Image
Egnyte | DoD CMMC Phase 2 Pause: What It Means

How DoD's CMMC Phase II Pause Impacts Your Company

In a recent announcement, the U.S. Department of Defense (DoD) suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. Since we’ve received questions from our customers about the announcement's impact, I’ve recapped the latest updates below. 

Remember to always consult your DoD contracts for the latest provisions and review these program updates with legal counsel, technology consultants, and third-party CMMC assessors, as appropriate. 

What CMMC Components Remained the Same? 

Even though the DoD’s announcement included several major changes, surprisingly most of CMMC’s components remained the same, as I explain below. 

CMMC hasn’t been discontinued. Requirements can still appear in DoD contracts, and any DoD contractor or subcontractor that manages contracts with Controlled Unclassified Information (CUI) or Federal Contract Information (FCI) still needs to comply.

Self-Assessment Requirements

As of July 2026, CMMC’s third-party assessment requirement is technically on hold, which I’ll discuss further below. However, CMMC self-assessment requirements are unchanged and remain in effect. Now is the perfect time to finalize preparation activities and complete your self-assessment, so you can maintain a competitive advantage in the federal space, 

NIST SP 800-171 and DFARS As Cybersecurity Baselines

NIST SP 800-171 continues to be a mission-critical security standard for contractors that manage CUI. Similarly, DFARS 252.204-7012 remains in effect, and the DoJ's Civil Cyber-Fraud Initiative continues to pursue organizations that misrepresent their cybersecurity posture under the False Claims Act. Egnyte supports the NIST and DFARS standards. You can find all of the compliance standards that Egnyte supports here

Strong Data Protection Practices for DoD Contractors

Regardless of formal regulatory requirements, DoD contractors are frequent cyberattack targets. Published reports indicate that 85% of cybersecurity professionals rank AI-powered attacks as DoD contractors’ #1 cybersecurity concern. Established data protection processes remain critically important for any organization in the Defense Industrial Base (DIB).

What CMMC Components Changed?

When the DoD’s announcement was published, many organizations assumed there would be major changes associated with it. Realistically, the changes are straightforward, and many of the updates could be anticipated based on the volume of Certified Third-Party Assessor Organizations (C3PAOs) available to defense contractors in Cyber AB’s CMMC Marketplace.

CMMC Phase II Is Officially on Hold

Phase II—originally planned for November 10, 2026—was suspended on the July 13, 2026 announcement date. That phase would have required DoD contractors to undergo third-party assessments that document their CUI protection processes.

Third-Party C3PAO Assessments Aren’t Required Yet

As mentioned above, formal assessments by a C3PAO aren’t required. That gives you additional time to prepare for and conduct your CMMC self-assessments, which are still required. The hiatus also gives you time to shore up your infrastructure and refresh your organization’s incident response plan. 

CMMC Reform Task Force Has Been Established

The DoD is evaluating CMMC's impact on broader federal programs, including the Acquisition Transformation System initiative. A formal task force has been created to conduct that review. Additional details are expected within a few months, and we will keep you posted on any changes. 

Where Do You Go from Here? 

Bottom line, now isn’t the time to become complacent with CMMC requirements. Rather, now you have more time to focus your attention on the 110 CMMC Level 2 controls and make provisions to attain them. Egnyte continues to help customers in the DIB to attain CMMC compliance and prepare for their required self-assessments. If you’d like to discuss your specific CMMC compliance requirements with Egnyte, schedule a workshop with our team. 

Learn More

To learn more about the latest CMMC updates, please register for our webinar with Egnyte customer ERRGIf you’re reading this blog after the live webinar date, you can access the session recording at the same link. 

Share this Blog

Don’t miss an update

Subscribe today to our newsletter to get all the updates right in your inbox.

By submitting this form, you are acknowledging that you have read and understand Egnyte’s Privacy Policy.