CMMC Phase II Suspension and Reform Task Force
The Department of War (DoW) is pausing the rollout of the Phase 2 implementation of CMMC while allowing Level 1 or Level 2 self-assessments to continue to be included in procurement requests. The cybersecurity NIST SP 800-171 Rev 2* requirements outlined in DFARS 252.204-7012 remain in effect. Cybersecurity compliance will continue to be enforced through self-assessments and select government-led assessments. See the press release here: https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/ and news coverage: https://defensescoop.com/2026/07/13/dod-halts-cmmc-cybersecurity-requirements-phase-2/
DoW is seeking feedback from industry by establishing a Cybersecurity Maturity Model Certification (CMMC) Reform Task Force to gather feedback about reducing compliance costs and administrative burdens while protecting federal data and strengthening operational resilience. A Request for Information (RFI), distributed on July 13th, seeks responses before August 14th to help shape the future of cybersecurity and the operational resilience of the Defense Industrial Base (DIB). To see more about how to respond to the RFI, view the announcement on SAM.gov: https://sam.gov/workspace/contract/opp/89ef9bfb0834473791e991c712698d94/view
For more information on how to comply with CMMC and upload your SPRS Score (which still matters), leverage Project Spectrum training at https://www.projectspectrum.io/ and check out the DoW Chief Information Officer website for additional resources: https://dowcio.war.gov/
Footnote:
*NIST SP 800-171 Rev 3 will eventually be adopted into DFARS – learn more here: https://www.governmentcontractslaw.com/2025/04/the-prestige-dod-unveils-nist-sp-800-171-revision-3-organizationally-defined-parameters/
Posted in: News Feed, Uncategorized
Leave a Comment (0) →

