CMMC Phase II Suspended: What Defense Manufacturers Need to Know
The Department of War has officially suspended the rollout of CMMC Phase II to conduct a comprehensive program review. Discover what this pause means for defense manufacturers, which self-assessment and NIST SP 800-171 requirements still apply, and how to navigate your compliance strategy moving forward.
.jpg)
CMMC Phase II Has Been Suspended
On July 13, 2026, the Department of War announced that it was suspending CMMC Phase II, also called CMMC Phase 2. This stage of the program was expected to begin in November 2026 and would have required many defense contractors to complete an outside cybersecurity assessment.
The suspension also pauses future CMMC rollout deadlines while the Department reviews the program. For manufacturers preparing for certification, this may provide more time, but companies should not assume that Phase II has been permanently canceled.
Why Is CMMC Being Reviewed?
The Department has created a task force to review how CMMC currently works. The group will consider feedback from defense contractors and look for ways to protect sensitive information without creating unnecessary costs and paperwork for smaller businesses.
The review could change when CMMC Phase II begins, which companies need outside assessments, or how the certification process works. The Department has not yet announced what those changes will be.
What Requirements Still Apply?
CMMC Phase I remains in place. Under Phase I, many contractors must review their own cybersecurity practices and report whether they meet the required standards.
The Department will also continue enforcing NIST SP 800-171, a federal cybersecurity standard for companies that store or handle sensitive government information. It covers areas such as passwords, user access, system monitoring, employee security, and how sensitive files are stored and shared.
Defense contractors are still responsible for protecting sensitive information connected to their government contracts. The certification schedule may be changing, but the underlying security responsibilities are not. Our guide to AI, CMMC, and ITAR compliance provides more background on what secure technology should look like for defense manufacturers.
What Should Defense Manufacturers Do Now?
Manufacturers should continue following the cybersecurity requirements already included in their contracts. They should maintain their current security controls, keep compliance records organized, and continue completing any required self-assessments.
Companies may want to reconsider major expenses that were based only on the November 2026 Phase II deadline. However, they should speak with their customers, cybersecurity advisors, or CMMC assessors before stopping an existing compliance project.
Manufacturing software can support this work by keeping records in one place, limiting access to sensitive information, and maintaining clear audit trails. Learn more about the role of quoting and ERP software in CMMC compliance.
Why This Matters to Smaller Manufacturers
Preparing for an outside CMMC assessment can require significant time, documentation, consulting support, and employee training. For smaller machine shops and contract manufacturers, those costs can make defense work harder to enter or maintain.
The review could lead to a simpler and more affordable certification process. It could also only change the timing of the current requirements. Until more information is released, manufacturers should continue meeting today’s requirements while preparing for several possible outcomes.
StartProto Is Tracking the CMMC Review
StartProto is actively tracking the Department’s review and any new guidance affecting defense manufacturers. We will continue sharing updates as the government provides more information about certification deadlines, outside assessments, and future CMMC requirements.
The suspension does not change StartProto’s focus on secure cloud manufacturing software, controlled user access, and the protection of sensitive production data. Manufacturers still need systems that help keep regulated information secure, organized, and available to the right people.
Learn more about StartProto’s approach to security and ITAR compliance.
The Bottom Line
CMMC Phase II has been suspended, but it has not been eliminated. Self-assessments and existing cybersecurity requirements remain in place, and defense contractors are still responsible for protecting sensitive government information.
StartProto will continue tracking the review and publishing updates as more information becomes available.
Conclusion
While CMMC Phase II is paused, Phase I self-assessments and NIST SP 800-171 standards remain actively enforced. Defense manufacturers must continue prioritizing secure data controls and audit trails to protect their contracts.
Book a demo with StartProto today to see how our cloud-native software keeps your shop floor compliant.
Unlock the potential of AI manufacturing
Blogs & Resources
Industry trends, manufacturing business tips, and more
Ready to get started?
We'll make it easy for you — pick the time that works best for you and we'll send an invite right to your calendar.


