CMMC Phase II Is Paused: Why Defense Contractors Cannot Afford to Stop Preparing

On July 13, 2026, the U.S. Department of War (DOW) suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program, delaying the third-party assessment requirement that was set to take effect on Nov. 10, 2026. The headline sounds like relief for the defense industrial base. The reality is far narrower: DOW paused one requirement while its obligation to protect defense information remains fully in force. If your organization processes, stores or transmits Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) under a DOW contract, your cybersecurity responsibilities have not changed. Here is what the pause actually covers, why it happened and why AppGate customers should keep moving toward full CMMC compliance.

What the DOW Actually Paused

The suspension applies to a single Phase II requirement: the mandate to obtain an assessment from a certified third-party assessor organization (C3PAO) for CMMC Level 2 contracts. That requirement is now on hold.

Everything else in the current phase stays in place. Under Phase I, which began on Nov. 10, 2025, DOW continues to include CMMC Level 1 (self) and Level 2 (self) requirements in solicitations and contracts whenever a contractor may handle FCI or CUI. Two points define the change:

  • The mandatory C3PAO third-party assessment for Level 2 contracts is suspended, not eliminated.
  • In place of mandatory outside audits, DOW will continue to rely on self-assessments and select government-led assessments, or spot checks, to verify compliance.

In short, DOW aims to keep third-party auditors from becoming a bottleneck while preserving current security requirements.

Why the DOW Hit Pause

The DOW Chief Information Officer (CIO) is establishing a CMMC Reform Task Force to conduct a 60-day review of the program. The goal is to align CMMC with the Secretary's Acquisition Transformation Strategy, which prioritizes speed to capability, lowers barriers for small, medium and non-traditional businesses and aims to replace bureaucratic compliance with scalable, resilient cybersecurity measures.

Cost is the driving concern. The suspension cites Small Business Administration (SBA) findings that CMMC has imposed compliance burdens on more than 100,000 small businesses, with individual certification costs approaching $600,000. The move also reflects a broader debate inside the government over how to balance defense security needs against the burden compliance places on industry.

To gather input, DOW issued a Request for Information (RFI) posing seven questions on cost drivers, which controls deliver the most risk reduction, which controls create disproportionate burden and how self-assessments could be streamlined. Responses are due by noon ET on Fri., Aug. 14, 2026.

What Did Not Change

Most cybersecurity requirements that apply to DoW contracts exist outside the CMMC program, so the pause leaves them fully in force. If you handle FCI or CUI, you are still obligated to:

  • Safeguard FCI and CUI in accordance with your contract
  • Implement the 110 security controls in National Institute of Standards and Technology (NIST) SP 800-171 Rev. 2
  • Meet the requirements of Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which the CIO confirmed remains in effect
  • Rapidly report cyber incidents to DOW
  • Complete self-assessments, post scores to the Supplier Performance Risk System (SPRS) and submit annual affirmations of continuous compliance

Enforcement has not paused either. The Department of Justice continues to pursue False Claims Act cases through its Civil Cyber-Fraud Initiative. If you attest to a compliance posture you cannot support, or report an inaccurate SPRS score, you remain exposed to significant penalties, whether or not a third-party audit is required.

Why You Should Keep Preparing

A paused deadline can feel like permission to slow down. For AppGate customers, it is not. Three realities make continued preparation the only sound course:

Compliance takes time. Building the necessary security controls and reaching full Level 2 compliance can take six to 12 months. If you stop now, you the work you have done will not carry forward, and you will have to begin again later.

CMMC is not canceled. The program could return in a substantially similar form after the 60-day review. Halting your program today simply creates a difficult backlog to clear later, likely under time pressure.

The requirements may expand elsewhere. As DoW reconsiders CMMC, other parts of the government are moving in the opposite direction. The Federal Acquisition Regulation (FAR) Council's proposed CUI rule, updated on June 23, 2026, would extend similar safeguarding and incident-reporting requirements to CUI across all federal contracts. If that rule is finalized as drafted, a narrower CMMC scope may offer little relief. Many contractors and subcontractors have already invested years preparing. This is not the moment to call that work off.

How AppGate Helps You Meet CMMC Requirements

The controls at the heart of CMMC and NIST SP 800-171 center on who can access what, and how tightly that access is governed. This is exactly where Zero Trust Network Access (ZTNA) applies. AppGate ZTNA gives defense contractors a direct-routed Zero Trust foundation that supports the access-focused requirements assessors and self-assessments scrutinize most closely.

With AppGate ZTNA, you can:

  • Enforce least privilege access so users and devices reach only the specific resources their role requires, supporting NIST 800-171 access control requirements
  • Verify identity before any connection using multi-factor authentication and identity-driven policy, mapping to identification and authentication requirements
  • Make protected resources invisible with single packet authorization (SPA), which cloaks systems from unauthorized users and shrinks your attack surface
  • Contain threats through micro-segmentation, which limits lateral movement across east-west traffic and helps isolate CUI environments
  • Apply consistent policy across on-premises, cloud and hybrid IT environments, so your security posture holds wherever your data lives

By reducing the attack surface and enforcing access at a granular level, AppGate ZTNA helps you strengthen the self-assessment scores you post to SPRS today and stand ready for third-party assessments when they return.

Keep Moving Forward

The pause is real, but narrow in scope. The DOW has delayed one requirement while it looks for ways to reduce cost and burden, all while holding firm on its expectation that contractors protect defense information. The organizations that keep building toward CMMC compliance now will be the ones ready to compete when the full framework takes hold.

Download our eBook, "CMMC 2.0: Mapping AppGate ZTNA Access Controls for Defense Contractors," to see how AppGate supports your CMMC and NIST SP 800-171 requirements.

Receive News and Updates From AppGate