CMMC Phase 2 Pause: What Contractors Need to Know

The certification timeline changed. The mission did not.

On July 13, 2026, the Department of War announced the immediate suspension of Cybersecurity Maturity Model Certification Phase II requirements, which had been scheduled to take effect on November 10, 2026.

The Department also established a CMMC Reform Task Force to conduct a comprehensive review of the program and deliver recommendations within 60 days. According to the official announcement, Phase I self-assessment requirements remain in place during this review.

The announcement has understandably created questions throughout the Defense Industrial Base:

  • Does this mean CMMC is going away?
  • Are Level 2 assessments still necessary?
  • Should companies pause their compliance investments?
  • What requirements remain enforceable?
  • What should contractors and subcontractors do while the review is underway?

To help our customers understand the announcement and make informed decisions, CUI Supply is hosting a free, customer-exclusive webinar:

CMMC Phase 2 Pause: What It Means and What Comes Next

During this webinar, we will break down the Phase 2 suspension, discuss what remains in effect, and explain why organizations should not treat the announcement as permission to stop protecting Controlled Unclassified Information.

Register for the free webinar

RESERVE YOUR SPOT

Webinar scheduling and attendance details are available on the registration page.

New to Controlled Unclassified Information?
Understanding what qualifies as CUI is foundational to CMMC, DFARS, and NIST SP 800-171 compliance. Read our guide, CUI 101: What Controlled Unclassified Information Really Is—and Why It Matters.

Share information about your brand with your customers. Describe a product, make announcements, or welcome customers to your store.