Pentagon Suspends CMMC Phase 2 Requirements and Launches Review of Cybersecurity Certification Program - WilmerHale
Pentagon suspends CMMC Phase 2 requirements and launches review of cybersecurity certification program.
Aforeworn detected this change in the Export Controls & ITAR (DDTC / BIS / DFARS) space on July 20, 2026 and published this briefing so affected operators are forewarned rather than caught off guard. It is rated High urgency. Defense contractors and subcontractors subject to DFARS cybersecurity requirements should confirm how it applies to their specific situation before acting. There is a time constraint attached: Ongoing; no immediate deadline but contractors should stay informed of review outcomes expected within months.. Acting after that point can mean penalties, a lapsed licence, or lost eligibility — exactly the kind of surprise Aforeworn exists to prevent. Aforeworn monitors Export Controls & ITAR (DDTC / BIS / DFARS) continuously and turns every detected change into a plain-English briefing like this one, so you always know first. Forewarned is forearmed.
What changed
CMMC Phase 2 requirements are suspended; DoD is reviewing the certification program. Contractors no longer need to achieve CMMC certification for new contracts during the review period.
Who it affects
Defense contractors and subcontractors subject to DFARS cybersecurity requirements
What you must do
Monitor DoD announcements for updated CMMC timelines and requirements. Continue to implement NIST SP 800-171 controls as required by DFARS clause 252.204-7012.
Deadline
Ongoing; no immediate deadline but contractors should stay informed of review outcomes expected within months.
Never miss a change like this again
Aforeworn watches Export Controls & ITAR (DDTC / BIS / DFARS) around the clock and alerts you the moment a rule moves — with a plain-English brief on what to do.
Start your free trialRelated changes in Export Controls & ITAR (DDTC / BIS / DFARS)
- Years in the Making, Suspended in a Day: DoD/W Halts CMMC Phase II but Keeps Baseline Cybersecurity Obligations - regulatoryoversight.com
- BIS Updates Connected Vehicle Rule Authorizations: Amended Limited Use Authorization and New Approved Supplier Registry - ArentFox Schiff
- New Bill: Senator Kevin Cramer introduces S. 4835: Bureau of Industry and Security License Administration Enhancement Act - Quiver Quantitative
- New Bill: Senator Marsha Blackburn introduces S. 4840: Export Control Enforcement and Enhancement Act - Quiver Quantitative
- US-CONGRESS HR4215: International Traffic in Arms Regulations Licensing Reform Act