accessibilityalertarrow-downarrow-leftarrow-rightarrow-upchevron-downchevron-leftchevron-rightchevron-upclosedigital-transformationdiversitydownloaddrivedropboxeventsexitexpandfacebookguideinstagramjob-pontingslanguage-selectorlanguagelinkedinlocationmailmenuminuspencilphonephotoplayplussearchsharesoundshottransactionstwitteruploadwebinarwp-searchwt-arrowyoutube
Client Alerts Client Alerts

CMMC Phase II suspended: what changes and what does not for European suppliers to the US defence industrial base

DoW has suspended third-party certification. For European suppliers, the compliance risk moves out of the regulation and into the subcontract.

The announcement

On 13 July 2026 the US Department of War (DoW) announced the immediate suspension of Phase II of the Cybersecurity Maturity Model Certification (CMMC) programme, which had been due to take effect on 10 November 2026. Phase II would have made assessment by a certified third-party assessment organisation (C3PAO) a condition of award for most contracts involving Controlled Unclassified Information (CUI). The suspension is set out in a memorandum dated 10 July 2026 signed by DoW Chief Information Officer, which places the Phase III and Phase IV milestones in abeyance and establishes a CMMC Reform Task Force to conduct a comprehensive review of the programme within 60 days. The stated rationale is cost: DoW cited evidence that compliance was pushing small and non-traditional suppliers out of the Defence Industrial Base at a time when their capabilities are most needed.

For European suppliers who had begun preparing for a November certification gate or had concluded that the certification gate was sufficient reason to stay out of US supply chains altogether, this announcement reopens a decision that many had already made. It is not, however, an invitation to relax.

1. What was suspended and what survives

The suspension removes a procurement gate. It does not remove a security obligation. Phase I remains firmly in place, including Level 1 and Level 2 self-assessments, submission of scores to the Supplier Performance Risk System (SPRS) and annual affirmations. DFARS 252.204-7012 continues to apply as the baseline contractual obligation to safeguard covered defence information and NIST SP 800-171 Rev. 2 remains the applicable control framework, now enforced through self-assessments and select government-led assessments rather than third-party certification.

The practical consequence is narrow but important. A supplier whose control environment does not meet the 110 requirements of NIST SP 800-171 remains in materially the same contractual position after the suspension as it would have been under Phase II. What has changed is who verifies compliance and when.

2. Bids and contracts in flight

DoW has directed that active solicitations and contracts containing a CMMC Level 2 (C3PAO) or Level 3 requirement must be amended to remove it. Suppliers do not need to seek relief; the relief is being provided automatically.

This cuts in two directions. Where certification was a barrier to bidding, the barrier is being removed through amendment. Where a supplier invested early and priced on the assumption that less-prepared competitors would be excluded, that competitive advantage is no longer secured by the solicitation and bid economics should be revisited. Bid teams should identify affected solicitations now and monitor amendments as they are issued.

Subcontract terms present the more acute challenge. Provisions drafted against the Phase II timetable, including definitions, conditions precedent, milestone dates and termination triggers linked to a certification requirement that will no longer apply, now reference a regulatory event that no longer exists. Those clauses should be reviewed and amended before either party attempts to rely on them.

3. Flow-down in the vacuum

This is the point of greatest practical significance for CEE suppliers and it may appear counterintuitive in light of the announcement.

Until last week, a prime contractor could treat a CMMC certificate as objective, standardised, third-party evidence that a supplier protected CUI adequately. With Phase II suspended, that evidence will largely be unavailable. The prime contractor’s own obligation to safeguard CUI and flow requirements down to subcontractors at all tiers remains unchanged, as does its exposure if a supplier fails to comply. Prime contractors are unlikely to absorb that risk. Instead, they are likely to substitute their own supplier assurance regimes, including questionnaires, contractual representations and warranties, audit and inspection rights, evidence packages, remediation undertakings and indemnities.

Risk therefore migrates from regulation into the subcontract. A regulatory gate is predictable, standardised and identical for every participant. A privately imposed assurance regime is negotiable, asymmetric and drafted by the counterparty. For suppliers whose contracts are typically issued on the prime contractor’s paper and whose negotiating leverage is limited, the second environment may prove more demanding than the first. Suppliers should expect to be asked to represent compliance rather than to demonstrate it through certification. Those representations should be reviewed with the same care afforded to warranties in a share purchase agreement because, functionally, that is what they are.

4. Enforcement asymmetry

The certification gate has softened. Exposure for inaccurate representations has not. The US Department of Justice continues to pursue cybersecurity misrepresentations under the False Claims Act through its Civil Cyber-Fraud Initiative and, as recently as June 2026, announced resolutions involving both small and large contractors based on alleged failures to implement NIST SP 800-171 controls and inaccurate SPRS scores. Self-assessments and annual affirmations remain government-facing representations and continue to be actionable, with treble damages potentially available.

The resulting position is uncomfortable. The least burdensome compliance route now available is also the one carrying the greatest legal exposure. A self-assessment supported by a documented, tested and demonstrable control environment is a defensible statement. A self-assessment supported only by an intention to comply may become the basis for a false claim. The removal of an independent assessor does not reduce the evidentiary burden; it means that a company’s own records become the primary evidence supporting its compliance position.

5. Investment already made

Readiness spending is not lost. DoW has stated that suppliers which improved their cybersecurity posture in anticipation of the deadline contributed to security rather than wasting resources. The underlying NIST SP 800-171 obligations that this spending was intended to address remain unchanged. For companies part-way through readiness efforts, the sensible course is to complete the work to the point at which the control environment is documented, tested and demonstrable. This is precisely the evidence base likely to be required both under DFARS 252.204-7012 and under any prime contractor-imposed assurance regime. Beyond that point, organisations may wish to pause planned assessment engagements unless a specific customer requires them. Any committed C3PAO engagement fees should be reviewed against the cancellation and suspension provisions of the relevant engagement letter.

6. The next decision points

DoW has issued a public Request for Information (RFI) seeking industry input on cost drivers, administrative burden, which NIST SP 800-171 controls provide meaningful risk reduction and whether commercial cybersecurity tools and managed services could be recognised in lieu of separate assessments. Responses are due by 14 August 2026. The Reform Task Force is expected to report to the DoW Chief Information Officer by mid-September 2026.

Two observations follow. First, the questions being asked suggest reform rather than elimination and raise the possibility of a successor programme requiring fewer than all 110 controls. Second, the RFI presents a genuine opportunity for participation. Nothing prevents submissions from suppliers outside the United States and relatively few are expected. Allied suppliers bearing the cost of duplicated assurance regimes have a distinct perspective to offer and this is the window in which to do so.

7. No reciprocity and no change to that

As discussed in our March 2026 alert on NIS2 and CMMC, the position of the accreditation body is that CMMC provides no reciprocity with ISO/IEC 27001, NIS2 or GDPR. International contractors are expected to comply with the same requirements as US contractors, without national equivalency or an alternative compliance pathway. The suspension does not alter that position. If anything, a period during which compliance requirements are defined primarily through contract rather than through a published certification standard may make it more difficult to establish a reusable mapping between EU programme security obligations and US CUI control requirements.

European suppliers should also note that data transfer considerations remain relevant. Where CUI or Federal Contract Information (FCI) is processed or stored on systems located in the EU, GDPR cross-border transfer requirements and adequacy determinations may apply alongside US export control and CUI handling obligations. The interaction between NIS2 supply-chain security obligations — which require entities to manage third-party cybersecurity risk through contractual and technical measures — and the private assurance regimes likely to be imposed by US prime contractors may create a dual compliance burden for European suppliers. Entities already subject to NIS2 incident-reporting and risk-management obligations may find that investments made for NIS2 compliance provide a partial foundation for meeting NIST SP 800-171 controls. However, the frameworks are not equivalent and a control-by-control gap analysis remains necessary.

Conclusion

The suspension of Phase II removes a date, not a duty. For European suppliers participating in transatlantic defence supply chains, the immediate work is contractual rather than technical: identify solicitations and subcontracts drafted against a regime that no longer applies, anticipate the private assurance requirements that prime contractors are likely to impose in place of certification and ensure that every representation made to a prime contractor or to the US government is supported by evidence capable of withstanding scrutiny. Suppliers that viewed CMMC primarily as a certificate to be obtained may find the next 12 months challenging. Those that viewed it as a control environment to be built and evidenced — and that can demonstrate alignment between their NIS2 compliance posture and NIST SP 800-171 requirements — are likely to find themselves in a stronger position than they were before the suspension was announced.

Download the Client Alert in English

Download PDF

Contributors