The Pentagon has suspended the next phase of its contractor cybersecurity certification rollout, delaying stricter checks that were due to start in November 2026 for companies seeking defense contracts. The Cybersecurity Maturity Model Certification (CMMC) phase 2 would have required third-party Level 2 assessments for contractors handling controlled unclassified information (CUI), but the Department of Defense said it will review the program for 60 days, citing industry feedback and too few approved assessors.
Why it matters: This affects defense contractors, subcontractors, and suppliers that do business with the U.S. military, especially smaller firms preparing for CMMC audits. It is not an emergency patching issue, but it changes compliance planning and procurement timelines for organizations handling federal contract information or CUI.
SecurityWeek News
2026.07.17
91% relevant
This article directly follows the same Pentagon decision to suspend CMMC Phase 2 and adds concrete reaction from compliance and defense-industry experts, including that DFARS 252.204-7012, SPRS submissions, and NIST SP 800-171 self-assessments remain in force while third-party audits are paused.
Eduard Kovacs
2026.07.14
100% relevant
This article establishes a distinct new policy story: the Pentagon's formal pause and review of CMMC phase 2 implementation.
← Back to all stories