CMMC Phase 2 Is Paused, But Defense Supply Chain Cyber Risk Remains
The CMMC Phase 2 suspension changes the assessment timeline, not the need for defense supplier cybersecurity assurance. Learn why defense contractors still need continuous third-party risk management, NIST SP 800-171 alignment, CUI protection, and supplier visibility.

The Cybersecurity Maturity Model Certification (CMMC) program has entered another period of uncertainty.
On July 13, 2026, the Department of War suspended CMMC Phase 2 requirements, which had been scheduled to introduce mandatory third-party assessments for certain defense contractors beginning November 10, 2026.
The announcement created immediate questions across the Defense Industrial Base (DIB). Does this mean organizations can pause their cybersecurity efforts? Does it reduce the importance of NIST SP 800-171? Does it eliminate the need to demonstrate supplier security?
The answer to all three questions is no.
The suspension changes how cybersecurity validation may occur. It does not remove the responsibility defense contractors and suppliers have to protect Federal Contract Information (FCI), Controlled Unclassified Information (CUI), and the systems supporting government contracts.
For organizations managing complex defense supply chains, the focus should not be waiting for the final version of CMMC. The focus should be building a defensible supplier cybersecurity program that remains valuable regardless of how assessment requirements evolve.
What Actually Changed With the CMMC Phase 2 Suspension?
CMMC was created to strengthen cybersecurity protections across the Defense Industrial Base by requiring contractors and subcontractors to demonstrate implementation of cybersecurity practices aligned with NIST SP 800-171.
The Phase 2 rollout was expected to introduce broader requirements for independent assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs).
The July 2026 suspension paused this assessment requirement while the Department reviews the future direction of the program.
However, several important obligations remain.
Defense contractors are still expected to understand their cybersecurity responsibilities, maintain accurate security representations, and ensure required protections are implemented.
NIST SP 800-171 remains a key foundation for protecting CUI, and organizations continue to face expectations around security controls, evidence collection, remediation, and accountability.
Why the Suspension Does Not Reduce Third-Party Risk
A common misconception is that fewer formal assessments mean less supplier oversight.
In reality, supplier risk continues regardless of the assessment timeline.
Independent assessments provide one validation point, but they are only one component of an effective supplier assurance program.
Defense organizations rely on thousands of suppliers, subcontractors, software providers, managed service providers, and technology partners. Many of these relationships involve access to sensitive information, operational systems, or environments connected to defense operations.
A supplier can introduce risk by handling CUI without appropriate safeguards, misconfiguring access controls, failing to maintain required security practices, using subcontractors without adequate oversight, or allowing security evidence to become outdated.
These risks exist whether or not a C3PAO assessment is required.
The Shift From Certification Readiness to Supplier Assurance
For many organizations, CMMC preparation has historically focused on achieving assessment readiness.
That approach often creates a short-term compliance mindset:
- Are our documents complete?
- Have we prepared for the assessment?
- Can we demonstrate compliance?
Those questions matter, but they do not provide a complete view of supply chain security.
A stronger approach focuses on ongoing supplier assurance:
- Which suppliers handle sensitive information?
- Which suppliers create the greatest operational risk?
- Are security controls still operating?
- Has a supplier’s risk profile changed?
- Can we demonstrate ongoing oversight?
This is where third-party risk management becomes essential.
CMMC defines cybersecurity expectations for protecting sensitive information, but managing defense supplier risk requires visibility throughout the entire supplier lifecycle.
Why Defense Contractors Need Continuous Supplier Monitoring
Supplier risk does not remain static after onboarding.
A supplier that appears low risk today may become significantly more important after a new system integration, a change in ownership, a new subcontractor relationship, a security incident, expanded access to sensitive environments, or changes in cloud infrastructure.
Annual assessments cannot capture every change that occurs between review cycles.
Modern supplier assurance requires continuous visibility into the factors that influence risk.
This does not mean replacing human decision-making with automated risk decisions. It means creating better information, stronger workflows, and clearer evidence so security teams can make informed decisions faster.
Building a Defensible Defense Supplier Assurance Program
A mature supplier security program begins with understanding the supply chain.
Organizations need visibility into which suppliers support critical operations, which suppliers handle sensitive information, and which relationships create the greatest exposure.
From there, organizations can apply a risk-based approach.
Higher-risk suppliers may require deeper assessments, stronger contractual requirements, more frequent reviews, and closer monitoring. Lower-risk suppliers may require a proportionate level of oversight.
The objective is not to treat every supplier equally.
The objective is to understand where risk exists and apply resources where they create the greatest impact.
Where TPSaaS Fits
TPSaaS is designed to help organizations build structured third-party security assurance programs across complex supplier ecosystems.
TPSaaS is not a CMMC certification solution and does not replace a C3PAO assessment.
Instead, TPSaaS supports the operational capabilities organizations need to manage supplier cybersecurity risk, including supplier intake and classification, risk-based supplier tiering, security assessments and evidence collection, remediation tracking, continuous monitoring, and supplier lifecycle governance.
The platform combines practitioner-led expertise with structured workflows to help organizations move beyond disconnected spreadsheets and point-in-time reviews.
The result is a more practical approach to supplier assurance: one that supports evolving regulatory expectations while improving visibility into real-world cyber risk.
What Defense Organizations Should Do Next
The CMMC Phase 2 suspension provides an opportunity for organizations to strengthen the foundation of their supplier security programs.
Rather than waiting for future assessment requirements, defense contractors should focus on capabilities that remain valuable regardless of regulatory changes.
That means understanding supplier dependencies, improving evidence management, strengthening remediation processes, and maintaining ongoing visibility into supplier security posture.
Organizations that are best prepared for the future will not simply be those that pass an assessment.
They will be the organizations that understand their supply chain risk and have the processes in place to manage it.
Frequently Asked Questions
Does the CMMC Phase 2 suspension mean defense contractors no longer need to prepare?
No. The suspension affects the timing and structure of third-party assessment requirements, but defense contractors still need to protect sensitive information and maintain appropriate cybersecurity practices.
Is CMMC certification no longer required?
The future structure of CMMC continues to evolve. Organizations should monitor official Department guidance while continuing to maintain cybersecurity practices aligned with applicable contract requirements and NIST SP 800-171.
How does CMMC relate to third-party risk management?
CMMC focuses on protecting information within the Defense Industrial Base. Third-party risk management provides the broader governance process needed to identify, assess, monitor, and manage suppliers that may introduce cybersecurity risk.
Why is continuous supplier monitoring important?
Supplier security posture changes over time. Continuous monitoring helps organizations identify changes between formal assessments and respond before supplier risk becomes a business-impacting event.
Can TPSaaS provide CMMC certification?
No. TPSaaS is not a CMMC certification provider and does not replace C3PAOs. TPSaaS supports supplier assurance through risk assessment, evidence management, remediation tracking, monitoring, and third-party security governance.

Founder & CEO of TPSaaS.io with 25+ years in cybersecurity, compliance, and third-party risk management. Vic built TPSaaS to make enterprise-grade third-party security smarter, faster, and accessible to all.
