CMMC Phase II Is Suspended. Your FAR, DFARS, and CAS Obligations Are Not.
On July 13, 2026, the Department of Defense announced the immediate suspension of CMMC Phase II. This third-party cybersecurity assessment requirement was scheduled to take effect on November 10, 2026.
DoD CIO Kirsten Davies is forming a 60-day CMMC Reform Task Force to review the certification program. For now, no one knows what the program will look like after that review.
For defense manufacturers, this is significant news. However, it does not mean compliance teams can take their foot off the gas.
CMMC was never the entire compliance picture. It is one program focused on one area of risk: cybersecurity. The broader obligations under the Federal Acquisition Regulation (FAR), Defense Federal Acquisition Regulation Supplement (DFARS), and Cost Accounting Standards (CAS) remain unchanged.
What Actually Changed?
CMMC Phase II would have required third-party assessments by Certified Third-Party Assessment Organizations, or C3PAOs, for contracts involving sensitive but unclassified information.
That requirement, along with pending and future CMMC milestones, is now suspended “until further notice.”
CMMC Phase I self-assessment requirements, which took effect last November, remain in place. The DoD will continue enforcing cybersecurity requirements through self-assessments and selected government-led reviews under NIST SP 800-171 Revision 2.
The Department’s announcement also makes an important distinction:
“This action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012.”
In other words, the government suspended a certification process. It did not suspend the responsibility to protect federal information, and it did not change any compliance obligations outside cybersecurity.
What Has Not Changed?
CMMC addresses how contractors demonstrate that their technology environments protect Covered Defense Information. It does not change your obligations related to:
- FAR requirements that must flow down from prime contracts to subcontractors
- DFARS clauses covering progress payments, supply chain integrity, and technical data
- CAS compliance for cost-type contracts
- Contractor Purchasing System Review (CPSR) readiness
- Defense Contract Audit Agency (DCAA) audits and incurred cost submissions
Each of these requirements follows its own regulations, timelines, and audit processes.
Pausing CMMC Phase II does not pause a CAS disclosure statement review. It also does not make an outdated contract flowdown matrix any less of a risk.
Where Manufacturers Can Get Into Trouble
The primary risk is not that manufacturers will assume CMMC is gone permanently. The greater risk is that the suspension creates a broader impression that compliance pressure is easing.
That impression can affect priorities. Audit preparation may be delayed. Flowdown reviews may slip. Teams may postpone updating the documents they use to track DFARS requirements because cybersecurity no longer feels as urgent.
Meanwhile, CAS, DCAA, and CPSR requirements remain fully in effect.
The DoD has said it wants to reduce unnecessary administrative work while continuing to hold contractors accountable for results. That does not mean oversight is going away. It may instead become more focused on whether contractors can demonstrate meaningful compliance, not simply whether they completed the paperwork.
That is exactly why accurate, current FAR and DFARS documentation remains essential.
The Practical Impact
Your overall compliance workload did not get smaller this week.
One specific part of it, third-party CMMC certification, received a 60-day reprieve while the task force determines what comes next. All your other contract-specific obligations continue on the same timelines they followed before the announcement.
Those requirements still determine whether your organization can pass a DCAA audit, successfully complete a CPSR, and keep its CAS disclosure statement current.
Where GovComply Fits
GovComply was never built as a CMMC tool, and this news is a good illustration of why that scope boundary matters.
GovComply reviews prime contracts clause by clause, determines which FAR and DFARS requirements must flow down, and tracks CAS and CPSR obligations across your active contract portfolio. It also helps your team produce audit-ready evidence when it is needed, not only when a regulatory headline creates urgency.
That work does not stop because a cybersecurity certification program is under review.
If your compliance approach depends on manually monitoring regulatory news to determine which requirements still apply, the CMMC suspension may point to a larger issue. Your organization needs a system that keeps its FAR, DFARS, and CAS obligations current, regardless of what else is changing in Washington.
GovComply.ai is compliance software built specifically for defense and aerospace manufacturers holding government contracts.
Sources
- U.S. Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” July 13, 2026
- Federal News Network, “Pentagon Suspends CMMC Phase Two Requirements, Launches Review of Program,” July 13, 2026