Key Takeaways

  • CMMC Phase II, which was scheduled to begin November 10, 2026, has been suspended while the Department of War reviews the program.
  • Phase I self-assessment requirements remain in place.
  • The Department will continue enforcing NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments during the suspension. 
  • The review specifically aims to address barriers affecting small, medium, and nontraditional businesses in the defense industrial base.
  • SMBs should view the suspension as an opportunity to evaluate their cybersecurity and compliance posture, rather than a reason to abandon CMMC preparation.

For small and midsized businesses in the defense supply chain, keeping up with CMMC has already required considerable attention. Now, another major change has arrived.

On July 13, 2026, the Department of War announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. Phase II had been scheduled to begin November 10, 2026. At the same time, the Department announced a comprehensive review of the program aimed, in part, at reducing barriers for small, medium, and nontraditional businesses.

For an SMB that has spent months preparing for CMMC Phase II, the announcement may raise an obvious question: Can we put compliance efforts on hold, too?

Not exactly.

The Phase II suspension changes the immediate certification landscape, but it does not eliminate CMMC or remove cybersecurity responsibilities defense contractors may already have. Understanding that distinction can help smaller contractors decide where to focus while the government determines what comes next.

Small business team discussing CMMC Phase II requirementsWhat Happened to CMMC Phase II?

CMMC was designed to provide a way for the government to verify that companies within the defense industrial base are meeting cybersecurity requirements appropriate to the information they handle.

The program has been rolling out in phases. Phase II was scheduled to expand implementation in November 2026, including greater use of third-party assessments for certain contractors.

That timeline has now changed.

The Department suspended Phase II requirements and established a CMMC reform task force to review the program. According to the Department, the review is intended to lower barriers to participation in the defense industrial base while replacing burdensome compliance processes with cybersecurity measures that can scale more effectively. 

That is particularly relevant to SMBs. CMMC preparation can demand time, money, and specialized knowledge. A large defense contractor may have dedicated cybersecurity and compliance personnel, while a smaller manufacturer, engineering company, or subcontractor may rely on a small IT team or outsourced provider.

The suspension provides an opportunity to reconsider how CMMC is implemented without signaling an end to cybersecurity requirements.

What Does the CMMC Phase II Suspension Mean for SMBs?

For smaller businesses, the most immediate change is that certain requirements expected to arrive with Phase II will not take effect according to the previous November 2026 schedule.

That provides some breathing room for businesses concerned about the cost, time, and resources associated with third-party certification.

However, small businesses may possess the same types of sensitive government information as much larger contractors, even if they have fewer employees and a smaller IT budget. The Department has made clear that businesses seeking to work with it will still need to meet applicable cybersecurity requirements and safeguard government information. 

So, for SMBs, the better question isn’t, “Can we stop worrying about CMMC?”

It is, Which requirements apply to us today, and where should we focus while CMMC is being reviewed?”

CMMC Phase II vs. CMMC Level 2: What’s the Difference?

This is an important distinction, especially because the terms sound similar.

Phase II describes a stage in the government’s rollout of CMMC.

Level 2 describes a CMMC compliance level.

The suspension of Phase II does not mean CMMC Level 2 has been eliminated.

CMMC requirements vary based on the type of federal information a contractor handles. For many businesses that handle Controlled Unclassified Information (CUI), Level 2 is particularly important because its security requirements align with NIST SP 800-171.

During the current suspension, the Department says it will continue enforcing compliance with NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments

In short, “Phase II suspended” does not mean “Level 2 cybersecurity requirements no longer matter.”

What Hasn’t Changed for Small Defence Contractors?

The certification timeline may be changing, but the underlying responsibility to safeguard sensitive information hasn’t.

DFARS 252.204-7012, for example, addresses safeguarding covered defense information and cyber incident reporting. The clause defines adequate security in terms of protective measures appropriate to the risks of loss, misuse, unauthorized access, or modification of information. 

The Department has also stated that all Phase I self-assessment requirements remain in place

Your organization may therefore still have contractual cybersecurity responsibilities today. Those obligations depend on the contracts you hold, the information you access, and the requirements that apply to your organization.

This is why SMBs should be careful about interpreting the announcement as a blanket compliance delay.

Digital security icons representing data protection and CMMC cybersecurity requirements

Is CMMC Going Away?

Based on what the government has announced, no.

CMMC is undergoing a comprehensive review, which means aspects of the program could change. The Department has said it wants to reduce compliance burdens and develop scalable cybersecurity measures while continuing to protect sensitive information. 

That’s different from cancelling CMMC.

For SMBs, it would be risky to make long-term technology decisions based on the assumption that certification requirements will never return. Businesses should instead distinguish between CMMC requirements that are temporarily suspended, requirements that remain in effect, and broader cybersecurity obligations contained in their contracts.

Should SMBs Keep Preparing for CMMC During the Phase II Suspension?

Preparation still makes sense, but the suspension gives SMBs an opportunity to approach it thoughtfully.

Instead of racing toward a November deadline, businesses can use this period to take a closer look at their current cybersecurity practices and identify potential compliance gaps.

For example, an organization can review where CUI enters its environment, who has access to it, where it is stored, and how it moves between employees, systems, and third parties. It can also examine whether current security controls match applicable NIST requirements and whether policies and documentation accurately reflect what’s happening in practice.

This is particularly valuable because compliance gaps can exist even when cybersecurity measures are already in place. A business may have endpoint protection, backups, and access controls but lack clear documentation. Another may have strong written policies that aren’t consistently followed.

Finding those issues now can put the company in a stronger position regardless of how CMMC changes.

Magnifying glass reviewing a checklist representing CMMC compliance assessment

Why the CMMC Phase II Pause Could Benefit SMBs

There’s another way for small businesses to look at the suspension: more time can be valuable when it’s used well.

Smaller defense contractors often face a difficult balance. They need cybersecurity capable of protecting sensitive information, but they don’t have unlimited budgets or large compliance departments.

A revised CMMC program could ultimately change how requirements are assessed or implemented. Until the review is complete, businesses don’t know exactly what the final approach will look like.

That makes this a good time to concentrate on the fundamentals rather than trying to predict every potential rule change. Understand your contracts. Know what sensitive information you handle. Identify security gaps. Keep required assessments current. Maintain accurate documentation.

Those efforts have value beyond certification.

CMMC May Change, But Cybersecurity Still Matters

One of the clearest messages accompanying the Phase II suspension is that the government isn’t backing away from cybersecurity.

The Department’s chief information officer has emphasized that contractors will still need to safeguard government information according to applicable requirements

For SMBs, that is probably the most useful way to view the current situation. CMMC requirements, assessment processes, and timelines may change, but the need to protect sensitive information remains.

Instead of treating compliance as a deadline-driven project, SMBs can use this period to build security practices that are manageable over the long term.

Get Help Navigating CMMC Changes

For SMBs, keeping up with changing cybersecurity requirements can be difficult, especially without dedicated compliance personnel. Blue Technologies helps businesses make sense of these requirements through BlueComply, its compliance services offering.

From identifying compliance gaps and mapping security controls to developing policies and preparing for CMMC requirements, Blue can help your business address potential weaknesses and stay prepared as the program evolves.

The Phase II suspension may have changed the timeline, but it hasn’t removed the need to protect sensitive information. Contact Blue Technologies to learn how BlueComply can help your business stay prepared for what comes next.

Frequently Asked Questions

Does CMMC apply to subcontractors, or only prime contractors?

CMMC can affect companies at different levels of the defense supply chain. A small business doesn’t necessarily avoid cybersecurity requirements simply because it works for a prime contractor rather than contracting directly with the government. Applicable requirements depend on factors such as contract terms and the type of federal information the company handles.

Can an MSP make an SMB CMMC compliant?

An MSP or compliance provider can help assess an organization’s environment, implement technical safeguards, develop documentation, identify gaps, and prepare for assessments. However, CMMC involves more than outsourced IT. The organization itself remains responsible for meeting the requirements that apply to its contracts and environment.

Should SMBs include CMMC in future IT budgets even though Phase II is suspended?

Affected defense contractors should continue accounting for cybersecurity and compliance needs in technology planning. The future CMMC assessment process is under review, so businesses should avoid assuming what certification will ultimately cost. However, security improvements, documentation, risk assessments, and other work needed to meet existing contractual requirements can still require resources. Planning for those needs can help prevent compliance work from becoming an unexpected expense later.

Author

  • Phil helps organizations strengthen their cybersecurity strategies by identifying risks, improving security awareness, and implementing solutions designed to protect critical business data. As a cybersecurity leader, Phil is passionate about helping businesses navigate emerging threats, adopt proactive security practices, and build resilient environments prepared for the challenges of AI and cybersecurity.