CBIZ

Insights. Applied. Integrated solutions that turn strategy into action.

  • Article
August 04, 2026

What is the Current State of Cyber Compliance Readiness for the Defense Industrial Base (DIB)? CMMC Phase 2 Suspension Update

By Jeremy Price, Managing Director Linkedin
What is the Current State of Cyber Compliance Readiness for the Defense Industrial Base (DIB)? CMMC Phase 2 Suspension Update
Table of Contents

On July 13, 2026, the US Department of War (DoW) announced the suspension of upcoming Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements, which were scheduled to take effect on November 10, 2026. This puts the need for third-party CMMC Level 2 compliance audits on hold pending a 60-day review period, effective immediately.

All CMMC Phase 1 compliance obligations remain in effect, including compliance self-assessment and attestation, posting compliance scores to the DoW’s Supplier Performance Risk System (SPRS) database, and DFARS 252.204-7012 requirements in existing DoW contracts.

What does this latest CMMC postponement mean for US defense industrial base (DIB) companies—especially contractors that handle controlled unclassified information (CUI)? And what should DIB orgs focus on now for cybersecurity compliance? This article reviews the essential facts and considerations for business and technical leaders.

Key takeaways

  • The DoW’s July 13, 2026 announcement suspends the transition from CMMC Phase 1 to CMMC Phase 2 requirements, along with all future CMMC milestones.
  • The entire CMMC program is now under a 60-day “top-to-bottom” review by a CMMC Reform Task Force.
  • All CMMC Phase 1 requirements remain in force.
  • Reasons for the suspension include prohibitive compliance cost and bureaucratic burdens for SMBs, plus a mandate to align CMMC with the Acquisition Transformation System directives designed to streamline participation in the DIB.
  • CMMC Level 2 certifications remain valuable for demonstrating supply chain trustworthiness to prime contractors

What does the DoW’s July 13 announcement mean for DIB orgs?

The DoW’s July 13, 2026 announcement suspends the transition from CMMC Phase 1 to CMMC Phase 2 requirements. It also suspends all pending and future CMMC milestones.

The entire CMMC program is now under “top-to-bottom” review by a CMMC Reform Task Force, with a plan to deliver recommendations to the DoW CIO within 60 days.

Meanwhile, the CMMC Phase 1 requirements remain active, including self-assessment of NIST SP 800-171 compliance for most companies that handle CUI, plus government-led assessments at the DoW’s discretion.

DIB orgs with a DFARS clause 252.204-7012 in their contract should view the Phase 2 suspension as putting the impending CMMC certification regime on hold—not the underlying NIST SP 800-171 control requirements.

CMMC does not mandate new cybersecurity controls for the DIB. It is a compliance verification/enforcement mechanism for requirements that have been in place since December 2017. The suspension changes nothing about a firm’s current cybersecurity compliance obligations with the DoW.

Why did the DoW suspend the CMMC Phase 2 rollout?

The DoW suspended the CMMC Phase 2 rollout mainly to delay the independent compliance assessment requirement for DIB orgs that handle CUI. Reasons cited include:

  • Prohibitive compliance costs for small and nontraditional businesses that are critical to the defense supply chain.
  • Onerous bureaucratic demands that add to the overall compliance burden, especially for SMBs.
  • A mandate to align the CMMC program with Secretary of War Pete Hegseth’s Acquisition Transformation System directives, which seek to lower barriers to entry for defense suppliers.

The goal of the 60-day review period by the CMMC Reform Task Force is to develop recommendations for scaling up CMMC without creating barriers to SMB participation in DoW contracts.

Another factor in pausing CMMC has been the perceived or anticipated third-party (C3PAO) assessment bandwidth constraints, along with a very slow certification rate. As of June 2026, only about 1,700 companies among the 80,000-plus that were slated to obtain an independent CMMC Level 2 compliance certification had done so—a completion rate of under 2%.

Despite being subject to a compliance self-attestation protocol for almost ten years, many defense subcontractors still have not implemented basic cybersecurity controls while declaring that they have done so. For example, more than 50% of DIB companies that hold CUI report not having a complete system security plan (SSP), which has been a contractual requirement since December 2017.

Over 80% of DIB orgs have already experienced one or more significant cyber incidents as nation state actors and other cybercriminals are increasingly targeting them.

Why is there a cyber compliance “readiness gap” across the DIB?

Cybersecurity professionals and third-party auditors report that about one-third of organizations seeking CMMC Level 2 certification are failing to meet Phase 1 pre-audit readiness requirements. Why are DIB orgs struggling with CMMC Level 2 compliance when they have been contractually agreeing to achieve it since 2017?

Widely reported shortcomings that render companies unprepared for a CMMC Level 2 or NIST SP 800-171 compliance audit include:

  • SSPs that did not line up with real-world cybersecurity controls/operations.
  • Failure to include Security Protection Assets within the CMMC/NIST 800-171 scope.
  • Other scoping documentation failures (e.g., asset inventories that are inconsistent with the network diagram) indicating that scoping was not performed in alignment with the DoW’s CMMC Level 2 Scoping Guide.
  • Pre-audit evidence packages that failed to meet basic standards for verifying compliance.
  • A view of the Phase 1 pre-audit process as a “dress rehearsal” for identifying compliance gaps rather than the validation of successful compliance efforts.

Why did so many organizations seeking CMMC Level 2 certification incorrectly believe they were ready for a third-party audit? A key factor may be that CMMC Level 2 compliance is notably harder than other cybersecurity frameworks like ISO 27001 and SOC 2. Most businesses need 6 to 12 months or more to fully implement the 110 NIST SP 800-171 controls to protect CUI.

What should DIB orgs focus on for cyber compliance now?

Defense suppliers that handle CUI remain subject to the same NIST SP 800-171 Rev. 2 compliance requirements that have been in place since December 2017. In the July 13 announcement, the DoW states that DIB orgs “… remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012.”

The critical requirements in DFARS 7012 include:

  • Demonstrating a NIST SP 800-171 compliant cybersecurity posture as “adequate security” to protect CUI.
  • Reporting qualifying cyber incidents within 72 hours through the updated Incident Collection Format (ICF) Portal process.
  • Ensuring that cloud services interacting with CUI in your environment meet FedRAMP Moderate requirements.
  • Ensuring that all your vendors and subcontractors in scope for CUI also comply with DFARS 7012 (aka “flowdown”).

DFARS 7019 and DFARS 7020 clauses also remain in force wherever they appear in DoW contracts. These specify requirements for self-assessment, posting a current compliance score to SPRS, and providing access to government assessors to audit your cybersecurity posture on request.

Importantly, the recent announcement changes nothing about current self-assessment responsibilities defined in CMMC Phase 1:

  • DFARS 7019 mandates that contractors maintain a current (within three years) NIST 800-171 compliance self-assessment score in SPRS to be considered for contract award.
  • The obligation for annual affirmation of that score by a senior company official also remains in force.

Another major driver for DIB orgs to maintain CMMC Level 2 certification initiatives is that the “Big Five” defense prime contractors (Lockheed Martin, Boeing, Northrop Grumman, General Dynamics, and RTX) continue to require CMMC Level 2 compliance or certification for subcontractors independent of the CMMC Phase 2 suspension (see below).

A business that is still working towards NIST SP 800-171 compliance or is maintaining an established compliance posture should continue to close gaps, address new risks, update program documentation, and/or track controls. A System Security Plan (SSP), risk assessments, and progress against any Plans of Action and Milestones (POA&Ms) on file in SPRS remain critical to demonstrating their compliance posture upon request from the DoW, primes, or other stakeholders.

If your company has DFARS 7019/7020 clauses in its contracts and a compliance score on file in SPRS, now is a good time to confirm that score is valid and current. Make sure your supporting documentation strongly corroborates your score.

What are the CMMC Phase 1 requirements?

CMMC Phase 1 requires DIB contractors to complete CMMC Level 1 or Level 2 self-assessments and to register their scores in the SPRS database as a prerequisite for new contract awards:

  • If your business processes, stores, and/or transmits CUI on its own systems, you must complete a CMMC Level 2 self-assessment against the 110 controls in NIST SP 800-171 Rev. 2, as required by DFARS 7012. An affirmation by a senior company official is also required.
  • If your business handles only federal contract information (FCI) and not CUI, your business must complete a compliance self-assessment against the 15 “basic cyber hygiene” controls specified in FAR clause 52.204-21. Again, an affirmation by a senior company official is required.
  • DoW program managers and contracting officers still have the power to require an independent Level 2 certification audit with a C3PAO as a condition of contract award or “at the time of any option period exercise” in cases where the contract’s risk profile warrants it.

If post-assessment remediation is required, firms seeking compliance with CMMC Level 2 can make limited use of POA&Ms. POA&Ms are not applicable with CMMC Level 1 self-assessments.

Can primes still require CMMC Level 2 certification while Phase 2 is suspended?

Prime contractors can—and are—still contractually requiring CMMC Level 2 third-party certification audits, a minimum SPRS score, or specific evidence of NIST SP 800-171 compliance (e.g., Exostar’s Cybersecurity Compliance and Risk Assessment questionnaire) independent of the DoW.

The major primes have been focused on building secure supply chains to meet their own CMMC flowdown requirements per 32 CFR 170.23. They will likely continue to do so as a function of their own risk management. If a subcontractor suffers a data breach and did not have proper controls in place, the prime faces reputational, financial, and legal exposure.

If your business has legally binding agreements with one or more primes, the DoW’s CMMC suspension does not impact these. You can either comply, renegotiate your agreement, or cancel the contract.

A potential renegotiation option in the current situation might be to conduct a third-party mock assessment of NIST 800-171 Rev. 2 compliance and offer a report as evidence. A prime may be more concerned with confirmation of a robust cybersecurity posture than with a CMMC certificate.

We have ITAR and EAR data—does the CMMC suspension impact these?

The International Traffic in Arms Regulations (ITAR) and Export Administration Regulations (EAR) are US federal laws that control the export of sensitive technologies, including software, to protect it from unauthorized use by non-US entities:

  • ITAR regulates sharing warfighting technology, services, and associated technical information with foreign entities both outside and within US borders. It is overseen by the US Department of State and references the United States Munitions List (USML).
  • EAR regulates “dual-use” and commercial products and services that have both military and non-military applications (e.g., nuclear technology, specialized electronics). It is overseen by the US Department of Commerce and references the Commerce Control List (CCL).

ITAR and EAR are designed to protect US national security, but are independent of the DoW. While their presence in your environment may strongly impact your CUI enclave or architecture, they are not directly related to CMMC and are unaffected by its suspension. Associated data protection requirements like US persons only access, US-only data hosting, NOFORN handling procedures, or other CUI Specified dissemination controls or export control mandates remain in effect.

If your business needs to meet the strict cybersecurity requirements associated with safeguarding ITAR and/or EAR data—as many DIB orgs do—then your compliance obligations are likely to go beyond what NIST SP 800-171 Rev. 2 dictates for protecting basic CUI.

ITAR and EAR violations are serious offenses, and you cannot relax those controls. If your export-controlled data is also considered CUI or covered defense information (CDI) under your DoW contracts, then DFARS 7012 and the associated NIST SP 800-171 controls continue to apply to it.

Do we still need to worry about the False Claims Act?

With CMMC Level 2 third-party assessment requirements suspended, do DIB orgs still need to worry about US Department of Justice (DoJ) prosecution under the False Claims Act if they misrepresent their cyber compliance status?

False Claims Act concerns could be greater than ever now that self-assessment and executive attestation of NIST SP 800-171 compliance is once again the DoW’s main mechanism for enforcing its cybersecurity requirements for CUI.

An accurate self-assessment score in SPRS, along with honest annual affirmations and thorough documentation to back it all up, are critical to contract awards and to nullify potentially devastating legal, financial, and reputational risks.

What if we have a DFARS 7021 clause in our current contract?

The DFARS 252.204-7021 clause requires contractors to have a CMMC certification at the level specified in their contract at the time the contract is awarded, and to maintain the required CMMC level (1 through 3) for the contract’s full duration. 

The CMMC program suspension effectively blocks inclusion of DFARS 7021 in new DoW contracts and solicitations during the 60-day review period.

But for contracts already in effect, a DFARS 7021 clause remains legally binding unless modified or renegotiated. This makes it essential due diligence to inquire officially with your contracting officer about how the CMMC suspension applies in your specific case.

What’s next?

Is your business in compliance with the DoW cybersecurity requirements your current or prospective contracts specify? Are you able to post, justify, and attest to a competitive compliance score in SPRS?

CBIZ Technology offers a full slate of advisory and consulting services for DIB companies. No matter where your cybersecurity posture stands today, our assessment, implementation, and remediation support will help to ensure you efficiently meet all cyber compliance obligations necessary for participating in DoW contracts.

Contact us today to schedule a conversation with a defense industry cybersecurity and compliance expert.

© Copyright CBIZ, Inc. All rights reserved. Use of the material contained herein without the express written consent of the firms is prohibited by law. This publication is distributed with the understanding that CBIZ is not rendering legal, accounting or other professional advice. The reader is advised to contact a tax professional prior to taking any action based upon this information. CBIZ assumes no liability whatsoever in connection with the use of this information and assumes no obligation to inform the reader of any changes in tax laws or other factors that could affect the information contained herein. Material contained in this publication is informational and promotional in nature and not intended to be specific financial, tax or consulting advice. Readers are advised to seek professional consultation regarding circumstances affecting their organization.

“CBIZ” is the brand name under which CBIZ CPAs P.C. and CBIZ, Inc. and its subsidiaries, including CBIZ Advisors, LLC, provide professional services. CBIZ CPAs P.C. and CBIZ, Inc. (and its subsidiaries) practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CBIZ CPAs P.C. is a licensed independent CPA firm that provides attest services to its clients. CBIZ, Inc. and its subsidiary entities provide tax, advisory, and consulting services to their clients. CBIZ, Inc. and its subsidiary entities are not licensed CPA firms and, therefore, cannot provide attest services.

Let’s Connect

Our team is here to help. Whether you’re looking for business solutions, financial strategies, or industry insights, we’re ready to collaborate. Fill out the form, and we’ll be in touch soon.

This field is for validation purposes and should be left unchanged.