The suspension halts the third-party assessment requirement for defense contractors handling Controlled Unclassified Information (CUI), but cybersecurity obligations and potential FCA exposure remain.
By Anne W. Robinson, Kyle R. Jefcoat, Dean W. Baxtresser, Morgan L. Maddoux, Drew Diachenko, Chris Caulder, Ysa Gomez-Gonzalez, and Pascal Jakowec
In a July 13, 2026, memorandum (CMMC Reform Memorandum) and press release, the US Department of Defense (Department of War) suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, pausing the requirement that contractors handling CUI obtain third-party assessments by November 10, 2026. DOD also established a CMMC Reform Task Force to conduct a 60-day review of the CMMC program, synthesize industry feedback, and issue recommendations.
Importantly, the suspension of government-required third-party assessments as a prerequisite to obtaining new contracts does not suspend the existing cybersecurity requirements for government contractors. Defense contractors must continue to protect CUI, implement all NIST SP 800-171 Rev. 2 controls to achieve a passing CMMC Level 2 score, and flow down applicable contractual requirements to subcontractors. Self-assessment certifications, Supplier Performance Risk Systems (SPRS) score submission, and other affirmations of compliance remain an area of potential exposure for contractors, particularly in light of the US Department of Justice’s (DOJ’s) continued use of the False Claims Act (FCA) to enforce cybersecurity requirements pursuant to its Civil Cyber-Fraud Initiative.