The U.S. Department of Defense has suspended CMMC Phase II requirements as part of a broader acquisition reform effort, delaying the planned expansion of mandatory third-party cybersecurity assessments for many defense contractors. The pause does not remove existing obligations: contractors still face NIST SP 800-171 Rev. 2 self-assessments, DFARS 252.204-7012 requirements, and annual executive affirmations submitted through SPRS, while prime-contractor scrutiny, possible government spot audits, and persistent nation-state threats continue to drive cyber risk.
At the same time, industry reporting warns that those executive affirmations have become a growing legal and governance exposure because controlled unclassified information (CUI) often spreads beyond initially scoped systems into contracts, resumes, email, collaboration platforms, schedules, and supplier environments without clear labeling or tracking. Under 32 CFR Part 170, inaccurate visibility into where CUI resides can make signed CMMC attestations unreliable and increase potential False Claims Act exposure, especially when subcontractors handle CUI unknowingly, leaving contractors under pressure to build defensible processes to identify, monitor, document, and validate CUI handling even as the framework is revised.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
In July 2026, the U.S. Department of Defense suspended CMMC Phase II requirements, pausing the expected expansion of mandatory third-party cybersecurity audits for many defense contractors. The cited analysis says the move reflects structural reform under the Pentagon’s Acquisition Transformation System rather than a cancellation of cybersecurity obligations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
govconwire.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.