CMMC Phase 2 Suspension Isn’t a Reason to Stop Preparing
The CMMC Phase 2 suspension gives defense contractors more time to prepare, not a reason to stop preparing. Here are some reminders and recommendations for the meantime.
The Cybersecurity Maturity Model Certification (CMMC) program was headed toward an important milestone on November 10, 2026. That was when Phase 2, also referred to as Phase I, was scheduled to begin, expanding the use of third-party CMMC assessments for defense contractors handling Controlled Unclassified Information (CUI).
As you may have already learned, that deadline has changed.
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of CMMC Phase II requirements, including the transition that had been scheduled for November 10. The DoW also suspended pending and future CMMC implementation milestones while it reviews the program.
The suspension does not, however, eliminate CMMC, cybersecurity requirements, or contractors’ responsibility to protect federal information. For organizations doing business with the DoW, view the pause as additional time to strengthen security controls, address gaps, and prepare for whatever comes next.
*Organizations should consult their compliance, contracting, or legal authorities to determine the requirements applicable to individual contracts and environments.
CMMC Phase 2 Is Suspended, Not Cybersecurity Requirements
CMMC is designed to provide the DoW with greater assurance that defense contractors and subcontractors have implemented required safeguards for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
Phase 1 began November 10, 2025. Phase 2 was scheduled to begin one year later and would have expanded the use of Level 2 (NIST 800-171) certification assessments performed by Certified Third-Party Assessment Organizations (C3PAOs).
Instead, the DoW established a CMMC Reform Task Force to conduct a top-to-bottom review of the program. The DoW cited compliance costs and administrative burdens, particularly for smaller and nontraditional members of the Defense Industrial Base (DIB), while emphasizing that cybersecurity and operational resilience remain priorities.
Most importantly for contractors, CMMC implementation is currently paused in Phase 1.
CMMC Phase 1 Self-Assessments Remain in Effect
The July announcement explicitly states that Phase 1 self-assessment requirements remain in place.
During the interim period, DoW says it will enforce cybersecurity compliance with NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments. Defense contractors and subcontractors also remain contractually obligated to safeguard covered defense information in accordance with DFARS 252.204-7012.
In other words, the Phase 2 suspension should not be viewed as a compliance holiday.
Use the CMMC Pause to Strengthen Security
The additional time provides contractors with an opportunity to address the underlying security work that CMMC is intended to measure.
Depending on applicable requirements, organizations can continue to:
- Identify systems that store, process, or transmit FCI and CUI
- Assess security gaps against applicable NIST SP 800-171 requirements
- Update System Security Plans (SSPs) and other security documentation
- Remediate deficiencies and manage permitted Plans of Action and Milestones (POA&Ms)
- Strengthen endpoint monitoring and protection
- Implement file integrity monitoring (FIM)
- Improve vulnerability and CVE detection
- Centralize security and audit logging
- Maintain records and evidence demonstrating that controls are operating
That work can improve security today while making an organization better prepared if third-party assessments or revised certification requirements return following the DoW review.
Discover how Atomicorp can help.
CMMC Compliance Across Mixed IT Environments
Microsoft technologies play an important role in many defense contractor environments. Intune, Entra ID, Defender, Microsoft 365, Sentinel, Azure, and related services provide identity, endpoint, cloud, productivity, and security capabilities.
But CMMC does not require an all-Microsoft environment. Contractors may also need to account for Linux and other non-Windows servers, cloud workloads, VMs, containers, network infrastructure, legacy Unix systems, operational technology (OT), and isolated or air-gapped systems within their CMMC assessment scope.
This raises an important question when preparing for CMMC: Do you have adequate security visibility and monitoring across all systems within your compliance scope?
Strengthen CMMC Readiness with Atomic OSSEC
Atomic OSSEC is a multiplatform endpoint detection and response (EDR) and cloud workload protection platform (CWPP) that helps organizations monitor and protect diverse IT and OT environments.
Capabilities that can support applicable CMMC and NIST SP 800-171 security requirements include:
- Endpoint detection and response (EDR)
- File integrity monitoring (FIM)
- Vulnerability and CVE detection
- Security and compliance monitoring
- Centralized audit and security logging
- Active and automated response
- Agent-based and agentless monitoring
- Support for current, legacy, end-of-life, isolated, and air-gapped systems
Atomic OSSEC supports Windows, Linux, AIX, Oracle Linux, Oracle Solaris, HP-UX, and other platforms. Integrations with Microsoft Intune, Microsoft Entra ID, Microsoft 365, and Azure also enable organizations to combine their Microsoft infrastructure with Atomic OSSEC security monitoring across heterogeneous environments.
Prepare for CMMC by Improving Security Now
The eventual outcome of the CMMC review remains to be seen. Phase 2 requirements could change, and organizations should follow DoW guidance rather than assume the previously planned implementation schedule will simply resume.
What has not changed is the need to protect FCI and CUI.
Organizations can use the Phase 2 suspension to strengthen their security posture, improve visibility, remediate deficiencies, and establish the monitoring and evidence needed to demonstrate that required controls are actually working.
Got a legacy or mixed-platform environment that must meet CMMC and NIST SP 800-171 security requirements?
Learn more about Atomic OSSEC and how Atomicorp can help extend endpoint security and continuous monitoring across current, legacy, and end-of-life systems.
Request an Atomicorp product demonstration.
Blog Q&A
What is CMMC Phase 2, and what is the difference between CMMC Phase 2 and CMMC Level 2?
CMMC Phase 2 was the second stage of the Department of War’s phased implementation of the Cybersecurity Maturity Model Certification (CMMC) program. Originally scheduled to begin November 10, 2026, Phase 2 would have expanded requirements for CMMC Level 2 third-party assessments performed by authorized CMMC Third-Party Assessment Organizations (C3PAOs) for applicable defense contracts.
CMMC Phase 2 should not be confused with CMMC Level 2. Phase 2 refers to the program’s implementation schedule, while Level 2 defines cybersecurity requirements for protecting Controlled Unclassified Information (CUI). CMMC Level 2 incorporates the 110 security requirements of NIST SP 800-171 Revision 2.
On July 13, 2026, the DoW suspended CMMC Phase 2 and pending and future implementation milestones while it reviews and reforms the program. CMMC Phase 1 remains in effect, including applicable Level 1 and Level 2 self-assessment requirements. Contractors should therefore continue protecting FCI and CUI, meeting applicable NIST SP 800-171 requirements, and maintaining required cybersecurity controls and assessment evidence.
