This audio is auto-generated. Please let us know if you have feedback.

Defense contractors, both primes and subs, should continue to comply with the Department of Defense’s cybersecurity regulation despite Phase 2 being postponed, experts told Manufacturing Dive.

The agency temporarily paused phase 2 of the Cybersecurity Maturity Model Certification program on July 13. CMMC focuses on verifying contractors that have implemented required security measures necessary to safeguard federal contract information not intended for public release. The regulations also shield controlled unclassified information created or owned by or for the government that’s deemed sensitive.

Two CMMC rules were finalized and went into effect in 2024: One that oversees the legal contractual requirements and another that establishes the structural framework and streamline the security levels, from five levels to three.

Phase 1 of the CMMC program began on Nov. 10, 2025 and remains in place. Phase 2 was set to begin exactly a year after.