What the Phase 2 pause means for current requirements, client readiness, and the future of CMMC
By Sumera Riaz, VP of Cybersecurity
At a Glance
- The Department of Defense (DoD) has paused the planned Nov. 10, 2026 rollout of CMMC Phase 2 while a 60-day review of the program is underway.
- All future CMMC implementation phases have been suspended pending the outcome of the review.
- CMMC Phase 1 self-assessment requirements remain in effect. Applicable defense contractors must still comply with NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments.
- The pause creates an opportunity for technology advisors to help customers identify security gaps and prepare for potential future CMMC requirements.
- Organizations that strengthen cybersecurity posture now will be better positioned when additional CMMC requirements resume.
Meeting cybersecurity requirements is an unavoidable part of doing business with the federal government. For many defense contractors, that means complying with Cybersecurity Maturity Model Certification (CMMC), a tiered program designed to ensure that companies handling sensitive government information have the proper safeguards in place.
But complying with CMMC isn’t always straightforward. Years of revisions, phased requirements, and shifting deadlines have made it difficult for busy defense contractors to keep pace—especially small firms that lack the resources of larger competitors.
The latest update took place on July 13, when the Department of Defense paused CMMC Phase 2 implementation, creating uncertainty among the Defense Industrial Base (DIB), or the global network of partners that research, design, and build military equipment and services.
As it turns out, the DoD’s decision to punt CMMC Phase 2 is a gift for technology advisors and defense clients—many of whom were unprepared for the planned assessment requirements. The pause creates a limited opportunity to assess customers’ cybersecurity posture before CMMC Phase 2 implementation resumes.
What Technology Advisors Need to Know About CMMC Compliance
Before we dive into the latest update, here’s a quick breakdown of CMMC, and why it matters to defense contractors.
- The DoD introduced its initial CMMC framework in 2019 to verify that defense contractors protect sensitive government information.
- The first complete model, CMMC 1.0, followed in 2020. The DoD then introduced version 2.0 in 2021 in response to industry concerns about the program’s cost and complexity.
- Today, CMMC compliance is table stakes for organizations pursuing applicable DoD contracts. The requirements extend throughout the Defense Industrial Base, covering both prime contractors and subcontractors.
CMMC 2.0 contains three levels, each with progressively advanced cybersecurity and assessment requirements based on the sensitivity of the government information that an organization handles.
As I explained in a recent post, CMMC is being implemented through a phased rollout that was initially scheduled to extend through 2028.
The DoD established four phases, beginning with the launch of Phase 1 on November 10, 2025.
- Phase 1: Initial self-assessment requirements began for Level 1 and Level 2 contractors
- Phase 2: Mandatory third-party assessments were scheduled to begin for applicable Level 2 contracts
- Phase 3: Level 3 government assessments were scheduled to be introduced for high-priority programs
- Phase 4: Full implementation was scheduled across all applicable contracts
How the DoD’s Phase 2 Pause Impacts the CMMC Rollout
On July 13, the DoD issued a memorandum and press release suspending the planned November 10, 2026 transition to CMMC Phase 2, including applicable Level 2 third-party assessment requirements.
In sum:
- The DoD has paused its plan to introduce Phase 2 of its CMMC requirements.
- The department is conducting a comprehensive 60-day review of its CMMC certification program.
- All pending and future CMMC deadlines—including Phase 3 and Phase 4—have been suspended until further notice.
The review is intended to align CMMC with the department’s broader acquisition strategy, which prioritizes faster procurement and lower barriers for small, medium-sized, and nontraditional businesses. Small businesses account for more than 70% of all DoD suppliers, making compliance costs and complexity significant concerns for the department.
“In support of Secretary Pete Hegseth’s directive to reduce compliance barriers for small and medium-sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program,” explained DoD Chief Information Officer Kirsten A. Davies in the press release. “Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness. We believe the DIB can achieve both, while we reduce unnecessary government red tape.”
How Technology Advisors Can Help Clients Achieve CMMC Compliance
CMMC compliance isn’t going away—at least for now. As the DoD stated in its July 13 press release, all Phase I self-assessment requirements remain in place.
In other words, the Phase 2 suspension does not suspend existing cybersecurity requirements for defense contractors. The transition to Phase 2 is on pause, but there are still important requirements that contractors must meet to maintain eligibility for certain DoD contracts.
For technology advisors and clients, this decision should be a wake-up call to verify cybersecurity posture before it affects an award, renewal, or customer relationship.
Unfortunately, the vast majority of contractors are behind the curve when it comes to CMMC adoption. According to Regulence, 96% of defense contractors are not prepared for CMMC Level 2—potentially making them ineligible to handle sensitive government data.
Why CMMC Compliance is High Priority for Defense Clients
One potential downside of the CMMC Phase 2 pause is that extended implementation timelines can encourage procrastination. Organizations may be tempted to postpone assessments or delay investments while waiting for additional guidance from the DoD.
However, it’s important to remember that the pause only affects the planned rollout beginning with Phase 2, while applicable Phase 1 self-assessment requirements remain in effect. As such, defense contractors must continue meeting current compliance obligations while preparing for future updates.
CMMC compliance has a direct impact on revenue because it can determine eligibility for applicable defense contracts—making it a priority for defense clients.
By focusing on CMMC readiness, defense contractors can:
- Maintain eligibility for certain defense contracts
- Demonstrate cybersecurity readiness
- Reduce future remediation pressure
Critical CMMC Discovery Questions to Ask Defense Clients
The following questions can help technology advisors keep CMMC discussions moving forward during the Phase 2 pause:
- If a Level 2 third-party assessment applied to your next DoD contract, would your organization be ready?
- Are you using the CMMC Phase 2 delay to address security gaps?
- Are your current security controls aligned with NIST SP 800-171?
- When was the last time you reviewed your System Security Plan or Plan of Action and Milestones?
- Have you recently completed a security gap assessment?
- Do you know which CMMC level applies to your organization?
The Bottom Line: Make the Most of this Limited Time Opportunity
The DoD just handed technology advisors and defense contractors a valuable gift: more time to assess CMMC readiness and make critical updates.
The question for technology advisors is: What will you do with it?
Advisors can use this opportunity to demonstrate their value as trusted partners and set the table for additional security sales. CMMC compliance conversations can deepen client trust and strengthen existing partnerships.
The most important thing to remember is that you don’t need to be a policy expert to guide customers through their CMMC compliance journey. The key to maximizing this opportunity is to start engaging defense clients about readiness and help them future-proof their environments.
Telarus is standing by to help identify readiness gaps, answer challenging questions, identify the right solutions, and build a practical roadmap for CMMC compliance.
FAQ: CMMC Phase 2 Requirements
What is CMMC?
The Cybersecurity Maturity Model Certification (CMMC) is a tiered compliance program designed to verify that defense contractors have implemented the necessary cybersecurity safeguards required to protect Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). The CMMC program contains three levels, with advanced security requirements based on the nature of the information an organization handles.
Which organizations are subject to CMMC requirements?
CMMC requirements apply to prime contractors and subcontractors in the defense industry that process, store, or transmit FCI or CUI on unclassified information systems.
What CMMC requirements remain in effect during the Phase 2 update?
During the Phase 2 pause, all applicable Phase 1 self-assessment requirements remain in effect. Contractors may still be required to complete Level 1 self-assessments or Level 2 self-assessments aligned with the NIST SP 800-171 Rev. 2. In addition, contractors must still protect FCI and CUI.
Is CMMC Phase 2 canceled or only paused?
At this point, CMMC Phase 2 is on hold pending further review. The CMMC Reform Task Force is expected to deliver a final report to the DoW in September 2026.
ABOUT THE AUTHOR
Sumera Riaz
Sumera Riaz is Vice President of Cybersecurity at Telarus, a CISSP-certified former Chief Information Security Officer turned industry advocate on a mission to change how cybersecurity is sold. Based in the Dallas–Fort Worth area, she empowers technology advisors to confidently guide their clients through AI risk, enterprise security, and what’s coming next—including the quantum computing shift organizations can’t afford to ignore. A Forbes Council member and sought-after speaker, Sumera translates technical complexity into human clarity, making the scary feel manageable and the stakes impossible to ignore. Her mission is simple: to leave every company better protected than she found it.