# DoW Reviews CMMC Phase 2

A sponsored Help Net Security article argues that AI-enabled, continuous cybersecurity operations could help small and midsize federal contractors maintain CMMC and other cybersecurity controls while reducing manual evidence collection and audit work. It reports that the Department of War suspended CMMC Phase 2 for a 60-day review in July 2026, while contractor obligations remain. The reported review period has elapsed by October 8, 2026, but the signal does not state its outcome; it describes no solicitation, contract award, or new procurement action.

- Contractors can evaluate continuous monitoring and evidence-collection tools as a way to reduce manual compliance workloads, while verifying that any tool supports their applicable CMMC controls.
- The reported pause should not be treated as a cancellation of contractor obligations; procurement and security teams should distinguish the Phase 2 review from the requirements the article says remain in effect.
- Because the article is sponsored and promotes an AI-based approach, buyers should assess vendor claims against their actual compliance and audit needs rather than treating the article as official DoW guidance.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 08, 2026

### Government Entities
- Department of War (DoW)

### Vendors
- Espresso Labs ()

### Sources
- [How AI can fix cybersecurity compliance: From dashboards to continuous execution - Help Net Security](https://www.helpnetsecurity.com/2026/10/08/espresso-labs-ai-cybersecurity-compliance) - Help Net Security