Skip to main content

CMMC Freeze Explained: What the DoD's 60-Day Review Means for Defense Contractors in 2026

The DoD's temporary freeze of CMMC Phase 2 has created uncertainty across the Defense Industrial Base. Learn what the review means, what requirements remain in place, and how contractors should prepare during the pause.

Seema Abdul 22 July 2026 · 4 min read
CMMC Freeze Explained: What the DoD's 60-Day Review Means for Defense Contractors in 2026

CMMC Freeze Explained: What the DoD's 60-Day Review Means for Defense Contractors in 2026

On July 13, 2026, the Department of Defense (DoD) announced an immediate freeze on the implementation of CMMC Phase 2 requirements while launching a comprehensive 60-day review of the Cybersecurity Maturity Model Certification (CMMC) program. The move quickly generated headlines across the defense contracting and cybersecurity communities, leaving many organizations wondering whether CMMC had been delayed, significantly altered, or even cancelled.

The reality is far less dramatic.

While the review temporarily pauses certain implementation activities, the DoD has not abandoned its cybersecurity objectives. Defense contractors handling Controlled Unclassified Information (CUI) remain responsible for protecting sensitive government information and maintaining compliance with applicable cybersecurity requirements.

For organizations throughout the Defense Industrial Base (DIB), the current pause should be viewed as an opportunity to improve readiness rather than a signal to stop compliance efforts.

What Was Frozen?

The DoD has temporarily suspended CMMC Phase 2 implementation activities while conducting a detailed review of the certification program.

The review is expected to evaluate several critical areas:

  • Assessment scalability across the Defense Industrial Base
  • Certification costs for small and mid-sized contractors
  • Availability of Certified Third-Party Assessment Organizations (C3PAOs)
  • Administrative burdens associated with compliance
  • Assessment timelines and scheduling challenges
  • Opportunities to streamline implementation

Importantly, the announcement does not eliminate cybersecurity obligations or contractual responsibilities related to protecting CUI.

What Has Not Changed?

One of the biggest misconceptions surrounding the announcement is that cybersecurity compliance requirements have disappeared.

They have not.

Protection of Controlled Unclassified Information

Organizations handling CUI must continue protecting sensitive government information through appropriate administrative, technical, and physical safeguards.

A temporary freeze in certification activities does not reduce the importance of protecting defense-related information.

NIST SP 800-171 Remains the Foundation

NIST SP 800-171 continues to serve as the baseline framework for safeguarding CUI within contractor environments.

Whether assessments occur this year or next year, organizations should continue implementing and maintaining required security controls. Delaying implementation now will likely result in greater remediation efforts in the future.

Contractual Requirements Still Apply

Many existing DoD contracts contain cybersecurity requirements independent of CMMC certification milestones.

Contractors remain responsible for meeting applicable contract clauses and security obligations unless those requirements are formally modified by contracting authorities.

Why Did the DoD Pause CMMC Phase 2?

Several factors likely contributed to the decision.

Industry Feedback

Over the past several years, defense contractors have raised concerns about:

  • Certification costs
  • Assessment scheduling delays
  • Limited assessor availability
  • Complex documentation requirements
  • Interpretation inconsistencies

Small businesses have been particularly concerned about the cost and resource burden associated with achieving certification.

Assessment Capacity Challenges

Questions have also emerged regarding the assessment ecosystem's ability to support the entire Defense Industrial Base.

With thousands of organizations requiring certification, concerns grew about whether enough qualified assessors exist to meet demand within originally planned timelines.

Program Optimization

The review provides an opportunity for the DoD to refine and improve program administration while maintaining cybersecurity objectives.

Potential areas for improvement may include:

  • Assessment workflows
  • Documentation guidance
  • Certification processes
  • Program governance
  • Small business support initiatives
  • Implementation timelines

Does This Mean CMMC Is Going Away?

Most industry experts believe the answer is no.

The cybersecurity threats that led to the creation of CMMC continue to grow. Nation-state actors and advanced threat groups remain focused on defense contractors, supply chain partners, aerospace organizations, research institutions, and manufacturers that support national security objectives.

Protecting sensitive information remains a critical mission for both government agencies and contractors.

The review is best understood as a program refinement effort rather than the elimination of cybersecurity expectations.

Common Myths About the Freeze

Myth 1: CMMC Has Been Cancelled

Reality: Only selected implementation activities have been paused. The broader cybersecurity goals of the program remain intact.

Myth 2: We Can Stop Compliance Preparation

Reality: Organizations that halt preparation efforts may face:

  • Higher future remediation costs
  • Compressed implementation schedules
  • Delayed certification readiness
  • Increased cybersecurity exposure

Myth 3: NIST SP 800-171 No Longer Matters

Reality: NIST SP 800-171 remains the foundation for protecting Controlled Unclassified Information.

Myth 4: Documentation Can Wait

Reality: Documentation is often one of the most time-consuming components of compliance readiness. Waiting until assessments resume may create unnecessary delays.

What Should Contractors Do During the Review?

Rather than viewing the freeze as downtime, organizations should use the review period to strengthen cybersecurity programs and improve assessment readiness.

Conduct a Gap Assessment

Evaluate current controls against NIST SP 800-171 requirements and identify:

  • Missing controls
  • Process weaknesses
  • Documentation gaps
  • Technology deficiencies

Strengthen Your System Security Plan (SSP)

Your SSP should accurately document:

  • System boundaries
  • Implemented controls
  • Security architecture
  • Technologies
  • Responsibilities
  • Data flows

Update Policies and Procedures

Review key governance documents, including:

  • Access Control
  • Incident Response
  • Configuration Management
  • Asset Management
  • Risk Management
  • Security Awareness
  • Media Protection
  • Personnel Security

Build Evidence Early

Collect evidence continuously rather than waiting until certification resumes.

Examples include:

  • Audit logs
  • Security monitoring reports
  • MFA configurations
  • Training records
  • Vulnerability scans
  • Patch management documentation

Conduct Internal Readiness Reviews

Internal assessments can identify weaknesses before official certification activities return, reducing future remediation costs and improving confidence.

The Business Value of Continued Preparation

Organizations that continue compliance efforts during the review period gain several advantages.

Faster Certification Readiness

Prepared organizations can move more quickly once updated implementation guidance becomes available.

Lower Costs

Addressing issues early is typically far less expensive than rushed remediation projects.

Improved Security

Strong cybersecurity practices provide value regardless of certification timelines by reducing operational risk and improving resilience.

Greater Customer Confidence

Prime contractors increasingly evaluate supplier cybersecurity maturity when selecting partners.

Organizations that maintain momentum may strengthen their competitive position within the defense supply chain.

Looking Ahead

Although the outcome of the DoD's review remains uncertain, most observers expect refinements to implementation processes rather than wholesale elimination of cybersecurity requirements.

Potential changes may include:

  • Assessment scheduling improvements
  • Updated certification processes
  • Enhanced guidance for contractors
  • Increased support for small businesses
  • Modified implementation timelines

The core objective of protecting sensitive defense information is unlikely to change.

Final Thoughts

The recent CMMC freeze has understandably created uncertainty throughout the defense contracting community. However, the most important takeaway remains clear:

The implementation timeline may be under review, but cybersecurity expectations have not disappeared.

Organizations that continue investing in NIST SP 800-171 compliance, cybersecurity maturity, documentation, and readiness activities during the review period will be significantly better positioned when the next phase of CMMC implementation begins.

Instead of asking, "Should we stop preparing?" smart contractors should be asking, "How can we use this time to become assessment-ready?"

That mindset may become one of the most valuable competitive advantages in the Defense Industrial Base over the coming year.

Published by

Seema Abdul Cofounder, SecureKnots LLC

About our partner

SecureKnots LLC

SecureKnots LLC is a global cybersecurity, governance, risk, compliance (GRC), privacy, and public sector advisory firm helping commercial enterprises, government agencies, and defense contractors build secure, resilient, and compliant organizations.We specialize in end-to-end consulting, implementation, readiness assessments, internal audits, managed compliance, and certification support across international standards, regulatory frameworks, and government security programs.Our commercial services include ISO 27001, ISO 27701, ISO 22301, ISO 9001, ISO 42001, SOC 1, SOC 2, HIPAA, PCI DSS, GDPR, DPDPA, NIST Cybersecurity Framework (CSF), third-party risk management, business continuity, information security, and privacy governance.Our Public Sector & Defense practice supports organizations delivering services to federal, state, and local governments through specialized advisory for:FedRAMP®StateRAMP / GovRAMPCMMC 2.0NIST SP 800-53NIST SP 800-171FISMACJIS Security PolicyCriminal Justice Information Services (CJIS)Controlled Unclassified Information (CUI)Export Administration Regulations (EAR)International Traffic in Arms Regulations (ITAR)DFARS cybersecurity requirementsSecure System Security Plans (SSPs)Security Assessment Plans (SAPs)Plan of Action & Milestones (POA&M)Authorization package development and audit readinessOur experts help organizations design, implement, and mature governance, cybersecurity, privacy, and compliance programs that meet evolving regulatory expectations while improving operational resilience and customer trust. Whether preparing for certification, achieving regulatory compliance, supporting government procurement, or strengthening enterprise security, SecureKnots delivers practical, risk-based solutions aligned with business objectives.SecureKnots LLC – Securing Trust. Enabling Compliance. Empowering Business.

Learn more