On July 13, 2026, the Department of War announced the suspension of CMMC Phase II requirements, which had previously been scheduled to take effect on November 10, 2026. The decision is the latest marker on a trail of evidence that the third-party assessment structure Phase II required represented barriers too steep for the smaller and non-traditional manufacturers the defense industrial base is trying to bring in. A 60-day CMMC Reform Task Force has been established to review the program and recommend a revised framework. Phase I self-assessment requirements remain in place.
A Deliberate Push to Expand the Defense Industrial Base
The suspension is part of a broader initiative. Secretary of War Hegseth’s Acquisition Transformation System has been focused on prioritizing speed to capability, reducing compliance overhead, and expanding access to defense contracting for smaller and non-traditional manufacturers. The CMMC Phase II suspension reflects that direction directly.
The data behind the decision was straightforward. Over 100,000 defense industrial base businesses needed third-party assessments under Phase II. Roughly 100 assessors were available to conduct them. For small and mid-sized manufacturers, the bottleneck made compliance effectively impossible within the timeline, regardless of how well-prepared they were. The Department of War acknowledged that the framework was pushing capable manufacturers out of the defense industrial base rather than bringing them in.
What It Means for Manufacturers Watching from the Sidelines
For manufacturers who have the operational capability to serve defense customers but have been deterred by the compliance landscape, this is a signal worth taking seriously. The administration is actively trying to grow the pool of eligible defense contractors, and that’s a meaningful shift in intent.
What opens the door, however, still requires organizations to walk through it. Defense customers don’t just need manufacturers who can clear a cybersecurity checklist. They need suppliers with documented, auditable quality systems that can meet the expectations of AS9100 and related standards. The compliance overhead may be getting lighter on the cybersecurity side. The quality expectations aren’t going anywhere.
How APEX QA Helps
For manufacturers looking to build the quality foundation that defense contracting requires, APEX QA offers Probitas-Authenticated AS9100 Lead Auditor and Internal Auditor training, as well as PFMEA, APQP, and Core Tools courses aligned to the latest revisions. Whether you’re pursuing AS9100 certification for the first time or strengthening an existing quality system ahead of a transition to IA9100, APEX’s courses are built for the people doing the work.
CMMC Phase II Suspension: Common Questions Answered
1) What is CMMC and why does it matter for manufacturers?
CMMC is the Department of War’s framework for verifying that defense contractors meet cybersecurity requirements and is a condition of eligibility for contracts involving controlled unclassified information.
2) What was suspended on July 13, 2026?
Phase II’s third-party assessment requirement. Phase I self-assessments and NIST SP 800-171 cybersecurity controls remain fully in force.
3) Does the suspension mean cybersecurity compliance is no longer required?
No. The underlying security requirements haven’t changed. What’s suspended is the requirement to have them verified by an accredited third party.
4) What happens next with CMMC?
A CMMC Reform Task Force will deliver a review within 60 days. A public RFI seeking industry feedback is open with comments due August 14, 2026.
5) What does this mean for manufacturers who want to pursue defense contracts?
The administration is reducing barriers to entry for smaller and non-traditional manufacturers. Organizations with quality systems already in place are better positioned to take advantage of that opening.



