Latest CMMC News
On July 13, 2026, the Department of War (DoW) announced the immediate suspension of CMMC Phase II requirements, which were scheduled to take effect November 10, 2026, and initiated a comprehensive 60-day review of the program. See the Q&A section below for common questions about this announcement.
Get In touchCMMC Questions & Answers
Before this announcement, the expectation was that DoW contracts requiring a contractor to store, process, or transmit Controlled Unclassified Information (CUI) would begin including requirements for obtaining CMMC Level 2 assessments by November 10, 2026. Compliance could be demonstrated through either a self-assessment or certification from an authorized CMMC 3rd Party Assessment Organization (C3PAO).
After this announcement, the requirement to obtain a CMMC 3rd Party Assessment from a C3PAO is suspended while the DoW reviews requirements over the next two months. However, the requirements to protect Controlled Unclassified Information (CUI) remain unchanged.
Federal Contractors MUST still:
- Protect CUI according to NIST SP 800-171 Rev 2.
- Complete CMMC Phase 1 obligations, including SPRS scoring and annual affirmations.
- Comply with DFARS 252.204-7012 requirements including safeguarding CUI and incident reporting.
- Use FedRAMP Moderate (or equivalent) cloud technologies when handling CUI.
- Comply with FAR 52.204-21 safeguarding requirements.
- Comply with ITAR/EAR data sovereignty requirements.
- Maintain an accurate SPRS score in PIEE (for DoW contractors).
Federal Contractors who have not implemented NIST SP 800-171 may already be out of compliance if their contracts contain the required clauses.
Risks include:
- Loss of contract due to non-compliance.
- DIBCAC may select your organization for a Medium and/or High assessment at any time.
- The Department of Justice (DOJ) may pursue False Claims Act actions for non-compliance with DFARS 252.204-7012 obligations, potentially resulting in significant fines and criminal penalties.
Absolutely not. C3PAOs continue conducting assessments. Many prime contractors still require certification from an authorized C3PAO to ensure their supply chain has appropriate security controls in place and to reduce risk.
Benefits include:
- CMMC certification provides a competitive advantage when bidding on Federal contracts.
- Demonstrates your organization's commitment to securing Federal information.
- Reduces the risk of contract termination due to NIST SP 800-171 deficiencies.
- Reduces the likelihood of reportable cybersecurity incidents.
DeMase is a CMMC 3rd Party Assessment Organization (C3PAO) providing certification assessments and cybersecurity consulting services.
Our team includes experts in NIST SP 800-171, NIST SP 800-172, NIST SP 800-53, NIST SP 800-82, NN-801, and other regulatory frameworks.
We partner with clients to understand their compliance and operational requirements, delivering tailored solutions including:
- Compliance consulting and readiness services.
- Custom information system and enclave design.
- CMMC assessment and certification support.
- Managed IT and cybersecurity services.
- Long-term compliance and operational support.
Ensure Your Compliance Today
Ensure your business is protected with our expert CMMC compliance solutions. Reach out to us now to safeguard your information and maintain a competitive edge in the industry.
Contact Us Now