On July 13, 2026, the Department of War (formerly the Department of Defense) announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect on November 10, 2026. The suspension eliminates the third-party assessment requirement — specifically, C3PAO (CMMC Third-Party Assessment Organization) audits for Level 2 certification and DIBCAC government-led assessments for Level 3 designations.
DoW published the final CMMC rule on September 10, 2025, ref. 90 Federal Register (FR) 43560, with an effective date of November 10, 2025.
Contractor Compliance with the Cybersecurity Maturity Model Certification Level Requirement[s]) to address new CMMC post-award requirements. DoW will implement CMMC in four phases:
- Phase 1 began on November 10, 2025.
- Phase 2 begins on November 10, 2026.
- Phase 3 begins on November 10, 2027.
- Phase 4, the final phase, begins on November 10, 2028.
Recommended Contractor Actions Now:
- Ensure your current cybersecurity posture aligns with contractual requirements related to NIST SP 800‑171 controls.
- Follows all steps to use Procurement Integrated Enterprise Environment (PIEE) applications, to secure access to the Supplier Performance Risk System (SPRS) module, and post a current self-assessment score in SPRS.
- Monitor updates from DoD, DPCAP, and SAM.gov for USACE Special Notices, official timelines and certification requirement updates.
- Comply with current DFARS 252.204-7012 requirements to report cyber incidents to DoD within 72 hours of discovery, using DoD’s Cyber Crime Center (DC3) portal at: https://dibnet.dod.mil.
Important Disclaimers:
- This notice is for INFORMATION ONLY and does not impose new requirements.
- This notice does not create any rights/benefits enforceable by law against the U.S. Government.