Is CMMC Going Away? Here's What Defense Contractors Need to Know
On July 13, 2026, the Department of War (DoW) announced an immediate 60-day pause of CMMC Phase 2 implementation. Originally scheduled to take effect on November 10, Phase 2 would mark the beginning of third-party assessment requirements in DoW solicitations containing CUI. The pause has resulted in speculation regarding the future of the CMMC program and has left some contractors wondering, is CMMC going away? The short answer to this question: No. While we may see some assessment requirements change, the underlying controls and requirements will remain the same.
What Happened, why a Pause?
The DoW released a statement announcing the suspension of CMMC Phase 2 in order to initiate a 60-day review of the program. The stated purpose is to "prioritize speed to capability" and "lower barriers to small, medium, and non-traditional businesses". During this pause, the Department's CIO, Kristin Davies, is establishing a CMMC Reform Task Force to address these concerns. You can read the entirety of the DoW's statement here.
So, is CMMC Going Away?
It's important to understand what CMMC is and what it is not. CMMC is a framework for assessing and verifying whether or not defense contractors have implemented applicable cybersecurity requirements, specifically those found in NIST SP 800-171 Rev. 2. CMMC did not create those underlying requirements, they have existed since Rev. 2's publication in 2020.
For many defense contractors handling Controlled Unclassified Information (CUI), the obligation to implement NIST SP 800-171 already exists through DFARS 252.204-7012. Related clauses, including DFARS 252.204-7019 and 252.204-7020, establish requirements associated with NIST SP 800-171 assessments, SPRS scores, and DoD access for assessment purposes.
That means a pause or potential change to CMMC assessment requirements does not eliminate the cybersecurity requirements contractors are already obligated to meet. Even if the DoW ultimately changes how CMMC assessments are structured or when third-party certification is required, defense contractors should not interpret the current pause as a pause in their underlying cybersecurity responsibilities.
What Hasn't Changed for Defense Contractors?
While the CMMC Phase 2 rollout is paused, many of the cybersecurity obligations already included in defense contracts have not changed. Contractors should continue to review the specific clauses in their contracts and understand the requirements that apply to their organization.
For contractors handling CUI, DFARS 252.204-7012 requirements remain in effect, including the obligation to provide adequate security for covered defense information and implement applicable NIST SP 800-171 requirements. Phase 1 CMMC self-assessment requirements also remain in place.
Why NIST SP 800-171 Still Matters
Regardless of what happens with CMMC, NIST SP 800-171 still remains central to protecting CUI within the Defense Industrial Base (DIB). For contractors subject to DFARS 252.204-7012, these requirements exist and are an obligation today -- not something that begins when a CMMC assessment is scheduled.
The requirements are designed to help organizations establish and maintain safeguards for CUI across areas such as access control, incident response, system security, configuration management, and risk assessment. Those protections matter whether compliance is being validated through a self-assessment, a DoD assessment, or a CMMC third-party assessment.
What Defense Contractors Should Do Now About the Pause
This pause is not an excuse to neglect compliance efforts. Defense contractors should stay the course and continue to implement applicable NIST SP 800-171 requirements. Failure to do so could result in a false claim, leading to significant financial, legal, and reputational damage. Additionally, the DoW clarified that CMMC Phase 1 obligations are not under suspension stating that "this action does not eliminate the requirement for companies to protect federal data. All defense contractors and subcontractors remain contractually obligated to safeguard covered defense information in accordance with DFARS clause 252.204-7012."
CorpInfoTech recommends that defense contractors stay the course. Regardless of changes made to the CMMC program, your organization will still need to comply with existing NIST 800-171 requirements.
How Can CorpInfoTech Help?
CMMC requirements may evolve, but defense contractors still need a clear, practical approach to meeting and maintaining their cybersecurity and compliance obligations. CorpInfoTech helps organizations navigate that process through our Define – Assess – Implement – Validate – Maintain roadmap.
- Define – Understand your requirements, CUI environment, scope, and compliance objectives.
- Assess – Evaluate your current environment against applicable NIST SP 800-171 and CMMC requirements and identify gaps.
- Implement – Remediate gaps and put the necessary security controls, technology, policies, and processes in place.
- Validate – Confirm controls are operating as intended and prepare the organization and supporting evidence for assessment.
- Maintain – Continuously manage, monitor, and improve the environment to support ongoing compliance.
CorpInfoTech supports both the strategy and execution behind this roadmap. Our goal is not simply to get you through a CMMC assessment, but to help you build and maintain a secure, compliant environment that supports your defense contracts today and prepares you for whatever comes next.
Key Takeaways
-
CMMC is not going away, but the Phase 2 assessment requirements may change as the DoW reviews the program.
-
The CMMC pause does not pause your existing cybersecurity obligations.
-
NIST SP 800-171 requirements remain applicable for defense contractors handling CUI and subject to DFARS 252.204-7012.
-
Existing DFARS requirements remain in effect, including applicable assessment and SPRS obligations under DFARS 252.204-7019 and 252.204-7020.
-
Defense contractors should stay the course by continuing to implement, document, and maintain their required security controls.
CorpInfoTech, a Managed Service Provider (MSP) with over 25 years in the SMB space, is a trusted partner for business pursuing compliance and cybersecurity. We are a CMMC Level 2 certified MSP and a Cyber AB Registered Provider Organization (RPO). Also, as the first CIS accredited organization, we help organizations implement the CIS controls as it pertains to CMMC and your overall cybersecurity posture. CorpInfoTech is your trusted partner for secure, compliant growth in every changing digital landscape.

