On July 13, 2026, the Pentagon suspended the second phase of its Cybersecurity Maturity Model Certification program.
Phase 2 had been scheduled to begin on November 10, 2026, expanding the use of third-party Level 2 assessments across applicable defense solicitations and contracts.
That expansion is now paused while the Department reviews the cost, complexity and effect of the program on smaller and non-traditional suppliers.
The underlying security requirement did not disappear.
Phase 1 remains active. Contractors handling Federal Contract Information or Controlled Unclassified Information may still be required to hold a current Level 1 or Level 2 self-assessment status before an award can be made.
The distinction matters for every defense company planning an AI initiative.
We have written before about why data fragmentation, rather than model quality, is the real barrier to AI in defense.
CMMC operates underneath that problem.
A company that cannot demonstrate the required cybersecurity posture may not be permitted to process, store or transmit the information its AI system needs in the first place.
The third-party certification timeline may have moved.
The data-handling gate remains.
What Is CMMC, in One Sentence?
CMMC is the Department of Defense framework used to assess whether contractors and subcontractors have implemented the cybersecurity protections required for the Federal Contract Information or Controlled Unclassified Information they handle.
The required status is identified in the solicitation and contract.
Before making an award, the contracting officer checks the Supplier Performance Risk System to determine whether each relevant contractor information system holds a current CMMC status at the required level or higher.
CMMC does not determine whether a company can build an effective AI model.
It determines whether the company has the security posture required to process the government information on which that model may depend.
What Are the Three Levels?
CMMC contains three levels based on the sensitivity of the information processed, stored or transmitted by the contractor’s systems.
Level 1: Federal Contract Information
Level 1 applies to systems handling Federal Contract Information that is not intended for public release.
It requires an annual self-assessment against 15 basic safeguarding requirements and an annual affirmation of continued compliance.
Plans of Action and Milestones are not permitted at this level.
A contractor must achieve a final Level 1 status rather than relying on a conditional assessment.
Level 2: Controlled Unclassified Information
Level 2 applies to systems handling Controlled Unclassified Information.
This is the level most likely to affect AI initiatives involving operational defense data, technical information, maintenance records, logistics data or other protected program information.
Level 2 is based on the 110 security requirements contained in NIST SP 800-171 Revision 2.
Under the original implementation structure, some Level 2 programs could rely on self-assessment while others would require an assessment by a Certified Third-Party Assessment Organization.
During the current Phase 2 suspension, the Department has limited new requirements to Level 2 self-assessment while it reviews the future of the third-party assessment model.
A final Level 2 status remains current for three years, provided the organization also submits the required annual affirmation and maintains compliance.
Level 3: Enhanced Protection for Sensitive CUI
Level 3 applies to selected systems handling the most sensitive Controlled Unclassified Information.
It builds on Level 2 and adds requirements derived from NIST SP 800-172.
Level 3 assessments are performed by the Defense Industrial Base Cybersecurity Assessment Center.
The Defense Contract Management Agency remains the sole Department of Defense entity designated to conduct these assessments.
Under the July 2026 suspension, new Level 3 requirements are not being introduced while the Department reviews the program.
What Was Supposed to Change on November 10, 2026?
Phase 1 began on November 10, 2025.
It introduced Level 1 and Level 2 self-assessment requirements into applicable solicitations and contracts, while allowing the Department to require a Level 2 third-party assessment in selected cases.
Phase 2 was scheduled to begin one calendar year later.
Under the original implementation plan, applicable solicitations involving Controlled Unclassified Information would increasingly require a Level 2 C3PAO assessment as a condition of award. The Department would also have been able to introduce Level 3 requirements in selected procurements.
That transition was suspended on July 13, 2026.
During the review period, program offices are restricted to Level 1 and Level 2 self-assessment requirements.
The original November 10 deadline should therefore no longer be described as a universal certification cutoff.
It remains an important date in the original regulatory structure, but the planned expansion into third-party certification will not proceed on that schedule unless the Department reinstates or replaces it.
What Has Not Changed?
The suspension did not remove CMMC from defense acquisition.
It did not eliminate the requirement to protect Federal Contract Information or Controlled Unclassified Information.
It did not allow contractors to process protected defense data inside systems that fail to implement the applicable security controls.
It also did not remove the contracting officer’s obligation to verify the required CMMC status before award when the relevant clauses appear in a solicitation.
For organizations operating under Phase 1, compliance is already an active contractual issue.
The difference is that, during the review, the Department is relying on self-assessment rather than expanding mandatory third-party certification across the industrial base.
The verification mechanism changed.
The obligation to secure the data did not.
Does CMMC Apply to Subcontractors?
CMMC requirements flow through the defense supply chain.
The prime contractor is responsible for identifying the CMMC level required for subcontractors based on the information each subcontractor will process, store or transmit.
A supplier that does not handle Federal Contract Information or Controlled Unclassified Information on its own systems may not require a CMMC status for that work.
A subcontractor that receives or processes protected information as part of a software integration, analytics workflow or AI data pipeline may fall directly within the program.
Its position in the supply chain does not change the sensitivity of the information.
A company several tiers below the prime may still require Level 2 controls when its systems touch Controlled Unclassified Information.
For AI programs, this can extend the security boundary to model developers, cloud environments, data-integration providers, annotators and other technical partners involved in processing the information.
What Does This Have to Do With AI Initiatives?
Many of the most valuable defense AI use cases depend on information likely to be treated as Controlled Unclassified Information.
Predictive maintenance may require platform-performance and component-failure records.
Logistics optimization may depend on supply, movement and readiness data.
Operational intelligence systems may combine sensor outputs, mission records and information from multiple programs of record.
An organization may have a technically strong plan for turning that data into an operational system and still be unable to deploy it inside its current environment.
The model architecture and the CMMC boundary are two separate design problems.
The first determines how information becomes useful.
The second determines where that information may legally and securely be processed.
A system designed without reference to the organization’s CMMC scope may create an architecture that cannot be authorized for the data it needs.
That problem becomes more complex when information moves between a prime contractor, subcontractors, cloud providers and specialist AI vendors.
Every system touching the protected information becomes part of the security and data-flow question.
The Suspension Does Not Make Early Preparation Irrelevant
The current pause creates uncertainty around how and when third-party assessments will return.
It does not make cybersecurity preparation unnecessary.
Contractors may still need a current Level 2 self-assessment status for applicable awards.
They must still implement the security controls on which both self-assessments and future certification assessments are based.
They must still define the system boundary, document how protected information moves and maintain evidence supporting the assessment submitted to the government.
A company that waits for the revised Phase 2 policy before beginning that work risks discovering that the underlying remediation takes longer than the policy review.
The external assessment may be paused.
The engineering work required to create a defensible security environment is not.
How Plans of Action and Milestones Actually Work
CMMC permits limited use of Plans of Action and Milestones at Levels 2 and 3.
A POA&M allows an organization that meets the minimum scoring and eligibility conditions to receive a conditional status while it completes specified remediation work.
That conditional status is not indefinite.
The remaining requirements must be closed and verified within 180 days. If the organization does not complete the closeout assessment within that period, the conditional status expires.
Certain critical requirements cannot be placed on a POA&M at all.
Level 1 does not permit POA&Ms.
A POA&M should therefore be treated as a tightly controlled remediation bridge, not as an alternative to implementing the required protections.
What Defense Contractors Should Be Doing Now
Certification planning and AI architecture should proceed in parallel.
Determine Which Information the System Will Touch
The required CMMC level should be based on the actual information processed by the proposed system.
Teams should identify whether the environment will handle Federal Contract Information, Controlled Unclassified Information or only publicly releasable data.
That classification should be determined before the architecture is finalized.
Define the Security Boundary
The organization should identify every system, user, integration and external provider that will process, store or transmit protected information.
The objective is not simply to document the corporate network.
It is to define the specific environment that supports the contract and the AI workflow.
Map the Data Flow
Protected information may move through ingestion pipelines, storage layers, retrieval systems, model endpoints, monitoring tools and human-review interfaces.
Every transition should be documented.
A system cannot be secured or assessed reliably when the organization does not know where the information travels.
Align the AI Roadmap With the Compliance Roadmap
The AI team should not design an operational data environment independently from the team responsible for cybersecurity and contract compliance.
The systems included in the AI architecture must be able to operate inside the assessed environment.
A model that requires data to leave that boundary may create a deployment that cannot be used on the contract it was built to support.
Preserve Evidence
Self-assessment does not mean evidence-free assessment.
Organizations should retain policies, system-security plans, technical configurations, access records, architecture diagrams and other evidence demonstrating how each requirement has been implemented.
That evidence supports the current self-assessment and reduces the disruption of any future independent assessment.
Certification and Data Readiness Are Different Gates
CMMC does not replace the work of unifying fragmented defense data into something an AI system can use.
It determines whether the organization and its systems are permitted to process that information under the applicable contract.
A company may clear its CMMC requirement and still have fragmented, inconsistent or unusable operational data.
It may also build an excellent data architecture inside an environment that does not hold the required CMMC status.
A deployable defense AI system has to clear both gates.
It needs a secure and contractually eligible operating environment.
It also needs traceable, interoperable and operationally trustworthy data.
The July 2026 suspension changed the timeline for expanding third-party certification.
It did not merge those two problems, and it did not eliminate either of them.
Explore how we approach the underlying defense data problem, our work across regulated, high-stakes industries, or talk to our team about where your cybersecurity boundary and AI roadmap need to intersect.
