Oregon APEX Accelerator

DoW Suspends CMMC Phase II Requirements

Date: 07/20/2026

The U.S. Department of War (DoW) has announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements which were previously scheduled to take effect on November 10, 2026.

Please note that CMMC Level 1 self-attestation to the 15 controls, and Level 2 self-assessment against the NIST 800-171 controls remain in effect. The suspension only applies to the third-party (C3PAO) certification requirements under Phase 2.

This decision does not remove the obligation for contractors to protect federal information. Defense contractors and subcontractors must continue to safeguard covered defense information (CDI) in accordance with DFARS clause 252.204-7012 and all applicable contract requirements. 

Ends 08/30/2026 05:00 PM