DOW SUSPENDS CMMC PHASES 2-4

On July 13, 2026 the United States Department of War (“DoW“) issued a memorandum suspending Phases 2-4 of the Cybersecurity Maturity Model Certification (“CMMC“) Program. The memorandum also announced that the CMMC Program will subject to top-to-bottom review by a “CMMC Review Task Force”. DoW expects the CMMC Review Taks Force to issue its report no earlier than mid-October 2026.

The suspension does not impact Peak InfoSec’s ability to conduct CMMC Mock or Level 2 (C3PAO) Certification Assessments, and Peak InfoSec is actively assessing defense contractors.  Contact us to schedule your assessment or for help implementing the NIST SP 800-171 requirements.

CMMC Certifications Consulting Training 

Let us help.

From compliance to capability, Peak InfoSec is your 360° cybersecurity partner. We deliver accredited CMMC assessments, expert consulting, tailored training, and on-demand staffing solutions to fortify your security posture, streamline regulatory readiness, and empower your team. Let us shoulder the complexity — you focus on growth.

Certifications -

Ready for your CMMC Level 2 Certification Assessment? Peak InfoSec has been a fully-authorized Cybersecurity Maturity Model Certification (“CMMC“) 3rd Party Assessment Organizations (“C3PAO“) since 2022, the year The Cyber AB began authorizing C3PAOs.  When your organization is ready for its CMMC Certification Assessment, trust Peak InfoSec  to deliver a high-quality, fair assessment.

Attestations -

Want to take some of the pressure off of your CMMC Level 1, Level 2, and Level 3 annual affirmations?  Let us review everything, ensure your records up to date, and issue a Letter of Attestation of Compliance.

Consulting -

Need help getting ready for your CMMC or ISO Certification Assessment?  Put our experience to work for your company.  Peak InfoSec’s team includes highly skilled assessors, educators, and more to help your organization feel confident in its CMMC and/or ISO compliance programs, and beyond!

Custom Training -

Does your staff need help understanding Controlled Unclassified Information (“CUI“), Federal Contract Information (“FCI“), or CMMC?  Peak InfoSec’s experts literally wrote the book(s) on CUI and CMMC!  Learn from the best!

CMMC Training -

Thinking of Becoming a CMMC Certified Professional (“CCP“) or CMMC Certified Assessor (“CCA“)?  Peak InfoSec’s instructors are some of the most experienced and trusted practitioners in the CMMC Ecosystem.  We help you learn not only how to pass the CCP and CCA exams, but also how to successfully help your clients create and maintain their CMMC programs.

CMMC Certifications

As an Authorized Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessment Organization (C3PAO), Peak InfoSec provides CMMC Level 2 Mock Assessments and formal Certification Assessments.

NIST SP 800-171 Rev. 2 Assessment Objectives Reviewed
0
Learn from the best

Delivering Cybersecurity Solutions That Help You Work Smarter

At Peak InfoSec, we equip businesses and professionals with the knowledge and support needed to thrive in today’s cyber landscape. Our team blends deep industry expertise with a proactive approach, helping organizations strengthen compliance, protect operations, and build long-term resilience.

Cybersecurity Assessments

We offer a full range of services, from Gap Assessments to Certification Assessments

Cybersecurity Compliance Consulting Services

Building your cybersecurity practices from CMMC to FISMA to ISO to NIST

CMMC and CUI Training

Building your future with cybersecurity training

Cybersecurity Subject Matter Experts

Subject Matter Experts to support you organization before and during litigation, including as Expert Witnesses

Our Value

Your Security, Our Expertise.

Cybersecurity shouldn’t be complicated. At Peak InfoSec, we make it clear, reliable, and results-driven. Our team delivers scalable training, consulting, and virtual cyber compliance officer, and virtual chief information security officer solutions that keep your systems secure today and resilient tomorrow.
Our Mission

Protecting Your Business With Proactive Cybersecurity

We exist to equip organizations with the knowledge, strategies, and professionals needed to stay ahead of evolving threats—so you can focus on growth without fear of disruption.
Our Vision

Shaping a Future Where Businesses Operate Without Cyber Risk

We envision a future where compliance, security, and innovation work hand in hand—empowering organizations to thrive in a digital world with confidence.
Consulting Clients Have Earned
CMMC Level 2 Certifications
0 +
CMMC Gap, Validation, Mock, and Certification Assessments Conducted by Our Teams
0 +
Students Taught About Cyber,
CMMC, and CUI by Our Instructors
0 +
Our Services

Let Us Handle Cybersecurity, So You Can Focus on What Matters.

We deliver a complete suite of cybersecurity training, consulting, and staffing services designed to strengthen compliance, protect data, and empower people.
Assessments

Validation that your information security program meets requirements specified in the FAR, DFARS, CMMC, and more!

Compliance Consulting

Expert guidance on NIST SP 800-171, CMMC assessments, and cybersecurity frameworks.

CMMC Training & Certifications

Prepare your team with CCP, CCA, and executive training programs designed for real-world application.

CUI Training

Learn how to identify, safeguard, and disseminate Controlled Unclassified Information correctly.

75+ Years
Collective instructor and consultant experience in CMMC, compliance, and cybersecurity
4,000+
Hours donated to help The Cyber AB create the CMMC Ecosystem
What we offer

Delivering cybersecurity training and consulting that enable you to work smarter.

As an Authorized Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessment Organization (C3PAO).

Gain the skills, certifications, and hands-on training you need to stand out in today’s cybersecurity field.

Executive Cybersecurity Bootcamps

Tailored for leaders—understand compliance risks and strategic responses.

CUI Training Programs

Take the mystery out of the Controlled Unclassified Information (CUI) program and learn how to properly handle CUI as a contractor, or state and local government employee.

Essential Compliance Templates

Free, pro bono resources for the Defense Industrial Base (DIB) to aid NIST SP 800-171 implementation, documentation, and preparation for CMMC Conformity Assessments. No guarantees or support provided.

Small Business Resources

CMMC will have a big impact on small businesses. We have collected a set of resources, including our own content, to help small businesses more cost-effectively prepare for CMMC.

Let us change the way you think about security.

Cybersecurity isn’t just about defense — it’s about confidence, growth, and resilience. At Peak InfoSec, we provide the training, consulting, and assessment solutions that empower your organization to operate securely today and prepare for tomorrow.

Department of War CMMC Phase 2 Frequently Asked Questions

The Department of War (DoW) Chief Information Security Officer (CIO) suspended the transition to CMMC Phase 2 on 13 July 2026.  This created quite a bit of confusion in the CMMC Ecosystem.  We are sharing the following FAQs to clarify what is going on.
You can also find The Cyber AB’s Press Release at https://cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements#!%23article-title.

Has the CMMC Program been shut down?

No. All CMMC program elements remain operational and available, to include C3PAO Level 2 certification assessments, CAICO-sanctioned training courses, CMMC professional exams, Registered Practitioner support services, and the DIBCAC’s assessment of C3PAOs and candidate C3PAOs.​ A press release regarding this is available from The Cyber AB at https://cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements

What did the Department of War (DoW) do?

DoW suspended the start of the CMMC Program Phase 2 rollout, which would have introduced “the requirement for CMMC Status of Level 2 (C3PAO) for applicable DoD solicitations and contracts as a condition of contract award” on 10 November.

What does this mean in our contracts with DoW?

DoW suspended the inclusion of the Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7021, “Compliance with the Cybersecurity Maturity Model Certification Level Requirements,” for CMMC Level 2 Certifications by a CMMC 3rd Party Assessment Organization (C3PAO) and for Level 3 assessments by the Defense Industrial Base Cybersecurity Assurance Center (DIBCAC).

What organizations in the Defense Industrial Base (DIB) does this affect?

The suspension of CMMC Program Phase 2 rollout is ONLY applicable to contracts awarded between DoW and the awarded contractor.

Does this affect our organization's contract with our prime?

The suspension of CMMC Program Phase 2 does not negate any contractual requirements from your primes if they require your organization to be CMMC Level 2 certified.

What contract clauses are still in effect?

The following DFARS Clauses are still in full effect for awarded contracts and related flow downs to suppliers: 252.204–7012: Safeguarding Covered Defense Information and Cyber Incident Reporting; 252.204–7019: Notice of NIST SP 800-171 DoD Assessment Requirements; 252.204–7020: NIST SP 800-171 DoD Assessment Requirements; 252.204–7021: Cybersecurity Maturity Model Certification Requirements; 252.204–7024: Notice on the Use of the Supplier Performance Risk System; and 252.204–7025: Notice of Cybersecurity Maturity Model Certification Level Requirements

What should we expect to see in the near term?

DIB companies will still see DFARS Clause 252.204-7021 requiring your organization to self-affirm your protections around CMMC Level 1 for Federal Contract Information (FCI) and CMMC Level 2 for Controlled Unclassified Information (CUI).

Can my prime contractor still require our organization to get CMMC Level 2 Certified?

Yes. That is a Business-to-Business contractual obligation.

What is the impact of the adoption of NIST SP 800-171 Revision 3 by the DIB?

This will further delay changes and add complications requiring your organization to migrate to NIST SP 800-171 Revision 3, at least until the new Federal Acquisition Regulation (FAR) CUI begins to show up next year.

If DIBCAC stopped doing CMMC Level 3 Assessments, what will they be doing?

Given that DIBCAC has ceased efforts to begin CMMC Level 3 Assessments, DoW will likely use this increased availability to step up its non-voluntary DFARS Clause 252.204-7012 audits by DIBCAC during this period. This will lead to increased False Claim Act charges filed by Department of Justice (DoJ),

Has the DoW directed any changes to the ecosystem?

No. The DoW has not directed any changes to The Cyber AB for program elements under its purview.

Can Peak InfoSec still conduct our CMMC Level 2 Certification Assessment?

Yes. C3PAOs continue conducting CMMC Level 2 Mock and Certification Assessments in support of CMMC Phase 2 being restarted and prime contractor flowdown requirements.

What about SPRS and CMMC eMASS? Can you still submit our results?

Yes. The Supplier Performance Risk System (SPRS) and CMMC Enterprise Mission Assurance Support Service (eMASS) remain open for C3PAOs to submit organization Certification Assessment results.

Should we still get certified?

Yes. DoW has paused Phase 2 and can reinstate it at anytime. Organizations that have a CMMC Level 2 Certification from a C3PAO will retain competitive advantage over their peers within the prime’s supply chains.

Does getting certified protect our organization from a FCA charge?

Organizations that have a CMMC Level 2 Certification from a C3PAO and have not withheld information during the assessment have increased protections against False Claims Act (FCA) charges by demonstrating due diligence.

Does this also suspend the Phase 2 step during an assessment?

There is no correlation between the DOW’s suspension of CMMC Program Phase 2 date to a suspension of “PHASE 2 – Assess Conformity To Security Requirements” under the CMMC Assessment Process (CAP) version 2.0.