What's Happening?
Echelon Risk + Cyber, a cybersecurity consulting firm based in Pittsburgh, PA, is advising defense contractors to continue developing their security programs despite the suspension of CMMC Phase II requirements. The suspension, effective July 13, 2026,
removes the third-party C3PAO assessment requirement for Level 2 certification while a task force reviews the program. However, Echelon emphasizes that underlying contractual obligations, such as implementing NIST SP 800-171 controls and cyber incident reporting, remain unchanged. The firm advises contractors to focus on closing security gaps and maintaining compliance with existing requirements.
Why It's Important?
The suspension of CMMC Phase II highlights the challenges and complexities of implementing cybersecurity standards in the defense sector. While the pause may provide temporary relief from compliance burdens, it does not eliminate the need for robust security measures. Defense contractors must continue to prioritize cybersecurity to protect sensitive information and maintain contractual obligations. The situation underscores the importance of ongoing cybersecurity vigilance and the potential risks of delaying security enhancements. Echelon's guidance serves as a reminder that the threat environment remains active, and contractors must remain proactive in their security efforts.
What's Next?
The task force reviewing the CMMC program is expected to report its findings by mid-September 2026. Depending on the outcome, the C3PAO assessment requirement may be reinstated or modified. In the meantime, defense contractors are encouraged to continue their security efforts and prepare for potential changes in compliance requirements. Echelon Risk + Cyber will provide updated guidance as the review progresses, helping contractors navigate the evolving cybersecurity landscape. The firm's emphasis on maintaining security programs reflects the ongoing need for vigilance and preparedness in the face of cyber threats.








