# Department of War Suspends CMMC Phase 1 Implementation

The Department of War (DoW) has suspended the Phase 1 implementation of the Cybersecurity Maturity Model Certification (CMMC) program, which initially required contractor assessments starting November 10, 2025. Despite the suspension, contractors handling Controlled Unclassified Information (CUI) must comply with CMMC Level 2 self-assessments based on NIST SP 800-171 Revision 2, with plans to update to Revision 3 in the future. The program applies broadly to all contractors, including non-U.S. entities, and mandates flow-down of cybersecurity requirements to subcontractors. Cloud Service Providers must meet FedRAMP Moderate or equivalent standards when handling CUI, while Managed Service Providers are included in assessment scopes but do not require separate certification. Changes to systems require careful management to maintain compliance, with reassessments triggered by significant modifications.

- **Why this matters:** Procurement professionals should note the suspension of Phase 1 does not remove existing CMMC compliance obligations, particularly for contractors managing CUI.
- Organizations must continue to implement and document cybersecurity controls per NIST SP 800-171 Rev 2 and prepare for future updates to Rev 3.
- Cloud and Managed Service Providers supporting DoW contracts must align with FedRAMP Moderate standards and understand their roles in compliance assessments.
- Contractors should plan for potential reassessments following significant system changes and ensure flow-down of requirements to subcontractors to maintain contract eligibility.

**Jurisdictions:** federal
**Industries:** Defense & Military
**Topics:** Cybersecurity
**Published:** September 15, 2026

### Government Entities
- Department of War (DoW)
- Cybersecurity Maturity Model Certification Program Management Office (CMMC PMO)
- National Institute of Standards and Technology (NIST)

### Key Quotes
> Costs incurred to implement existing contract requirements for safeguarding information (e.g., DFARS clause 252.204-7012) are not considered part of the CMMC compliance cost. However, the cost of achieving CMMC compliance depends on factors including required CMMC level and cybersecurity posture.
> — Original poster

### Sources
- [Control 3.13.11 - Employ FIPS](https://www.reddit.com/r/CMMC/comments/1wh144i/control_31311_employ_fips) - reddit-cmmc