GOVCON · ANALYSIS
Federal government suspends CMMC Phase II requirements while keeping Phase I in place
GLOBAL-TO-LOCAL WATCH

What changed
Loudoun Forward section: GovCon Word count: 326
Why this matters
This development has practical implications for Loudoun businesses and organizations in Government Contracting, Technology.
Operational impact
Readers can use the reporting and linked sources to evaluate timing, risk, cost, or market opportunity.
WHAT TO DO NEXT
- Review the linked sources and assess the practical impact on your organization.
Loudoun Forward section: GovCon
Word count: 326
The U.S. Department of War announced the immediate suspension of Cybersecurity Maturity Model Certification Phase II requirements on July 13, 2026. The Phase II requirements had been scheduled to take effect on November 10.
The department also suspended pending and future Phase II implementation milestones in its solicitations and contracts while it conducts a review of the CMMC program. Its announcement describes a 60-day study focused on the future of the program and on reducing compliance burdens while maintaining cybersecurity and operational resilience in the defense industrial base.
The suspension does not eliminate CMMC or every cybersecurity obligation connected to defense contracting. The Department of War’s Chief Information Officer states that all Phase I self-assessment requirements remain in place. The department also says it will continue enforcing compliance with NIST SP 800-171 Revision 2 through self-assessments and selected government-led assessments during the review period.
That distinction is important for Virginia and Loudoun defense contractors. A pause in the next implementation phase is not a general release from existing contractual clauses, current solicitation requirements or responsibilities for protecting controlled unclassified information. Contractors should review the terms of each contract and solicitation rather than changing a compliance program solely because of the Phase II announcement.
The department has established a CMMC reform task force and published materials related to the suspension and broader review. The official CMMC website provides the press release, implementation memoranda, the request for information and program resources.
The announcement applies to the federal rollout described by the department. It does not amend every private agreement or determine how a contracting officer will address a specific procurement outside the published federal instructions.
Businesses should preserve their cybersecurity records, continue any required self-assessments and verify current instructions through the Department of War’s official CMMC pages. This article does not determine what a particular contractor must do under a specific award. The controlling contract documents and current federal guidance remain the relevant sources for that decision.
Verified reference sources
- U.S. Department of War — Suspension of CMMC Phase II Requirements
- Department of War Chief Information Officer — CMMC
Sources verified July 22, 2026.
Affected sectors: Government Contracting · Technology
Locations: Loudoun County
Source: Verified references in article