Chuck Brooks is the president of Brooks Consulting International and one of Executive Mosaic’s GovCon Experts.
The Cybersecurity Maturity Model Certification, or CMMC, program has been a source of anxiety for the defense industrial base for many years. The dynamic has changed significantly. The Department of War announced the immediate suspension of all CMMC Phase II requirements on July 13, 2026, delivering an industrial-grade bombshell.
Phase II has been put on hold. It was originally scheduled to start an intensive ramp-up on November 10, 2026, requiring tens of thousands of mid-sized and small defense contractors to participate in costly, required third-party audits, or C3PAOs. Under Secretary Pete Hegseth’s Acquisition Transformation System, or ATS, the Pentagon has begun a comprehensive, top-to-bottom structural review.
There is a clear warning for executive boards: Don’t confuse a bureaucratic stop with a cybersecurity vacation. The underlying threat vector is still very alive, but the administrative apparatus is changing.
The Pentagon’s Reasons for Stopping Phase II
A sharp awareness that bureaucratic, paper-driven compliance was essentially stifling warfighting capacity led to the suspension of the stringent third-party verification methodology.
The very innovators the military most needs were being negatively impacted by the initiative. Small-to-midsize commercial technology companies that were leading the way in autonomous systems, artificial intelligence and sophisticated software were declining Pentagon contracts. Simply put, the entry hurdle had gotten too high because of:
*A severe lack of certified C3PAO auditing organizations across the country.
*R&D resources were depleted by excessive and crippling compliance expenditures.
*Regulatory red tape was intricate and constantly changing, slowing the pace to capability.
The DoD CIO realized that our defense industrial pipeline was being stalled by the conflict between protecting sensitive data and facilitating the quick incorporation of cutting-edge technology.
What Actually Swapped (And What Remains Non-Negotiable)
Let’s separate rumor from operational reality. This is a reform, not a cancellation. To maintain clear contract eligibility, you must understand exactly how the board has been reset:
Regulatory Component | Status under the July 2026 Update | Impact on Contractors |
| Phase II Third-Party Audits | 🛑 Suspended Indefinitely | Independent C3PAO audits are no longer required for contract awards pending the ATS review. |
| Phase I Requirements | Firmly in Place | Basic cyber hygiene and self-attestation mandates remain fully active. |
| NIST SP 800-171 Rev 2 | Enforced via Self-Assessment | Organizations must still implement the 110 baseline controls and upload valid scores. |
| DFARS 252.204-7012 | Fully Active | The legal obligation to safeguard Covered Defense Information is completely unchanged. |
| Annual Executive Affirmation | Required | Corporate officers (CEOs/CISOs) must still formally attest to their security posture in the SPRS. |
The Reality Check: Being Ready Rather Than Certified
The Pentagon will mostly rely on self-evaluations and selective, government-led spot audits under this transitory regulatory structure. It is a disastrous business strategy, nevertheless, to use this halt as a justification for postponing your security roadmap.
Prime contractors continue to assess the preparedness of their suppliers. If anything, they are actively cleaning their supply chains to avoid being held accountable under the False Claims Act. Even if your company manages controlled unclassified information, state-sponsored advanced persistent threats still use automated vulnerability scanners and agentic AI to target your data.
Additionally, the defense environment is adjusting to NIST SP 800-171 Rev 3 changes that incorporate more stringent controls and organization-defined parameters. Compliance is a dynamic structure that should never be viewed as a static, one-time task.
An Action Plan for Prospective Contractors
Change your focus right away if you want to keep a competitive edge while the CMMC Reform Task Force rewrites the regulations:
- Boost Your SPRS Score: Make sure your present environment is reflected in your Supplier Performance Risk System, or SPRS, score. Instead of speculating or assuming, check your gaps.
- Prioritize Real Resilience Over Checkboxes: Establish a proactive network posture. Put in place stringent multifactor authentication, separate your shop-floor operational technology from your corporate IT and create an unchangeable backup of your data.
- Take on a Zero Trust Attitude: Your perimeter is not safe just because a Phase II audit has been put on hold. Transform your architecture such that asset verification is automated and ongoing. Please see my article in GovConWire: Next Chapter in Defense Cybersecurity—Chuck Brooks on CMMC
The Pentagon is moving away from strict administrative compliance and toward real-world, scalable and flexible security. Our defense systems must change at the same rate as our opponents, who are innovating at machine speed. Don’t put off securing your home until after a final rule. Create a robust business architecture now so that your company is protected when Phase II reappears in its simplified version.














