Defense Suppliers Must Maintain Cyber Rules Despite Phase II Pause

Defense Suppliers Must Maintain Cyber Rules Despite Phase II Pause

2026-10-05 politics

Washington, Monday, 5 October 2026.
The Pentagon suspended CMMC Phase II requirements, but basic cybersecurity self-assessments remain strictly mandatory for hundreds of thousands of suppliers. Non-compliance threatens contracts and risks massive supply-chain breach costs.

Regulatory Suspension and Continuing Obligations

Despite the temporary suspension of Phase II implementation of the Cybersecurity Maturity Model Certification (CMMC), defense contractors and suppliers must continue complying with Level 1 self-assessment requirements [1]. The Department of Defense announced the suspension of CMMC Phase II requirements on July 13, 2026, which were previously scheduled for November 10, 2026 [5]. Class Deviation 2026-O0025, Revision 3, signed September 3, 2026, confirms that CMMC Level 1 self-assessments remain mandatory for procurement requests despite the Phase II suspension [1]. Contractors remain legally obligated to perform annual self-assessments, submit scores to the Supplier Performance Risk System (SPRS), and maintain compliance with NIST SP 800-171 Rev. 2 under DFARS 252.204-7012 [2]. The Department of Defense has suspended the CMMC program rollout to conduct a comprehensive review aimed at reducing compliance burdens and aligning with defense acquisition reforms [3].

Impact on the Defense Industrial Base

The Department of Defense’s September 10, 2025 DFARS final rule estimated that 209,540 entities—including 142,487 small businesses—will eventually require Level 1 self-assessment [5]. Small businesses constitute approximately 68 percent of the entities affected by these requirements [1]. Non-compliance with overlapping privacy regimes increased breach costs by an average of $201,112 in 2026 [2]. Supply-chain risk accounted for 48 percent of security breaches, driving a shift toward continuous evidence collection rather than point-in-time annual audits [2]. Prime contractors are required to verify that subcontractors meet applicable CMMC requirements when sharing covered information [3]. Defense contractors face False Claims Act exposure for noncompliance, with the Department of Justice’s Civil Cyber-Fraud Initiative pursuing contractors for knowingly misrepresenting CMMC compliance [6].

Technology and Compliance Tools

Compliance platform AssessrLog announced new free tools and record-keeping systems to help defense industrial base companies maintain mandatory compliance standards and avoid contractual delays [1]. ProfytAI publicly launched AssessrLog in September 2026, a platform offering tools for U.S. defense suppliers to manage CMMC Level 1 compliance [1]. AssessrLog launched free CMMC Level 1 resources as of 2026-10-04, including a 24-question Readiness Check and a Reference Center covering all 15 requirements and 59 assessment objectives [1]. Microsoft Fabric reached general availability in GCC High on October 1, 2026, enabling defense contractors to utilize workloads like OneLake within the compliance boundary [7]. EPC Group advises defense contractors to complete a nine-point data-foundation checklist before provisioning Fabric capacity, utilizing the current CMMC suspension as a planning window rather than a compliance reprieve from NIST SP 800-171 [7].

Future Outlook and Strategic Planning

The Department of Defense established a CMMC Reform Task Force to perform a 60-day review of the program, gather industry feedback, and issue recommendations [6]. The 60-day review period initiated by the Department of Defense following the July 2026 suspension should have concluded by approximately 2026-09-08 [6]. The Phase II pause did not eliminate Level 1 self-assessment requirements, and for suppliers required to hold Level 1 status, a senior official still affirms in SPRS every year [5]. Organizations are advised to maintain audit-ready evidence repositories that satisfy both current self-assessment rules and anticipated future C3PAO criteria to prepare for potential assessments [2]. A 90-minute educational webinar titled CMMC program requirements and the current landscape is scheduled for Thursday, November 19, 2026, to address practical risk mitigation strategies [6].

Sources


Defense Industry Cybersecurity Compliance