The Department of Defense (DoD) Chief Information Officer CIO suspended implementation of the Cybersecurity Maturity Model Certification (CMMC) Phase II on July 13, 2026 and launched a CMMC Review and Reform Task Force to reassess the CMMC program, reduce compliance burdens, and gather direct industry feedback regarding future cybersecurity requirements. Based on the recently issued suspension memorandum and accompanying request for information (RFI), defense contractors should evaluate the potential impact on their compliance strategies and consider participating in the comment process before the August 14, 2026, deadline.
We recently published an update on these developments. Read the full insight here.