The Department of Defense has suspended the planned transition to CMMC Phase 2, pausing third-party compliance-attestation requirements while it reviews the Cybersecurity Maturity Model Certification program. The department received more than 1,100 responses totaling over 10,000 pages of feedback, with many commenters—particularly small and mid-sized defense contractors—describing the requirements as disproportionately burdensome. During the review, contractors are expected to demonstrate compliance with NIST SP 800-171 Rev. 2 through self-assessments and selected government-led assessments; DoD has also halted CMMC waivers for 60 days.
DoD CIO Kirsten Davies said the redesigned program should emphasize continuous cybersecurity and resilience, including protections for manufacturers' operational technology, rather than point-in-time compliance checks. Industry feedback also highlighted inconsistent government handling and marking of controlled unclassified information as a supply-chain challenge. Legal commentators warned that suspending requirements through memoranda may be vulnerable because the underlying CMMC and DFARS rules remain in force, and that restoring self-attestation removes independent validation intended to counter inaccurate contractor reporting amid continued state-sponsored espionage against the defense industrial base.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
Two DoD memoranda directed contracting activities to accept contractor self-assessments during a 60-day review, remove higher-tier assessment requirements from active solicitations and later contract modifications, and bar CMMC waivers. DoD expected to use NIST SP 800-171 Revision 2 and selected government-led assessments during the pause.
DoD CIO Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey suspended the planned transition to CMMC Phase 2, which had been scheduled for November 2026. The suspension paused requirements including third-party compliance attestation.
CISA and allied cyber authorities warned that Chinese state-sponsored operations had industrialized and integrated intelligence, military, and civilian security services into a continuous exfiltration effort.
The companion CMMC acquisition rule became effective, adding a contract clause and solicitation provision to the Defense Federal Acquisition Regulation Supplement.
The CMMC Program rule took effect, establishing assessment levels, a third-party assessor ecosystem, annual affirmations, and case-by-case waiver authority.
DoD began accepting applications for its Cyber Registered Apprenticeship Program, a skills-based hiring initiative for cybersecurity talent. The first listing closed four days early after receiving more than 15,000 applications, and DoD planned additional opportunities.
Industry stakeholders and defense leaders identified inconsistent government designation and marking of controlled unclassified information as a major supply-chain challenge. Davies also identified cyber resilience for manufacturers' operational technology as a gap not addressed by the prior CMMC framework.
DoD received more than 1,100 responses totaling more than 10,000 pages in response to its CMMC reform request for information. More than half of respondents supported the Phase 2 pause and reform effort, while many cited disproportionate burdens on small and medium-sized contractors.
The Department of Defense established a CMMC Reform Task Force to review the full program and issued a request for information seeking feedback from contractors affected by CMMC regulations.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcedefensescoop.com
Open sourcelawfaremedia.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.