The CMMC Phase II suspension changes the cybersecurity compliance timeline for thousands of companies working within the Defense Industrial Base. However, it does not eliminate CMMC or the cybersecurity requirements that already apply to defense contractors and subcontractors.
On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II. The next phase had originally been scheduled to begin on November 10, 2026. Phase II would have expanded the use of third-party CMMC assessments for applicable contracts.
Instead, CMMC implementation will remain in Phase I while the Department conducts a broader review of the program. Current Phase I self-assessment requirements remain in place. Therefore, manufacturers should view the suspension as additional preparation time rather than an end to their compliance responsibilities.
For manufacturers that handle Federal Contract Information or Controlled Unclassified Information, the distinction is especially important. Cybersecurity requirements can affect contract eligibility, subcontracting relationships, technology investments, and how sensitive information moves throughout the organization.
What the CMMC Phase II Suspension Actually Changes
The Department announced the CMMC Phase II suspension after raising concerns about compliance costs and administrative burdens across the Defense Industrial Base. These concerns were particularly relevant to small, midsize, and nontraditional defense contractors.
The Department also announced a comprehensive review of the CMMC program. According to its official July 13 CMMC announcement, the review is intended to reduce unnecessary barriers while maintaining cybersecurity requirements for organizations working with government information.
As a result, the transition into Phase II has stopped. The previously planned November 10, 2026 implementation milestone will not move forward as originally scheduled.
This change matters because Phase II would have expanded the use of CMMC Level 2 assessments performed by Certified Third-Party Assessment Organizations, commonly called C3PAOs.
However, the suspension does not mean companies can abandon their existing cybersecurity programs. Instead, CMMC remains in Phase I.
CMMC Phase I Requirements Are Still in Effect
The official CMMC program guidance states that the program is currently paused in Phase I. During this period, applicable contracts may require Level 1 or Level 2 self-assessments.
The appropriate level depends largely on the information a contractor processes, stores, or transmits.
CMMC Level 1: Protecting Federal Contract Information

CMMC Level 1 focuses on Federal Contract Information, also known as FCI.
Organizations at this level must complete an annual self-assessment against 15 cybersecurity requirements from FAR 52.204-21. They must also provide an annual affirmation of continued compliance.
Assessment results are entered into the Supplier Performance Risk System, or SPRS. The CMMC Level 1 requirements published by the Department also specify that Plans of Action and Milestones are not permitted for unmet Level 1 requirements.
Therefore, organizations seeking Level 1 status must satisfy all applicable requirements rather than relying on a future remediation plan.
CMMC Level 2: Protecting Controlled Unclassified Information
CMMC Level 2 applies to organizations that handle Controlled Unclassified Information, commonly called CUI.
During the current Phase I pause, Level 2 may require a self-assessment every three years. Organizations must evaluate compliance with the 110 security requirements contained in NIST SP 800-171 Revision 2.
In addition, companies must provide an annual affirmation of continued compliance. Limited Plans of Action and Milestones may be permitted for certain unmet Level 2 requirements.
These requirements are outlined within the Department’s current CMMC Level 2 assessment guidance.
The current pause removes the planned expansion of mandatory C3PAO assessments under Phase II. It does not remove the underlying requirements for protecting CUI.
| CMMC Level | Protected Information | Current Assessment | Security Requirements | Affirmation |
|---|---|---|---|---|
| Level 1 | Federal Contract Information (FCI) | Annual self-assessment | 15 FAR 52.204-21 requirements | Annual |
| Level 2 | Controlled Unclassified Information (CUI) | Self-assessment every three years during the current Phase I implementation | 110 NIST SP 800-171 Revision 2 requirements | Annual |
Why the CMMC Delay Does Not Eliminate Cybersecurity Obligations
CMMC is one part of a larger federal cybersecurity framework. Defense contractors may already have contractual requirements that exist independently of the Phase II rollout.
For example, DFARS 252.204-7012 requires applicable contractors to provide adequate security for covered defense information. Covered contractor information systems may also need to satisfy NIST SP 800-171 requirements.
The DFARS clause specifically requires covered contractor information systems to implement applicable NIST SP 800-171 protections. It also contains cybersecurity incident reporting and subcontractor requirements.
Therefore, a delay in CMMC certification requirements does not automatically remove existing DFARS obligations.
Current DFARS cybersecurity policy also requires applicable contractors and subcontractors to provide adequate security on covered contractor information systems. Contractors subject to NIST SP 800-171 requirements may need a current DoD assessment at the time of contract award.
This distinction is important for manufacturers that participate in defense supply chains. A company might manufacture components several layers below a prime contractor yet still receive information that requires specific safeguards.
CMMC and related cybersecurity requirements can also flow through the supply chain. Manufacturers should understand what information they receive and which systems interact with that information.
Simply assuming that CMMC no longer matters because Phase II stopped could create significant problems later.
Is Your Organization Prepared for Current CMMC Requirements?
The CMMC timeline may have changed, but existing cybersecurity obligations remain. Manufacturers that handle FCI or CUI should use this period to identify security gaps, document their environment, and prepare for future changes.
Onsite Computing helps organizations evaluate their current cybersecurity environment against applicable CMMC requirements. Our team can help identify technical gaps and build a practical remediation strategy around your existing infrastructure.
Five Areas Defense Manufacturers Should Review Now
The CMMC Phase II suspension gives manufacturers additional time to strengthen their environments before the program moves forward again.
However, compliance preparation should focus on more than completing a checklist. Businesses need to understand where sensitive information exists and whether their technology actually protects it.
Identify Where FCI and CUI Exist
The first step is identifying where regulated information enters, moves through, and leaves the organization.
Manufacturing environments can make this complicated. CUI might appear in engineering drawings, specifications, emails, shared folders, ERP systems, cloud storage, workstations, or vendor portals.
For example, an engineering department may receive a controlled drawing through email. Employees might then download the file to a workstation or place it within a shared production folder.
Each system that processes, stores, or transmits that information can affect the organization’s security scope.
Reducing unnecessary exposure can also reduce complexity. Therefore, organizations should avoid allowing sensitive information to spread across systems without a clear business need.
Review Identity and Access Controls
Organizations should know who can access sensitive information and why that access is necessary.
Former employees, shared accounts, excessive administrator privileges, and outdated permissions can create unnecessary risk. Likewise, weak authentication can undermine other security investments.
Manufacturers should review user accounts, administrator access, multifactor authentication, password policies, and access to sensitive files.
In addition, access reviews should become an ongoing process. Employee roles change over time, and permissions should change with them.
Evaluate Endpoint and Network Security
CMMC compliance depends on the technology that protects the environment every day.
Organizations should review workstation security, patching, endpoint protection, network configurations, remote access, logging, and system monitoring. Unsupported hardware and software can also create additional challenges.
Manufacturing companies may face another layer of complexity because business networks often connect with production environments.
ERP systems, engineering workstations, file servers, production equipment, and operational technology can create dependencies that require careful planning.
As a result, manufacturers should understand how these systems communicate before changing network architecture or security controls.
NIST SP 800-171 Revision 3 Is Also on the Horizon
The CMMC Phase II suspension is not the only potential change defense contractors should watch.
The August 14, 2026 Federal Regulatory Plan includes a planned amendment to the CMMC program addressing the transition from NIST SP 800-171 Revision 2 to Revision 3.
According to the regulatory plan, the amendment is intended to establish both a deadline and transition period for moving from Revision 2 to Revision 3.
Revision 3 introduces changes to the security requirements and adds greater specificity in several areas. It also introduces organization-defined parameters within certain security requirements.
However, current CMMC Phase I guidance still points organizations to NIST SP 800-171 Revision 2.
Manufacturers should not assume Revision 3 requirements already apply to their CMMC assessment. Instead, businesses should monitor the transition while continuing to improve their current cybersecurity programs.
A well-managed security environment should be able to adapt as requirements evolve.
Use the CMMC Phase II Suspension as Preparation Time
The CMMC Phase II suspension gives the Defense Industrial Base more time before the previously planned expansion of third-party assessments.
That extra time has value. Manufacturers can use it to understand their information, improve security controls, correct weaknesses, and build better documentation.
Waiting for the government to announce the next deadline creates the opposite advantage.
Cybersecurity projects often involve more than purchasing software. Businesses may need to redesign networks, replace unsupported equipment, revise access controls, create policies, train employees, or change how sensitive information moves between systems.
Those projects become much harder when completed under a contract deadline.
The final structure of CMMC may change after the Department completes its review. However, the Department has emphasized that cybersecurity requirements remain in place and that organizations working with government information must continue protecting that information.
Manufacturers should therefore focus on building a defensible cybersecurity program rather than preparing only for an assessment date.
Onsite Computing works with manufacturers and other organizations throughout the Defense Industrial Base to evaluate technology, cybersecurity, and CMMC readiness. We can help identify gaps and develop a practical roadmap around your organization’s requirements.
Contact Onsite Computing to schedule a CMMC readiness assessment today.
FAQ: CMMC Phase II Suspension
The Department announced the CMMC Phase II suspension on July 13, 2026. Phase II had been scheduled to begin November 10, 2026. According to the official suspension announcement, the Department instead paused implementation in Phase I while it conducts a broader review of the CMMC program.
Yes. CMMC has not been eliminated. Current Phase I CMMC requirements remain in effect. Applicable defense contractors must also continue meeting contractual cybersecurity requirements related to FCI, CUI, DFARS, and NIST SP 800-171.
The planned Phase II expansion of Level 2 C3PAO assessments has been suspended. Current Department guidance states that CMMC remains in Phase I and may require Level 1 or Level 2 self-assessments. Organizations should always review the specific cybersecurity requirements included in their contracts and solicitations.
Manufacturers should review where FCI and CUI exist within their environments. They should also evaluate access controls, endpoint security, network configurations, documentation, and third-party relationships. Correcting cybersecurity gaps now can make future compliance changes easier to manage.
The August 2026 Federal Regulatory Plan identifies a planned CMMC amendment addressing the transition from NIST SP 800-171 Revision 2 to Revision 3. However, current CMMC Phase I guidance continues to use Revision 2. Defense contractors should monitor the transition rather than assuming Revision 3 already applies.


