CMMC Phase II Is Paused, but Defense Contractors Face DFARS and FAR Cybersecurity Requirements | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


With Phase II third-party assessments suspended, Magna5 says contractors should verify current cybersecurity obligations, reporting, and evidence while the Department reviews the next phase of CMMC.

PITTSBURGH, Aug. 31, 2026 /PRNewswire/ — The Department of Defense (DoD) suspended Cybersecurity Maturity Model Certification (CMMC) Phase II requirements that had been scheduled for Nov. 10 while a reform task force reviews the program. CMMC Phase I remains in effect, including self-assessment requirements, and the Department says it will continue enforcing National Institute of Standards and Technology Special Publication (NIST SP) 800-171 Revision 2 through contractor self-assessments and selected government-led assessments.

For defense contractors, the announcement changes the timing of certain third-party assessments, not the need to keep CMMC readiness moving, according to Bill Osborne, Vice President of Defense Sector Services at Magna5, a national managed IT, cybersecurity, cloud, and compliance services provider.

“Some contractors may hear ‘pause’ and think they can postpone the program and their obligations,” said Osborne. “The Department has given the Defense Industrial Base more time to prepare, not permission to stop protecting the information their contracts require them to safeguard.”

The Pause Changes the Assessment Calendar

Level 1 self-assessments continue to cover 15 safeguarding requirements from Federal Acquisition Regulation clause 52.204-21 and are conducted annually. Level 2 self-assessments continue to measure implementation of the 110 security requirements in NIST SP 800-171 Rev. 2. Those assessments are conducted every three years, with annual affirmation, and the results are entered into the Supplier Performance Risk System (SPRS).

For contracts covered by Defense Federal Acquisition Regulation Supplement clause 252.204-7012, contracting officers must verify that a current NIST SP 800-171 DoD Assessment score is available in SPRS before certain awards, contract extensions, or option exercises. A paused third-party assessment schedule does not make an inaccurate or outdated score irrelevant.

“The assessment schedule changed. The underlying requirement to safeguard Controlled Unclassified Information (CUI) did not,” Osborne said. “Level 2 still measures the contractor against all 110 requirements, even if a third-party assessment is no longer arriving on the original timeline.”

Contractors Still Need to Keep Moving

The pause may affect when a contractor should engage a CMMC Third-Party Assessment Organization (C3PAO). Osborne said companies that are not already scheduled and fully prepared for an assessment may choose to wait while the Department reviews the program.

Contractors can use the interim period to:

  • Verify current SPRS scores and supporting evidence.
  • Confirm System Security Plans reflect the current environment.
  • Resolve unresolved CUI boundary questions.
  • Review subcontractor requirements and flow-down obligations.
  • Identify work that can continue while the Phase II timeline is under review.

“This may be a reason to delay the assessment, not the readiness work,” Osborne said. “If the documentation, score or scope is wrong today, contractors should use this window to fix it before those gaps show up in a contract requirement or assessment.”

A Pause Tests Whether the Program Is Real

A deadline-driven compliance project can lose momentum when a milestone moves. An operating cybersecurity program should continue maintaining evidence, assigning responsibility, addressing gaps, and budgeting for future assessment needs because the underlying contract and data-protection responsibilities remain.

The pause creates a practical test: can the organization keep its security plans, evidence, access decisions, and supplier requirements current without a near-term assessor driving the calendar? If not, the program may have been built around a certification event rather than the way the company handles sensitive defense information.

Contractors should also watch how NIST SP 800-171 Rev. 3 enters future federal contracting requirements. The DoD continues to use Rev. 2 for current CMMC obligations, while an upcoming FAR clause could require Rev. 3 for other federal contracts. Contractors working across multiple agencies may therefore need to manage both versions at once.

“The Defense Industrial Base has already seen multiple pauses and updates,” Osborne said. “When the program moves again, contractors should expect it to move quickly. The companies that keep their scope, evidence, and reporting current will be ready; the ones that wait for another deadline will always be rebuilding under pressure.”

About Magna5

Magna5 is a national managed IT, cybersecurity, cloud and compliance services provider serving small and mid-sized businesses, mid-market organizations, and regulated industries across the United States. The company helps organizations manage critical IT infrastructure, protect networks and data, support users, and strengthen operational resilience through 24/7/365 monitoring, managed security, cloud, backup, disaster recovery, and compliance support. Magna5 works with security- and uptime-conscious sectors including the Defense Industrial Base, healthcare, financial services, legal, manufacturing, education, construction, government, and professional services. For more information, visit www.magna5.com.

Sources:

  • Abrahams, J. C., Horan, J. G., Pashkoff, D. B., Francois, M. Y., & Young, A. F. (2026, July). DoD suspends CMMC Phase II third-party audit requirements. Faegre Drinker Biddle & Reath LLP. faegredrinker.com/en/insights/publications/2026/7/dod-suspends-cmmc-phase-ii-third-party-audit-requirements
  • National Institute of Standards and Technology. (2021). Protecting controlled unclassified information in nonfederal systems and organizations (Special Publication 800-171 Rev. 2). csrc.nist.gov/pubs/sp/800/171/r2/upd1/final
  • National Institute of Standards and Technology. (2024). Protecting controlled unclassified information in nonfederal systems and organizations (Special Publication 800-171 Rev. 3). csrc.nist.gov/pubs/sp/800/171/r3/final
  • U.S. Department of War. (2026, July 13). Forging the arsenal of freedom: Department of War suspends CMMC Phase II requirements. Office of Industrial Base Growth. business.defense.gov/Engage/News/Article/4542563/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/
  • U.S. Department of War, Office of the Chief Information Officer. (n.d.). About CMMC. Retrieved August 24, 2026, from dodcio.defense.gov/CMMC/About/

Media Inquiries:
Karla Jo Helms
JOTO PR™
727-777-4629
Jotopr.com

SOURCE Magna5

——————————————————-


Click Here For The Original Source.