As the Department of Defense pauses its Cybersecurity Maturity Model Certification Phase II requirements to review compliance burdens for contractors, Congress and the White House continue shaping the defense market through strict cyber supply chain mandates and evolving National Institute of Standards and Technology guidelines.
The CMMC Phase II Suspension and Industry Pushback
The Department of Defense has suspended the planned implementation of Cybersecurity Maturity Model Certification (CMMC) Phase II requirements. This pause enables a comprehensive review of the program following extensive industry feedback. According to Federal News reporting from August 18, 2026, formal comments from the Office of Advocacy and trade groups like the Associated Builders and Contractors emphasized the need to reduce compliance burdens on small and mid-sized defense contractors.

Despite this pause, baseline security remains mandatory. CMMC Level 1 compliance continues to be required for all federal contractors and subcontractors handling Federal Contract Information (FCI). Enforcement carries on under existing procurement rules while the CMMC Reform Task Force reviews input through mid-September 2026.
The task force is addressing several central priorities, seeking to make Controlled Unclassified Information rules clearer, prioritize vital cybersecurity safeguards, and investigate phased compliance options to improve financial viability for the Defense Industrial Base.
Understanding the CMMC Framework Architecture
The underlying structure of the CMMC program dictates how defense contractors manage data protection and operational security. Ambika Biggs of Hirschler notes that the program features three distinct tiers designed to safeguard sensitive information, as outlined by Corporate Compliance Insights.
Level 1 focuses on the basic safeguarding of FCI. It mandates baseline security requirements and procedures to protect contractor information systems that process, store, or transmit federal contract information. Contractors must complete an annual self-assessment of compliance with the 15 security requirements in FAR 52.204-21 and submit an annual affirmation into the Supplier Performance Risk System.
Level 2 addresses the broad protection of Controlled Unclassified Information. It requires compliance with the 110 security requirements in NIST Special Publication 800-171. Depending on the solicitation, contractors must complete either a self-assessment or an independent assessment by an authorized CMMC Third-Party Assessment Organization every three years.
Level 3 demands higher-level protection against advanced persistent threats. It mandates attaining a finalized Level 2 standing along with triennial evaluations conducted by the Defense Industrial Base Cybersecurity Assessment Center of the Defense Contract Management Agency. It also mandates an annual affirmation verifying compliance with 24 identified requirements from NIST SP 800-172.
Phased rollout schedules span four phases over three years. Phase 1 began in November 2025, requiring Level 1 or Level 2 self-assessments where applicable. Phase 2 schedules Level 2 certifications for November 2026. Phase 3 targets Level 3 certifications by November 2027. Finally, Phase 4 dictates that by November 2028, all solicitations will include applicable CMMC level requirements as a condition of contract award.
False Claims Act Scrutiny and Self-Certification Risks
Self-certification carries legal exposure. Because contractors are currently able to self-certify their compliance with Level 1 and Level 2 cybersecurity requirements, misrepresenting self-assessed scores can trigger federal investigations. In 2021, the Department of Justice launched its civil cyber-fraud initiative to enforce government contracting compliance, turning inaccurate cybersecurity self-assessments into targets for False Claims Act scrutiny.
Federal Supply Chain Revamps and NIST Human-Centered Guidance
Beyond the Department of Defense, broader federal initiatives are altering procurement standards. The White House Office of the Federal Chief Information Officer is undertaking a governmentwide initiative to revamp cyber supply chain security data calls. According to Federal News, this effort improves the government’s ability to assess and mitigate risks posed by foreign adversaries prior to contract awards.
Aligning with updated NIST guidelines, the initiative emphasizes a shared risk management approach across federal agencies. Procurement professionals should anticipate more stringent cyber risk assessments and data reporting requirements tied directly to contract eligibility. Vendors with foreign affiliations face increased scrutiny and potential exclusion under enhanced risk criteria.
Simultaneously, NIST is actively soliciting public input through September 30, 2026, on an initiative to develop human-centered cybersecurity guidance. This effort integrates human factors—such as usability, organizational culture, and workforce challenges—into cybersecurity technologies and processes. By shifting away from traditional employee awareness training limitations, NIST aims to empower people as active defenders, influencing future cybersecurity procurement requirements and vendor evaluations alike.