Page 1 of 1

SME Questionnaire Form - August 25

Publication Target Date: Aug 25

Submission Deadline: Aug 12

Article Working Title: CMMC Phase II suspended: What the 60-day reform window means for defense contractor compliance

Editorial Brief: DoW CIO Kirsten Davies has suspended CMMC Phase II, including third-party assessment requirements due to begin November 10, 2026, citing the cost burden on small and non-traditional defense contractors. A new CMMC Reform Task Force will conduct a 60-day review, with recommendations expected by mid-September.

During the pause, Program Managers may require only CMMC Level 1 or Level 2 self-assessments. C3PAO and DIBCAC requirements, waivers, and later implementation phases are also suspended. NIST SP 800-171 Rev. 2 and DFARS 252.204-7012 obligations remain in force.

The article will examine what the pause means for contractor investment, self-attestation risk, subcontractor flow-down requirements, possible alternatives to third-party assessment, and the future of the CMMC assessor ecosystem.

About you

First Name

Last Name

Company/Organization

Job Title/Designation (to be used in feature)

Business Email

Short Bio

Upload headshot (JPG/PNG up to 5MB; Square 500×500px, 300 DPI recommended)

Question Set

Contractors have already invested significant time and money preparing for C3PAO assessments. How much of that work is likely to remain relevant after the 60-day review, and where is the greatest risk of those investments becoming stranded?

DoW says the suspension does not change contractors’ underlying NIST SP 800-171 and DFARS obligations, only the requirement for third-party verification. Does the pause materially reduce contractors’ compliance risk, or simply shift that risk toward self-attestation, government audits, and potential False Claims Act exposure?

How should subcontractors respond when prime contractors continue to flow down CMMC Level 2 certification requirements despite the federal pause? Can subcontractors reasonably challenge those requirements, or do they remain binding contractual conditions regardless of DoW’s implementation timeline?

What would a scalable and realistic alternative to universal third-party assessment look like? Can DoW reduce the burden on small and non-traditional contractors while maintaining a credible security and verification baseline?

If the task force recommends greater reliance on self-assessments supported by targeted government audits, what would that mean for C3PAOs and the broader CMMC consulting ecosystem? How should contractors currently engaged with assessment firms approach those relationships during the review period?

Thank you for your response!