ARTICLE
15 July 2026

DoD Suspends Rollout Of CMMC Program

PA
Peckar & Abramson PC

Contributor

For over four decades, Peckar & Abramson has been a leader and innovator in construction law, providing tailored results for its clients – delivered with a commitment to efficiency, value and client service. With over 100 attorneys in ten offices in the United States and affiliations around the globe, P&A is the recipient of many accolades that reflect the firm’s stature as the premier construction law firm in the industry. Firmly rooted in its history, P&A maintains an unmatched national presence while providing its local clients with highly sophisticated legal insights.
The Department of Defense has abruptly halted the rollout of its Cybersecurity Maturity Model Certification program, suspending higher-level certification requirements and initiating a 60-day review to reform the framework. Defense contractors must now navigate this significant policy shift while maintaining compliance with existing cybersecurity obligations under DFARS regulations.
United States Government, Public Sector
Richard J.“RJ” Pinto II’s articles from Peckar & Abramson PC are most popular:
  • in European Union
  • in European Union
Peckar & Abramson PC are most popular:
  • within Environment topic(s)

Citing prohibitive compliance costs and bureaucratic burdens, on July 13, 2026, the DoD announced the immediate suspension of the rollout of its Cybersecurity Maturity Model Certification (CMMC) program and the implementation of Phase 2, which was scheduled to begin on November 10, 2026. Effective immediately:

  • As a condition of contract award, procuring agencies may only require a contractor to hold a status of CMMC Level 1 (Self) or Level 2 (Self). Any requirement for a status of Level 2 (C3PAO) or Level 3 (DIBCAC) is suspended until further notice, as is the implementation of Phase 2 of the CMMC program.
  • If a current solicitation or contract includes a requirement for Level 2 (C3PAO) or Level 3 (DIBCAC), the procuring agency must initiate a solicitation amendment or contract modification removing such requirement as soon as practicable.
  • Over the next 60 days, the DoD’s Chief Information Officer intends to review and reform the CMMC program to ensure the Defense Industrial Base remains secure without imposing significant burden on businesses.
  • Contractors must continue to comply with the cybersecurity requirements set forth in DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, which remain in effect.

It is anticipated that further guidance will be provided at the conclusion of the DoD’s 60-day review.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More