Last Updated July 15, 2026
If your company has been preparing for the next phase of the Cybersecurity Maturity Model Certification (CMMC), you’ve likely seen the recent headlines announcing that CMMC Phase II has been suspended.
For many manufacturers, the first question is simple: What does this mean for us?
The short answer is that the timeline for mandatory third-party CMMC assessments has changed, but cybersecurity requirements have not disappeared.
Here’s what we know and what manufacturers should be thinking about moving forward.
What Changed?
The Department of War has suspended the planned rollout of CMMC Phase II and launched a 60-day review of the program.
According to the announcement, the review is intended to evaluate whether the current implementation places unnecessary burdens on defense contractors while still achieving its cybersecurity objectives.
- Among the concerns cited were:
- The rising cost of compliance
- Limited availability of certified third-party assessors
- Delays in the certification process
- The impact on small and mid-sized businesses that support the Defense Industrial Base
The review will examine ways to maintain strong cybersecurity standards while reducing unnecessary complexity and administrative burden.
What Has Not Changed?
While the Phase II rollout has been paused, the responsibility to protect sensitive government information remains.
Organizations that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) should continue complying with the cybersecurity requirements applicable to their contracts. The suspension affects the rollout of mandatory Phase II certification requirements. It does not eliminate the need to safeguard sensitive information or meet existing contractual obligations.
In its announcement, the Department emphasized that maintaining strong cybersecurity remains a critical priority, even as it evaluates potential improvements to the program.
What Should Manufacturers Do Now?
Although the certification timeline may shift, this is not the time to put cybersecurity initiatives on hold.
Instead, manufacturers can use this additional time to strengthen their overall security posture and continue preparing for future requirements.
Some practical next steps include:
- Review your current cybersecurity program.
- Continue addressing known security and compliance gaps.
- Keep policies, procedures, and documentation current.
- Stay informed as additional guidance is released following the 60-day review.
- Continue making cybersecurity a business priority rather than treating it as a one-time compliance exercise.
No one knows exactly what the revised Phase II requirements will look like, but organizations that continue improving their cybersecurity programs today will be better prepared regardless of how the program evolves.
Why This Matters
For many manufacturers, this announcement provides additional breathing room. It also reinforces an important point.
The Department is not stepping away from cybersecurity. Instead, it is evaluating how to achieve the program’s objectives in a way that is more practical and sustainable for the companies that make up the Defense Industrial Base.
That distinction is important. The goal is not less cybersecurity. The goal is a more effective and efficient path to achieving it.
How Godlan Helps Defense Manufacturers
Godlan has decades of experience helping aerospace and defense manufacturers improve operations, meet complex compliance requirements, and prepare for evolving industry demands.
Whether your organization is modernizing its ERP system, strengthening operational processes, or preparing for future cybersecurity requirements, our team understands the unique challenges facing defense manufacturers.
As additional guidance becomes available following the Department’s review, manufacturers should continue monitoring developments and remain focused on building a strong cybersecurity foundation. Organizations that stay prepared today will be in the best position to adapt to whatever comes next.
Frequently Asked Questions About the CMMC Phase II Suspension
Is CMMC canceled? Is CMMC suspended?
No. The Department has suspended the planned rollout of CMMC Phase II while it conducts a 60-day review of the program. The review is intended to evaluate how the program can continue strengthening cybersecurity while reducing unnecessary complexity and administrative burden.
Does the suspension mean cybersecurity requirements no longer apply?
No. Organizations that handle Federal Contract Information (FCI) or Controlled Unclassified Information (CUI) are still responsible for meeting the cybersecurity requirements outlined in their contracts. The suspension applies to the rollout of Phase II certification requirements, not to the obligation to protect sensitive government information.
Should manufacturers stop preparing for CMMC?
No. While the certification timeline may change, manufacturers should continue strengthening their cybersecurity programs, maintaining documentation, and addressing known security gaps. Staying prepared now can make it easier to adapt once updated guidance is released.
What is the purpose of the 60-day review?
According to the Department, the review will evaluate whether the current CMMC implementation places unnecessary burdens on defense contractors while still meeting its cybersecurity objectives. The goal is to identify opportunities to simplify the program without compromising security.
Will third-party CMMC assessments still be required?
That has not yet been determined. The Department has paused the planned Phase II rollout while it reviews the program. Additional guidance is expected after the review is complete.
What should defense contractors do during the review period?
Manufacturers should continue protecting sensitive government information, monitor announcements from the Department, and maintain momentum on cybersecurity initiatives rather than putting them on hold.
How does this affect companies pursuing new Department of Defense contracts?
Companies should continue reviewing the cybersecurity requirements included in each solicitation or contract. While the Phase II rollout has been suspended, existing contractual cybersecurity requirements remain in effect.
Does this change NIST 800-171 requirements?
The announcement does not eliminate existing contractual cybersecurity requirements. Organizations should continue following the requirements specified in their contracts and applicable regulations while awaiting additional guidance from the Department.
How can manufacturers prepare for future CMMC requirements?
Manufacturers can use this additional time to strengthen their cybersecurity posture by reviewing policies and procedures, improving documentation, addressing known compliance gaps, and working with trusted advisors to prepare for future certification requirements.
How can Godlan help?
Godlan has extensive experience helping aerospace and defense manufacturers modernize operations, improve compliance readiness, and prepare for evolving regulatory requirements. Our team can help manufacturers evaluate their current environment and develop a practical roadmap for meeting future cybersecurity expectations.
Source: U.S. Department of War, “War Department Changes Cybersecurity Maturity Model Certification Requirements.” Read the official announcement