★ Annual Review 2027 tickets now on sale Get your tickets →

News/Compliance & Enforcement/Client Alert—CMMC Level 2 November Deadline Suspended Indefinitely
Expert Opinion·Compliance & Enforcement Brief

Client Alert—CMMC Level 2 November Deadline Suspended Indefinitely

Fox Rothschild – On July 13, 2026, the Department of Defense (DoD) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Level 2 third-party assessment requirements, which were originally scheduled to come into effect on November 10, 2026.  The announcement clarified that all CMMC Level 1 and CMMC Level 2 self-assessment requirements, which have been in effect since November 10, 2025, will remain in place.  The Pentagon intends to conduct a comprehensive review of the CMMC program, raising fresh uncertainty about the long-term direction of cybersecurity compliance obligations for defense contractors.

🔒 Members Only · Compliance & Enforcement BriefYou’ve reached the member portion of this brief.Members read the full analysis and the source documents in every Brief, six days a week.
Filed Under#c3pao#cmmc#contracting-officers#controlled-unclassified-information#cybersecurity#defense-contractors#department-of-defense#nist-sp-800-171#self-assessment#third-party-assessment
Not ready to join? Take the free Pub K Weekly digest.One email. Free. Top industry articles, the community calendar, and the latest job postings.