CMMC Phase 2 Suspended: What It Means for Your Supply Chain

Key Takeaways

  • On 13 July 2026 the US suspended CMMC Phase 2, the mandatory third-party assessment stage that was due to start on 10 November 2026.
  • A 60-day top to bottom review is now running, led by US Department of Defense CIO Kirsten Davies through a new CMMC Reform Task Force.
  • This is a pause, not a cancellation. Phase 1 self-assessment and the underlying legal duty to protect US federal data remain in force.
  • The reasons given were high compliance costs, a severe shortage of approved assessors, and firms leaving the defence market as a result.
  • If your organisation sits anywhere in a US defence supply chain, keep preparing. The timetable moved, the obligation did not.

Introduction

The US has hit pause on the part of CMMC that most worried organisations in the supply chain. On 13 July 2026 it suspended Phase 2, the stage that would have forced mandatory independent assessment from 10 November 2026. A pause is not the same as the end, so it would be a mistake to stop work now. In fact, this process is common in the Defence Industry environment on both sides of the Atlantic, acting almost like a Warning Order or reality check along the lines of;

  • Defence announces a new requirement/standard
  • Compliance deadlines are set
  • Defence Industry resists the change
  • Deadline approaches and creates contract compliance issues
  • Industry recognises the requirement/standard
  • Defence extends the deadline
  • Industry achieves compliance.

This post sets out plainly what happened, why, who decided it, and what it means if your organisation supplies into US defence, either directly or as one link in a longer chain.

What Actually Happened

The US Department of War announced an immediate suspension of CMMC Phase 2 requirements. Phase 2 was the mandatory third-party certification stage, the point at which suppliers handling Controlled Unclassified Information (CUI) would have needed an external assessor to verify their controls rather than signing their own attestation. CMMC covers unclassified defence data only, meaning Federal Contract Information and CUI. Classified information is protected under separate regimes and sits outside the scheme entirely.

In its place, DoD Chief Information Officer Kirsten Davies signed a memo launching a 60 day top to bottom review of the whole programme, delivered through a newly formed CMMC Reform Task Force. The Task Force is expected to report its findings and recommendations within that window, which means the shape of any revived scheme should become clear before the autumn. Understanding why the US pulled back tells you a great deal about what comes next.

Why the US Hit Pause

The official reasoning is blunt. CMMC was meant to raise the security of the Defence Industrial Base (DIB), but in practice it created heavy compliance costs and bureaucracy that pushed innovative firms out of the market. The concern is that the very businesses the US wants to keep, small specialist suppliers, were opting out of contracts rather than facing the bill.

There is also a capacity problem. Somewhere over 100,000 businesses need a third-party assessment, yet only around 100 approved assessors exist to carry them out. With that imbalance, the November timetable was never realistic, and the pause aligns the programme with a wider push to strip bureaucracy out of defence acquisition. None of that, however, removes the duty at the heart of the scheme.

Why You Cannot Stop Preparing Yet

Here is the point too many organisations will miss. The suspension covers the assessment mechanism, not the requirement to protect data. Phase 1, the self-assessment obligation that went live in November 2025, remains fully in force. So, the underlying contract clause, DFARS 252.204-7012, which requires suppliers to safeguard federal information and report incidents is still a requirement.

One more thing has not changed. Other UK certifications still do not count towards CMMC. As we set out in our guide to CMMC 2.0 for UK contractors in US defence, UK schemes such as Cyber Essentials, ISO 27001 and the Defence Cyber Certification do not automatically satisfy the US standard. When Phase 2 returns in some form, the organisations ready for it will be those that kept working on their NIST SP 800-171 controls during the pause. So the real question is what to do with the breathing space.

The Next Step for Supply Chain Organisations

Whether you are a Defence Prime, a commercial manufacturer, a software house, or an SME further down the supply chain, the actions are the same. First, confirm exactly what data you handle. If your work touches Federal Contract Information or Controlled Unclassified Information, you are in scope no matter how far down the chain you sit. Second, maintain a Gap Analysis against NIST SP 800-171 moving and maintain an honest score in the Supplier Performance Risk System, because that self-assessment duty is live today.

For Primes, the flow down duty has not gone away either. Assurance across your suppliers is still your responsibility, and as we argued in Beyond the Questionnaire, a self-certification tick box was never real assurance in the first place. Treat this pause as time to build genuine visibility of your supply chain rather than time to defer the issue. It is worth remembering that the broader regulatory direction is tightening, not loosening, as our note on the UK Cyber Security and Resilience Bill makes clear. For organisations that want a domestic benchmark to build from, the Defence Cyber Certification is a sensible foundation, and Pera Prometheus is an approved certifying body for DCC Level 0 as well as for Cyber Essentials and Cyber Essentials Plus. We can also assist you with gap analysis, remediation activities, implementation, and maintenance of DCC Levels 1, 2, and 3.  In fact, these are the areas where we excel, using our veteran experience to provide logical solutions to meet Defence requirements.

Ready to Take the Next Step?

A pause with no clear endpoint is unsettling, especially when your place in a supply chain depends on getting this right. At Pera Prometheus, we work with organisations across the full supply chain at exactly this stage. Get in touch and let us talk through where you sit and what to do with the time this pause has bought you.

Frequently Asked Questions

Q: Is CMMC cancelled?

A: No. Phase 2 is suspended and under a 60-day review, but the programme still exists and Phase 1 remains in force.

Q: Does the pause mean we can stop our NIST SP 800-171 work?

A: No. The duty to protect federal data under DFARS 252.204-7012 is unchanged, and the firms ready when Phase 2 returns will be those who kept going.

Q: Does the 10 November 2026 deadline still apply?

A: No. The mandatory third-party assessment date has been suspended, and any new timetable will follow the review.

Q: We are a Prime. Do we still flow requirements down to our suppliers?

A: Yes. Your responsibility to protect data and assure your supply chain continues, regardless of the Phase 2 pause.

Q: What should we do during the 60-day review?

A: Confirm what data you handle, keep your gap analysis and SPRS score current, and use the time to close real weaknesses rather than waiting.

Stay Safe, Stay Secure