CMMC Freeze Explained: What the DoD's 60-Day Review Means for Defense Contractors in 2026
On July 13, 2026, the Department of Defense (DoD) announced an immediate freeze on the implementation of CMMC Phase 2 requirements while launching a comprehensive 60-day review of the Cybersecurity Maturity Model Certification (CMMC) program. The move quickly generated headlines across the defense contracting and cybersecurity communities, leaving many organizations wondering whether CMMC had been delayed, significantly altered, or even cancelled.
The reality is far less dramatic.
While the review temporarily pauses certain implementation activities, the DoD has not abandoned its cybersecurity objectives. Defense contractors handling Controlled Unclassified Information (CUI) remain responsible for protecting sensitive government information and maintaining compliance with applicable cybersecurity requirements.
For organizations throughout the Defense Industrial Base (DIB), the current pause should be viewed as an opportunity to improve readiness rather than a signal to stop compliance efforts.
What Was Frozen?
The DoD has temporarily suspended CMMC Phase 2 implementation activities while conducting a detailed review of the certification program.
The review is expected to evaluate several critical areas:
- Assessment scalability across the Defense Industrial Base
- Certification costs for small and mid-sized contractors
- Availability of Certified Third-Party Assessment Organizations (C3PAOs)
- Administrative burdens associated with compliance
- Assessment timelines and scheduling challenges
- Opportunities to streamline implementation
Importantly, the announcement does not eliminate cybersecurity obligations or contractual responsibilities related to protecting CUI.
What Has Not Changed?
One of the biggest misconceptions surrounding the announcement is that cybersecurity compliance requirements have disappeared.
They have not.
Protection of Controlled Unclassified Information
Organizations handling CUI must continue protecting sensitive government information through appropriate administrative, technical, and physical safeguards.
A temporary freeze in certification activities does not reduce the importance of protecting defense-related information.
NIST SP 800-171 Remains the Foundation
NIST SP 800-171 continues to serve as the baseline framework for safeguarding CUI within contractor environments.
Whether assessments occur this year or next year, organizations should continue implementing and maintaining required security controls. Delaying implementation now will likely result in greater remediation efforts in the future.
Contractual Requirements Still Apply
Many existing DoD contracts contain cybersecurity requirements independent of CMMC certification milestones.
Contractors remain responsible for meeting applicable contract clauses and security obligations unless those requirements are formally modified by contracting authorities.
Why Did the DoD Pause CMMC Phase 2?
Several factors likely contributed to the decision.
Industry Feedback
Over the past several years, defense contractors have raised concerns about:
- Certification costs
- Assessment scheduling delays
- Limited assessor availability
- Complex documentation requirements
- Interpretation inconsistencies
Small businesses have been particularly concerned about the cost and resource burden associated with achieving certification.
Assessment Capacity Challenges
Questions have also emerged regarding the assessment ecosystem's ability to support the entire Defense Industrial Base.
With thousands of organizations requiring certification, concerns grew about whether enough qualified assessors exist to meet demand within originally planned timelines.
Program Optimization
The review provides an opportunity for the DoD to refine and improve program administration while maintaining cybersecurity objectives.
Potential areas for improvement may include:
- Assessment workflows
- Documentation guidance
- Certification processes
- Program governance
- Small business support initiatives
- Implementation timelines
Does This Mean CMMC Is Going Away?
Most industry experts believe the answer is no.
The cybersecurity threats that led to the creation of CMMC continue to grow. Nation-state actors and advanced threat groups remain focused on defense contractors, supply chain partners, aerospace organizations, research institutions, and manufacturers that support national security objectives.
Protecting sensitive information remains a critical mission for both government agencies and contractors.
The review is best understood as a program refinement effort rather than the elimination of cybersecurity expectations.
Common Myths About the Freeze
Myth 1: CMMC Has Been Cancelled
Reality: Only selected implementation activities have been paused. The broader cybersecurity goals of the program remain intact.
Myth 2: We Can Stop Compliance Preparation
Reality: Organizations that halt preparation efforts may face:
- Higher future remediation costs
- Compressed implementation schedules
- Delayed certification readiness
- Increased cybersecurity exposure
Myth 3: NIST SP 800-171 No Longer Matters
Reality: NIST SP 800-171 remains the foundation for protecting Controlled Unclassified Information.
Myth 4: Documentation Can Wait
Reality: Documentation is often one of the most time-consuming components of compliance readiness. Waiting until assessments resume may create unnecessary delays.
What Should Contractors Do During the Review?
Rather than viewing the freeze as downtime, organizations should use the review period to strengthen cybersecurity programs and improve assessment readiness.
Conduct a Gap Assessment
Evaluate current controls against NIST SP 800-171 requirements and identify:
- Missing controls
- Process weaknesses
- Documentation gaps
- Technology deficiencies
Strengthen Your System Security Plan (SSP)
Your SSP should accurately document:
- System boundaries
- Implemented controls
- Security architecture
- Technologies
- Responsibilities
- Data flows
Update Policies and Procedures
Review key governance documents, including:
- Access Control
- Incident Response
- Configuration Management
- Asset Management
- Risk Management
- Security Awareness
- Media Protection
- Personnel Security
Build Evidence Early
Collect evidence continuously rather than waiting until certification resumes.
Examples include:
- Audit logs
- Security monitoring reports
- MFA configurations
- Training records
- Vulnerability scans
- Patch management documentation
Conduct Internal Readiness Reviews
Internal assessments can identify weaknesses before official certification activities return, reducing future remediation costs and improving confidence.
The Business Value of Continued Preparation
Organizations that continue compliance efforts during the review period gain several advantages.
Faster Certification Readiness
Prepared organizations can move more quickly once updated implementation guidance becomes available.
Lower Costs
Addressing issues early is typically far less expensive than rushed remediation projects.
Improved Security
Strong cybersecurity practices provide value regardless of certification timelines by reducing operational risk and improving resilience.
Greater Customer Confidence
Prime contractors increasingly evaluate supplier cybersecurity maturity when selecting partners.
Organizations that maintain momentum may strengthen their competitive position within the defense supply chain.
Looking Ahead
Although the outcome of the DoD's review remains uncertain, most observers expect refinements to implementation processes rather than wholesale elimination of cybersecurity requirements.
Potential changes may include:
- Assessment scheduling improvements
- Updated certification processes
- Enhanced guidance for contractors
- Increased support for small businesses
- Modified implementation timelines
The core objective of protecting sensitive defense information is unlikely to change.
Final Thoughts
The recent CMMC freeze has understandably created uncertainty throughout the defense contracting community. However, the most important takeaway remains clear:
The implementation timeline may be under review, but cybersecurity expectations have not disappeared.
Organizations that continue investing in NIST SP 800-171 compliance, cybersecurity maturity, documentation, and readiness activities during the review period will be significantly better positioned when the next phase of CMMC implementation begins.
Instead of asking, "Should we stop preparing?" smart contractors should be asking, "How can we use this time to become assessment-ready?"
That mindset may become one of the most valuable competitive advantages in the Defense Industrial Base over the coming year.
Published by
About our partner
SecureKnots LLC
SecureKnots LLC is a global cybersecurity, governance, risk, compliance (GRC), privacy, and public sector advisory firm helping commercial enterprises, government agencies, and defense contractors build secure, resilient, and compliant organizations.We specialize in end-to-end consulting, implementation, readiness assessments, internal audits, managed compliance, and certification support across international standards, regulatory frameworks, and government security programs.Our commercial services include ISO 27001, ISO 27701, ISO 22301, ISO 9001, ISO 42001, SOC 1, SOC 2, HIPAA, PCI DSS, GDPR, DPDPA, NIST Cybersecurity Framework (CSF), third-party risk management, business continuity, information security, and privacy governance.Our Public Sector & Defense practice supports organizations delivering services to federal, state, and local governments through specialized advisory for:FedRAMP®StateRAMP / GovRAMPCMMC 2.0NIST SP 800-53NIST SP 800-171FISMACJIS Security PolicyCriminal Justice Information Services (CJIS)Controlled Unclassified Information (CUI)Export Administration Regulations (EAR)International Traffic in Arms Regulations (ITAR)DFARS cybersecurity requirementsSecure System Security Plans (SSPs)Security Assessment Plans (SAPs)Plan of Action & Milestones (POA&M)Authorization package development and audit readinessOur experts help organizations design, implement, and mature governance, cybersecurity, privacy, and compliance programs that meet evolving regulatory expectations while improving operational resilience and customer trust. Whether preparing for certification, achieving regulatory compliance, supporting government procurement, or strengthening enterprise security, SecureKnots delivers practical, risk-based solutions aligned with business objectives.SecureKnots LLC – Securing Trust. Enabling Compliance. Empowering Business.
Learn moreHelp your peers
Share what you've learned with fellow public servants