• Skip to primary navigation
  • Skip to main content
  • About
  • Team
  • Industries
  • Products
  • White Papers
  • Case Studies
  • Portal
  • Pay Now

Advantage Technology

Advantage Tech logoAdvantage Tech logo light

Cybersecurity & Managed IT Service Provider

  • AI
    • AI
    • AI Agents & Automation Consulting
    • AI Fraud Detection
    • AI Inside Advantage.Tech
    • AI Managed IT & Service Desk
    • AI Security Customization
    • AI Tools & Platforms
    • AI Training & Workforce Enablement
  • Managed IT
    • Managed IT
    • Antivirus & Spam Filtering
    • Data Backup & Recovery
    • IT Help Desk
    • Maintenance & Support
    • Remote Monitoring & Management
  • Cybersecurity
    • Cybersecurity
    • Services & Solutions

      • Attack Surface Management (ASM)
      • Cloud Security
      • Continuous Compliance Monitoring
      • Data Loss Prevention (DLP)
      • Email Security
      • Encryption
      • Endpoint Security
      • Identity & Access Management (IAM)
      • Managed Detection & Response (MDR)
      • Multi & Two-Factor Authentication
      • Network Security
      • Security Information & Event Management (SIEM)
      • Security Operations Center
      • Web Security
    • Audits & Testing

      • Cyber Security Risk Assessments
      • Cyber Threat Intelligence
      • Digital Forensics & Incident Response (DFIR)
      • Penetration Testing
      • Vulnerability Management
    • Compliance

      • CMMC Compliance
      • CMMC 2.0 Requirements
      • Certification Audit Support
      • FedRAMP
      • FISMA
      • NIST 800-171
      • Readiness Assessment
      • RPO Support
      • 3PAO Support
  • Infrastructure
    • Infrastructure
    • On-Premises

      • Network Administration
      • Security Camera Installation
      • Server Consolidation
      • Server Installation & Maintenance
      • Server Migration
      • Structured Cabling
    • Cloud-Based

      • Cloud Migration
      • Cloud Hosting
      • Colocation Data Center
      • Virtualization
    • Phone & Telecom

      • PBX Phone Systems
      • SIP Phone Systems
      • Unified Communications (UCaaS)
      • VoIP Phone Systems
    • Data Centers

      • Compliance
      • Management
      • Relocation
      • Structured Cabling
  • Consulting
    • Consulting
    • IT Staff Augmentation
    • GSA Capabilities & Schedule 70
    • Security Awareness Training
    • Technical Support
    • Virtual CIO
    • Virtual CISO
  • Products
    • Products
    • Computers
    • Networking
    • Security Cameras
    • Servers
    • Telecommunications
  • About
    • About
    • Areas Served
    • Blog
    • Careers
    • Case Studies
    • Contact
    • Events
    • Industries
    • News
    • Team
  • Portal
  • Pay Now
  • Contact Advantage

DoW Pauses CMMC Phase II: Why NIST 800-171 Compliance Still Matters

July 24, 2026 · Advantage Technology · CMMC Compliance

DoW has suspended CMMC Phase II requirements. See what still applies, what the Reform Task Force review means, and how to stay audit-ready.

The Department of War (DoW) suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program effective July 13, 2026, roughly four months before the requirements were set to take effect on Nov. 10, 2026. The decision does not affect CMMC Level 1 self-assessments or a contractor’s underlying obligation to protect applicable federal data.

System hacked hologram notification appearing in front of a laptop.

CMMC Phase II is currently under a 60-day review, to be conducted by the CMMC Reform Task Force. This team is charged with finding realistic and scalable security measures that maintain compliance while also prioritizing speed to capability.

This review could reshape how the DoW verifies contractor cybersecurity for years to come. Small and mid-market defense contractors that have spent the past two years preparing for third-party assessments can take this time to use CMMC audit support services to stay ahead.

In This Article

  • What the Department of War Suspended, and What It Didn’t
  • What Still Applies During the Pause
  • The CMMC Reform Task Force and Its 60-Day Timeline
  • Why Self-Assessment Still Carries Legal Exposure
  • What the Review Could Mean for Small and Non-Traditional Contractors
  • What To Do During the CMMC Phase II Suspension

What the Department of War Suspended, and What It Didn’t

The suspension applies to CMMC Phase II, the phase that would have required many contractors to pass an assessment of Level 2 controls by a Certified Third-Party Assessor Organization (C3PAO). Phase I, which relies on self-assessment against Level 1 and Level 2 requirements, remains firmly in place.

During the suspension, contracting officers can only write CMMC Level 1 (Self) or Level 2 (Self) requirements into new solicitations and contracts. Level 2 Certification Assessments performed by accredited third-party assessment organizations, along with Level 3 government-led assessments, are temporarily suspended until the review concludes.

In the official release, Department of War Chief Information Officer (CIO) Kirsten A. Davies said, “In support of Secretary Pete Hegseth’s directive to reduce compliance barriers for small and medium sized businesses, we are today suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program.”

What Still Applies During the Pause

DFARS clause 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, still applies and remains the core DFARS cybersecurity clause for contracts involving covered defense information. The clause obligates contractors to implement the security requirements in NIST Special Publication 800-171 and to report cyber incidents to the department within 72 hours of discovery.

Software, coding hologram and woman on tablet looking at the code

The NIST published version 3 of SP 800-171 in May of 2024. However, the transition to that version isn’t expected until late 2026 or the middle of 2027. While the Task Force reviews CMMC Phase II, the DoW will enforce compliance against the NIST SP 800-171 Rev 2 standard through self-assessments and a smaller set of government-led assessments, according to the July 13 release.

The technical bar has not moved. The security requirements in SP 800-171 still apply, including encryption of controlled unclassified information at rest and in transit, multifactor authentication, access control, and incident response planning.

The CMMC Reform Task Force and Its 60-Day Timeline

To carry out the review, CIO Davies established the CMMC Reform Task Force to collect industry input through a public Request for Information on technical and operational compliance challenges. The deadline for the public to comment is August 14, 2026, after which the Task Force is expected to deliver a final report to the Department of War CIO around mid-September 2026.

“We have a strategic imperative to reduce bureaucracy as we build the world’s strongest Arsenal of Freedom,” said Hon. Michael Duffey, Under Secretary of War for Acquisition and Sustainment. “The CIO’s decision ensures we maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain.”

The Task Force’s mandate is to recommend scalable security measures that prioritize speed to capability and reduce barriers for small and non-traditional businesses, in line with Secretary Hegseth’s Acquisition Transformation System.

Why Self-Assessment Still Carries Legal Exposure

A shift from third-party certification back to self-assessment can look like a less thorough, lower-stakes credential. It isn’t. It doesn’t remove liability but changes where that liability sits. When a contractor self-attests to NIST SP 800-171 compliance, that attestation becomes the government’s record of the contractor’s security posture, and a false or unsupported attestation can trigger liability under the False Claims Act.

The Department of Justice has followed this course since October 2021, when it launched the Civil Cyber-Fraud Initiative. Under this legal theory, contractors are accountable for knowingly misrepresenting their cybersecurity practices or failing to implement controls they certified as in place.

For contractors relying on self-assessment during the CMMC pause, an accurate System Security Plan and a documented Plan of Action and Milestones matter as much as the underlying controls themselves.

What the Review Could Mean for Small and Non-Traditional Contractors

The DoW cited data from the Small Business Administration showing that CMMC compliance costs were pushing smaller and non-traditional companies out of the defense industrial base. This was causing delays in the delivery of capabilities the department needs. The Small Business Administration publicly welcomed the suspension on those grounds.

The outcome of the review and any recommendations the Task Force offers will not be known until the report reaches CIO Davies. The announcement made clear that CMMC Phase II compliance costs were forcing small and non-traditional contractors out of the defense industrial base, and that access to those companies’ capabilities is central to Hegseth’s Arsenal of Freedom initiative.

Taken together, one possible outcome is that the Task Force will recommend security requirements that scale with a contractor’s size and risk profile rather than applying one certification tier across the board.

What To Do During the CMMC Phase II Suspension

The contractors best positioned when Phase II requirements return, in whatever form the Task Force recommends and CIO Davies enacts, will be those that maintained and kept building toward NIST SP 800-171 during the interim. That means maintaining current System Security Plans, closing out open Plans of Action and Milestones, and being able to demonstrate that controls are operating as documented.

Man using a computer with two monitors that show coding.

For defense contractors trying to make sense of what changed on July 13 and what to do about it, the fastest way through is usually a conversation with someone who has already read the memo, the RFI, and the underlying NIST controls. That is the conversation we have with clients across the defense industrial base every week right now.

Advantage.Tech works with organizations in regulated sectors to assess NIST SP 800-171 posture, document control implementation through defensible System Security Plans and Plans of Action and Milestones, and prepare for whatever assessment structure the Department of War ultimately adopts. Our CISSP-certified engineers do this work in plain English, without the jargon that usually surrounds compliance conversations, and we walk clients through what the requirements mean for their specific contracts rather than handing over a generic checklist. Contact Advantage.Tech to schedule a compliance readiness review and get a clear picture of where your organization stands during the CMMC transition.

Let's Talk About Your Ideas

Toll-Free: 866-497-8060
support@advantage.tech

Charleston, WV

950 Kanawha Blvd E. #100 / Charleston, WV 25301
V: 304-973-9537 | F: 304-720-1423

Bridgeport, WV

1509 Johnson Avenue / Bridgeport, WV 26330
V: 304-973-9550

Frederick, MD

8 East 2nd St. #201 / Frederick, MD 21701
V: 240-685-1255

"*" indicates required fields

Full Name*
This field is hidden when viewing the form
Send Now

Advantage Tech logo light

Since the early 2000's, Advantage Technology has been providing reliable managed IT services to organizations across a range of industry types. With multiple offices located in West Virginia and Maryland, we tailor our IT solutions to the unique needs and requirements of businesses throughout the Mid-Atlantic region.


Company

  • About
  • Areas Served
  • Blog
  • Careers
  • Case Studies
  • Contact
  • Events
  • Industries
  • News
  • White Papers
  • Team
  • Request Consultation

Managed IT

  • Antivirus & Spam Filtering
  • Data Backup & Recovery
  • IT Help Desk
  • Maintenance & Support
  • Remote Monitoring & Management

Cybersecurity

  • Services & Solutions
  • Audits & Testing

Infrastructure

  • On-Premises
  • Cloud-Based
  • Phone & Telecom

AI

  • Agents & Automation Consulting
  • Fraud Detection
  • Inside Advantage.Tech
  • Managed IT & Service Desk
  • Security Customization
  • Tools & Platforms
  • Training & Workforce Enablement

Consulting

  • IT Staff Augmentation
  • GSA Capabilities & Schedule 70
  • Security Awareness Training
  • Technical Support
  • Virtual CIO
  • Virtual CISO

Link to company Facebook page

Link to company Instagram page

Link to company LinkedIn page

Link to company Twitter page

Link to company YouTube page

© Copyright 2026 | Powered by 321 Web Marketing

Connecting to Albert…

Albert

Connecting…