could discourage companies from participating in the Defense Industrial Base. Officials said the review will look for a more scalable approach while maintaining cybersecurity and operational resilience.

That concern isn't hard to understand from a small-business perspective.

Picture a 30-person manufacturer that makes a specialized component for a larger defense contractor. It doesn't have a Fortune 500 IT department. The owner may be trying to interpret NIST requirements, document policies, secure cloud services, train employees, prepare an assessment environment and keep production moving at the same time.

Cybersecurity still matters enormously.

But so does whether smaller suppliers can realistically navigate the process.

That's the tension the government is now reconsidering.

Does the hold mean you no longer need CMMC Level 2 security?

No. A pause in Phase II should not be interpreted as permission to stop protecting CUI or ignore existing contract requirements.

The government's current small-business cybersecurity guidance still describes CMMC Level 2 as protection for Controlled Unclassified Information (CUI) and ties Level 2 to the 110 security requirements in NIST SP 800-171 Revision 2.

Separate DFARS requirements also continue to matter. DFARS provisions require applicable contractors to provide adequate security for covered contractor information systems, and NIST SP 800-171 requirements remain part of that framework.

Here's the easier way to think about it:

The certification timetable changed. The need to protect sensitive defense information did not.

CMMC issue Current status
CMMC program Still exists
Phase I requirementsRemain active
Level 1 self-assessmentStill applicable where required
Level 2 self-assessmentStill applicable where required
Phase II rollout scheduled for Nov. 10, 2026Suspended
Expanded mandatory Level 2 C3PAO certification rolloutOn hold pending review
Protecting applicable CUIStill required
Applicable NIST SP 800-171/DFARS obligationsStill matter
New Phase II start dateNot yet announced

 Sources: Department CMMC guidance and July 13 announcement.


What was CMMC Level 2 supposed to require?

Level 2 is aimed at organizations handling Controlled Unclassified Information.

CUI isn't classified information in the traditional "Top Secret" sense. But it is government information that still needs protection.

For example, depending on the contract, that could involve technical information, engineering data, specifications or other sensitive information connected with defense work. DFARS guidance specifically recognizes technical information such as engineering drawings, specifications, manuals, technical reports, data sets and software as examples within this broader environment.

Under the CMMC model, Level 2 requires implementation of the 110 NIST SP 800-171 Revision 2 security requirements. Depending on the solicitation and information involved, Level 2 was designed around either self-assessment or assessment by a C3PAO, along with annual affirmation requirements.

That is much more than installing antivirus software.

It reaches into areas such as access control, authentication, system configuration, incident response, employee practices, monitoring, documentation and how sensitive information moves through the organization.

 What does the CMMC pause look like on a timeline?

Before the July announcement, Phase II was scheduled to start on November 10, 2026. The July 13 action suspended that transition and pending/future implementation milestones while the Department undertakes its review.

The chart does not suggest Phase II will begin later this year. As of this article's August 28, 2026 update, the old November milestone is suspended; contractors should wait for official guidance rather than assuming a replacement date.

Should companies stop spending money on CMMC preparation?

For most businesses handling CUI, completely stopping would be a risky interpretation of the announcement.

There is a difference between not rushing into an assessment that is no longer required on the old timetable and abandoning cybersecurity work your contracts may already require.

This pause may actually be useful.

Instead of treating CMMC like a mad dash toward a certificate, companies can look at the underlying environment:

  • Where does our CUI actually live?
  • Who can access it?
  • Are we protecting accounts with appropriate authentication?
  • Are systems properly configured and monitored?
  • Do our policies describe what we actually do?
  • Do employees understand their responsibilities?
  • Does our NIST SP 800-171 assessment reflect reality?
  • Can we prove the controls we claim to have implemented?

That last question matters.

A policy sitting in a folder isn't the same thing as a working security control.

What should defense contractors do during the government hold?

Use the pause to improve readiness, not to forget about it. Contractors should first determine what their current contracts and solicitations actually require, then keep working on the cybersecurity obligations that remain applicable.

A sensible checklist looks like this:

1. Review your current contracts.
Don't make a compliance decision based on a headline. Identify the clauses and cybersecurity requirements that actually apply to your organization.

2. Confirm whether you handle CUI.
You can't properly scope a CMMC environment until you know where sensitive information enters, where it is stored, who touches it and where it leaves.

3. Review your NIST SP 800-171 posture.
Applicable contractors should know where they meet requirements and where gaps remain.

4. Check your self-assessment and SPRS obligations.
Phase I did not disappear with the Phase II suspension. The Department expressly says Phase I self-assessment requirements remain in place.

5. Keep your evidence organized.
Policies, configurations, logs, diagrams, training records and other evidence are much easier to maintain continuously than recreate shortly before an assessment.

6. Watch official CMMC guidance.
Don't build your strategy around rumors about what the revised program "will" look like. The government is reviewing it now.

Could CMMC Level 2 certification come back?

Yes, the current action is a suspension and review, not an announcement that Level 2 cybersecurity has been eliminated.

What nobody should do, however, is pretend to know exactly what the revised certification structure will look like before the government finishes its work.

The Department announced a comprehensive review intended to reduce barriers while retaining cybersecurity protections. That creates the possibility of changes to implementation, assessment or compliance mechanics. Until official guidance arrives, predictions are just predictions.

For a business owner, that's actually the most important takeaway.

Prepare for the security requirement, not just the test.

If your systems genuinely protect CUI, your documentation is current and your organization understands its responsibilities, adapting to whatever comes next should be far easier than starting from scratch.

What should you remember about the CMMC Level 2 hold?

CMMC has been confusing enough without turning a government pause into another round of rumors.

The simple version is this:

Phase II is suspended. Phase I remains active. The old November 10, 2026 Phase II rollout date is no longer the deadline businesses were preparing around. But applicable cybersecurity and CUI-protection responsibilities remain important.

For defense contractors and subcontractors, this isn't a reason to panic.

It isn't a reason to throw away the work you've already done either.

It's a chance to get the fundamentals right. 

People Also Ask

AI Phishing Attacks Are Changing Fast: What Busine...

Related Posts

Top Breaches Cost ($) of 2024

HEALTHCARE
FINANCIAL
INDUSTRIAL
TECHNOLOGY
ENERGY
Source: IBM Cost of a Data Breach Report 2024