# DoD Suspends CMMC Phase 2 Requirements

The Department of Defense suspended Cybersecurity Maturity Model Certification (CMMC) Phase 2 requirements as of July 13, 2026, pending a comprehensive reform review. Despite this suspension, contractors must continue to comply with Phase 1 mandates, including adherence to DFARS 7012 cybersecurity clauses, conducting self-assessments, maintaining Supplier Performance Risk System (SPRS) scores, and fulfilling pre-award conditions such as annual affirmations and flow-down requirements. Notably, inflated SPRS scores remain subject to false claims liability, underscoring the ongoing importance of accurate cybersecurity reporting and compliance for defense contractors.

- **Why this matters:** Procurement professionals and contractors must maintain vigilance in meeting existing cybersecurity requirements despite the suspension of Phase 2, ensuring contract eligibility and avoiding legal risks.
- The suspension signals potential future changes in DoD cybersecurity standards, requiring organizations to stay informed on reform outcomes.
- Companies should continue using the 12-tab workbook tools for tracking practices, SPRS weights, and Plans of Action and Milestones (POA&M) to support compliance.
- This development affects contract award readiness and risk management strategies within the defense supply chain.

**Jurisdictions:** federal
**Industries:** Defense & Military
**Topics:** Cybersecurity
**Published:** September 29, 2026

### Government Entities
- Department of Defense (DoD)

### Sources
- [CMMC Phase 2 is suspended, not gone. DFARS 7012, the SPRS score and Phase 1 self-assessments still apply. 12-tab workbook: 110 practices, SPRS weights, POA&amp;M tracker. https://t.co/pBB038IvMW #CMMC #CyberCompliance https://t.co/fdkHzB28iy](https://x.com/CisoMarketplace/status/2104854449248194982) - twitter-regulatory