San Francisco Circuits has addressed the implications of the Department of War’s temporary suspension of the planned Phase II rollout for the Cybersecurity Maturity Model Certification program.
On July 13, 2026, the Department of War (DoW), formerly the Department of Defense, announced the immediate suspension of CMMC Phase II requirements and established a 60-day CMMC Reform Task Force to review the program and reduce its cost and administrative burden. During this review, the transition to Phase II and pending or future CMMC implementation milestones have been suspended, including the transition that would have made third-party C3PAO Level 2 assessments mandatory beginning November 10, 2026.
However, for companies operating within the Defense Industrial Base, the announcement does not signify a pause in cybersecurity enforcement. While the government has suspended the third-party verification requirement, it has not suspended the underlying obligation to safeguard Controlled Unclassified Information (CUI).
Underlying cybersecurity obligations remain active under existing regulatory frameworks. When incorporated into an applicable contract, DFARS 252.204-7012 continues to require defense contractors and subcontractors to safeguard covered defense information and implement applicable NIST SP 800-171 security requirements. Furthermore, Phase I self-assessment requirements remain in full effect. Contractors are required to maintain accurate assessment information and report assessment scores through the Supplier Performance Risk System (SPRS) where mandated.
Companies are encouraged to continue assessing their systems and working toward formal certification, as delaying third-party verification is not permission to delay baseline cybersecurity implementation.
San Francisco Circuits achieved final CMMC 2.0 Level 2 status on May 8, 2026, following an independent C3PAO assessment. The company notes that the temporary program suspension does not alter the controls implemented or the value of independently validated security for buyers of mission-critical printed circuit boards. There remains a meaningful distinction between relying primarily on a supplier’s self-assessment and partnering with a vendor that has already completed an independent C3PAO Level 2 assessment.






