DOW SUSPENDS CMMC PHASES 2-4
On July 13, 2026 the United States Department of War (“DoW“) issued a memorandum suspending Phases 2-4 of the Cybersecurity Maturity Model Certification (“CMMC“) Program. The memorandum also announced that the CMMC Program will subject to top-to-bottom review by a “CMMC Review Task Force”. DoW expects the CMMC Review Taks Force to issue its report no earlier than mid-October 2026.
The suspension does not impact Peak InfoSec’s ability to conduct CMMC Mock or Level 2 (C3PAO) Certification Assessments, and Peak InfoSec is actively assessing defense contractors. Contact us to schedule your assessment or for help implementing the NIST SP 800-171 requirements.
From compliance to capability, Peak InfoSec is your 360° cybersecurity partner. We deliver accredited CMMC assessments, expert consulting, tailored training, and on-demand staffing solutions to fortify your security posture, streamline regulatory readiness, and empower your team. Let us shoulder the complexity — you focus on growth.
Ready for your CMMC Level 2 Certification Assessment? Peak InfoSec has been a fully-authorized Cybersecurity Maturity Model Certification (“CMMC“) 3rd Party Assessment Organizations (“C3PAO“) since 2022, the year The Cyber AB began authorizing C3PAOs. When your organization is ready for its CMMC Certification Assessment, trust Peak InfoSec to deliver a high-quality, fair assessment.
Want to take some of the pressure off of your CMMC Level 1, Level 2, and Level 3 annual affirmations? Let us review everything, ensure your records up to date, and issue a Letter of Attestation of Compliance.
Need help getting ready for your CMMC or ISO Certification Assessment? Put our experience to work for your company. Peak InfoSec’s team includes highly skilled assessors, educators, and more to help your organization feel confident in its CMMC and/or ISO compliance programs, and beyond!
Does your staff need help understanding Controlled Unclassified Information (“CUI“), Federal Contract Information (“FCI“), or CMMC? Peak InfoSec’s experts literally wrote the book(s) on CUI and CMMC! Learn from the best!
Thinking of Becoming a CMMC Certified Professional (“CCP“) or CMMC Certified Assessor (“CCA“)? Peak InfoSec’s instructors are some of the most experienced and trusted practitioners in the CMMC Ecosystem. We help you learn not only how to pass the CCP and CCA exams, but also how to successfully help your clients create and maintain their CMMC programs.
As an Authorized Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessment Organization (C3PAO), Peak InfoSec provides CMMC Level 2 Mock Assessments and formal Certification Assessments.
At Peak InfoSec, we equip businesses and professionals with the knowledge and support needed to thrive in today’s cyber landscape. Our team blends deep industry expertise with a proactive approach, helping organizations strengthen compliance, protect operations, and build long-term resilience.
We offer a full range of services, from Gap Assessments to Certification Assessments
Building your cybersecurity practices from CMMC to FISMA to ISO to NIST
Building your future with cybersecurity training
Subject Matter Experts to support you organization before and during litigation, including as Expert Witnesses
Validation that your information security program meets requirements specified in the FAR, DFARS, CMMC, and more!
Expert guidance on NIST SP 800-171, CMMC assessments, and cybersecurity frameworks.
Prepare your team with CCP, CCA, and executive training programs designed for real-world application.
Learn how to identify, safeguard, and disseminate Controlled Unclassified Information correctly.
As an Authorized Cybersecurity Maturity Model Certification (CMMC) Third-Party Assessment Organization (C3PAO).
Gain the skills, certifications, and hands-on training you need to stand out in today’s cybersecurity field.
Tailored for leaders—understand compliance risks and strategic responses.
Take the mystery out of the Controlled Unclassified Information (CUI) program and learn how to properly handle CUI as a contractor, or state and local government employee.
Free, pro bono resources for the Defense Industrial Base (DIB) to aid NIST SP 800-171 implementation, documentation, and preparation for CMMC Conformity Assessments. No guarantees or support provided.
CMMC will have a big impact on small businesses. We have collected a set of resources, including our own content, to help small businesses more cost-effectively prepare for CMMC.
Cybersecurity isn’t just about defense — it’s about confidence, growth, and resilience. At Peak InfoSec, we provide the training, consulting, and assessment solutions that empower your organization to operate securely today and prepare for tomorrow.
The Department of War (DoW) Chief Information Security Officer (CIO) suspended the transition to CMMC Phase 2 on 13 July 2026. This created quite a bit of confusion in the CMMC Ecosystem. We are sharing the following FAQs to clarify what is going on.
You can also find The Cyber AB’s Press Release at https://cyberab.org/News-Events/Press-Releases/statement-on-the-department-of-wars-suspension-of-cmmc-phase-ii-requirements#!%23article-title.