# Department of War Suspends CMMC Phase 2

The Department of War (DoW) has officially suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program, delaying the mandatory third-party assessments and certifications that were scheduled to begin in November 2026. This suspension follows the establishment of a CMMC Reform Task Force tasked with reviewing the program's scope, including potential roll-backs or expansions. A comprehensive report from the Task Force is due to the DoW Chief Information Officer, Kirsten Davies, in September 2026. In the interim, contractors must continue to perform self-assessments and maintain compliance with existing cybersecurity requirements under DFARS and NIST standards.

- **Why this matters:** The suspension impacts contractors preparing for mandatory third-party CMMC certification, requiring adjustments to compliance strategies and timelines.
- Contractors should maintain rigorous self-assessment practices to meet current DFARS and NIST cybersecurity requirements despite the delay.
- Procurement professionals should anticipate potential changes in cybersecurity certification requirements pending the Task Force report, which may affect future contract eligibility and evaluation criteria.
- Organizations involved in DoW contracts should monitor official communications closely for updates following the Task Force's recommendations to ensure ongoing compliance and competitive positioning.

**Jurisdictions:** federal
**Industries:** Defense & Military
**Topics:** Cybersecurity
**Published:** September 21, 2026

### Government Entities
- Department of War (DoW)

### Sources
- [CMMC Reform Task Force Updates September 2026 | Inside Government Contracts](https://www.insidegovernmentcontracts.com/2026/09/cmmc-reform-task-force-updates-september-2026) - Inside Government Contracts