The CMMC Phase 2 rollout is on hold, but defense contractors and suppliers must still meet existing cybersecurity requirements. Find out what the delay means and what to do next.
The US Department of War has delayed the date on which certification becomes a condition of contract award. It has not withdrawn the program, and it has not lifted the cybersecurity obligations already written into defense contracts and passed down supply chains. Here is what has changed, what has not, and what we recommend you do next.
If your organization supplies into the US defense supply chain directly, or several tiers down as a manufacturer, software provider or service partner you will have seen headlines suggesting that the Cybersecurity Maturity Model Certification (CMMC) program has been shelved. It has not. One date has moved. Almost everything else stands.
CMMC is the framework used by the US Department of War (DoW) to verify that companies handling sensitive defense information have the controls in place to protect it. It runs across three levels, from Level 1 self-assessment through to Level 2 certification carried out by an accredited independent assessor and Level 3 assessment carried out by the US government. For suppliers, it is the mechanism that turns a contractual promise about cybersecurity into something that can be checked.
What has changed
One thing. DoW has suspended the start of the CMMC Phase 2 rollout. The trigger date of 10 November would have made a CMMC Level 2 certification issued by a C3PAO, an accredited CMMC Third-Party Assessment Organization a condition of award for applicable DoW solicitations and contracts, alongside the inclusion of the associated DFARS contract clause. That trigger is on hold.
The scope of the pause is narrower than the coverage suggests. It applies only to contracts awarded directly between DoW and the contractor it awards to. It does not touch requirements that a prime contractor has already placed on its own suppliers.
What has not changed
- The assessment ecosystem is fully operational. Certification assessments by C3PAOs are continuing. Training and assessor qualification through the CAICO (the body that authorizes CMMC training providers and certifies assessors) is running normally. The Cyber AB’s mandate is unchanged, and the US government systems that record assessment results, SPRS and eMASS, remain open. An organization that wants to be certified today can be.
- Prime contractor flow-down requirements stand. A “flow-down” is a requirement a prime contractor passes to its suppliers through their contract. If your customer requires you to hold or self-attest to CMMC Level 2, that is an obligation between you and them. DoW’s pause does nothing to change it, and nothing to change the commercial consequences of failing it.
- The compliance floor has not moved. The existing DFARS cybersecurity clauses (252.204-7012, -7019, -7020, -7021, -7024 and -7025) remain in full effect on awarded contracts and their supplier flow-downs. Defense Industrial Base companies must still self-affirm Level 1 protections for Federal Contract Information (FCI is information generated under a government contract that is not intended for public release) and Level 2 protections for Controlled Unclassified Information (CUI is sensitive but unclassified government information, such as technical drawings and specifications).
- The assessment process itself is untouched. The CMMC Assessment Process (CAP 2.0) contains its own stage called “Phase 2”, which relates to how an assessment is conducted. It is unrelated to the Phase 2 rollout that has been paused. The two share a name and nothing else. A point worth clarifying internally before it causes confusion.
One further consequence: the pause also delays any migration to the updated NIST SP 800-171 Revision 3 standard, most likely until the new FAR CUI rule appears next year. For organizations mid-way through a control uplift, that is useful breathing room rather than a change of direction.
What we are seeing
From our conversations with manufacturers and technology suppliers across the US defense supply chain, three themes come up consistently.
First, primes are not relaxing. The flow-down language is already in signed contracts, and the larger primes we speak to have made significant investments in supplier assurance that they are not about to unwind because a government start date has slipped. Several are continuing to ask suppliers for evidence on their original timelines.
Second, we expect scrutiny to shift rather than fall away. With the government’s Level 3 assessment queue idled, that capacity is likely to be redeployed into stepped-up, non-voluntary audits under DFARS 252.204-7012. Organizations that read the pause as a reduction in oversight may find the opposite is true.
Third, where organizations are not ready, the gap is rarely the technology. It is scoping, evidence and documentation. Knowing precisely where CUI lives in the business and being able to demonstrate the controls around it. Those are the things that take months to put right and cannot be accelerated in the weeks before an assessment.
“The deadline moved. The mission did not. The organizations that benefit most from this pause will be the ones that use it, not the ones that stand down and start again in twelve months’ time.”
Brian Rhodes – Head of Government Services, LRQA
Why this matters if you are not a US business
For any organization that may be involved in the US defense supply chain, geography offers no exemption. These requirements travel through contracts, not borders. If you supply components, subassemblies, software, engineering or logistics services to a US prime or to one of its tier-one suppliers, the obligations can reach you wherever you are based and they attach to the information you hold, not to the country you hold it in.
There is a wider point for global organizations, too. CMMC is the most developed example of a government moving supply chain cybersecurity from self-declaration to independent verification. Similar expectations are emerging in other sectors and jurisdictions. Organizations that build the underlying disciplines now, knowing what sensitive data they hold, where it flows, and who in their supply chain touches it are building capability that will outlast any single regulation.
Certification still matters
Nothing in this announcement diminishes the value of being certified. Organizations holding a C3PAO-issued CMMC Level 2 certification retain a genuine competitive advantage inside prime supply chains, where certified suppliers are easier to onboard and lower risk to place work with. Certification also strengthens an organization’s position against False Claims Act exposure in the US, by demonstrating documented due diligence rather than an untested self-declaration.
When Phase 2 restarts and the program has been designed on the assumption that it will. The assessment capacity will be finite. Demand will not arrive evenly.
What organizations should do now
- Continue preparing for certification. Treat the pause as schedule relief, not a reprieve. Keep your program running and use the additional time to close gaps properly rather than at pace.
- Read your contracts, not the headlines. Check what your customers have already flowed down to you. Those obligations are unaffected by this announcement and remain enforceable.
- Review the suppliers in your own supply chain. Understand which of them handle FCI or CUI on your behalf, what you have required of them, and whether they can evidence it.
- Confirm your scope and your self-attestation. Make sure you know where sensitive information sits in your environment and that any score or affirmation you have submitted is current, accurate and defensible.
- Use the window for evidence and documentation. Policies, system security plans and remediation records are what assessments turn on and what enforcement activity examines.
- Talk to us. If you are unsure how this affects your obligations or your timeline, we can help you work through it.
How LRQA can help
LRQA supports organizations across the global defense supply chain with readiness assessments, gap analysis and certification. Whether you are certified, mid-program or still establishing what applies to you, we can help you understand what this announcement means for your organization and what to prioritize next.
Contact us to discuss what the latest CMMC announcement means for your organization
