On July 13, 2026, the Department of War (DOW) issued a Memorandum announcing the immediate suspension of the Phase II rollout of the Cybersecurity Maturity Model Certification (CMMC) program while a CMMC Reform Task Force conducts a 60-day review. This means government contractors will not be required to obtain a third-party assessment for CMMC Level 2 certification (or DIBCAC assessment for Level 3 certification) unless and until the DOW reinstates the requirement or imposes a new one.
Read the full blog post.