The suspension changes how compliance is checked, not what contractors must do. On 13 July 2026 the US Department of Defense suspended CMMC Phase 2, removing the requirement for third-party assessments that was set to begin on 10 November 2026. The obligation to protect Controlled Unclassified Information and to implement the NIST SP 800-171 controls stays fully in force. This post explains what changed, how CMMC and NIST SP 800-171 relate, and how MyID® supports the identity and access controls at the centre of both.
What the Department of Defense actually suspended
The suspension pauses third-party certification, not cybersecurity itself. The Department of Defense stated that CMMC assessment costs, limited assessor capacity, and administrative complexity had become a barrier for small and medium-sized defense suppliers. It has launched a 60-day review through a new CMMC Reform Task Force to rebalance strong security with wider participation in the defense supply chain.
Existing requirements remain unchanged. Contractors must still run self-assessments, protect Controlled Unclassified Information, and implement every applicable NIST SP 800-171 control. The Department was explicit that this is a pause on how compliance is verified, not a reduction in what is required.
CMMC verifies NIST SP 800-171, it does not replace it
CMMC is not a separate framework. It is the mechanism the Department of Defense uses to confirm that contractors have implemented the controls defined in NIST Special Publication 800-171, “Protecting Controlled Unclassified Information in Non-federal Systems and Organizations”.
NIST SP 800-171 sets out security requirements grouped into 14 control families:
- Access Control
- Identification and Authentication
- Audit and Accountability
- Configuration Management
- Incident Response
- Media Protection
- Personnel Security
- Physical Protection
- Risk Assessment
- Security Assessment
- System and Communications Protection
- System and Information Integrity
- Awareness and Training
- Maintenance
Under CMMC Level 2, any organization that processes, stores, or transmits Controlled Unclassified Information must show it has implemented the applicable NIST SP 800-171 requirements. NIST SP 800-171 defines the controls; CMMC provides the assessment the Department uses to validate them.
How MyID supports NIST SP 800-171 and CMMC compliance
MyID strengthens identity and access management, which sits at the core of both NIST SP 800-171 and CMMC. MyID software covers the full authentication scale, password security to passkey issuance and management to government-grade PKI credential management, so defense contractors can protect every part of the workforce with one set of tools.
MyID issues and manages high-assurance credentials, including:
- PIV and PIV-I credentials
- Smart cards
- Derived credentials for mobile devices
- FIDO2 security keys and passkeys
- Certificate-based authentication credentials
These capabilities map directly to several NIST SP 800-171 control families and their matching CMMC practices.
Identification and Authentication
MyID MFA delivers phishing-resistant multi-factor authentication, certificate-based authentication, and cryptographic credentials that verify user identity and cut the risk of credential compromise. It supports passkeys, hardware tokens, and passwordless Windows logon across the workforce.
Access Control
By working with logical access systems, Active Directory, public key infrastructure, and cloud services, MyID CMS helps ensure that only authorized users reach sensitive systems and Controlled Unclassified Information.
Audit and Accountability
MyID keeps full records of credential issuance, lifecycle events, and revocation, giving contractors the evidence trail that auditing and accountability requirements demand.
System and Communications Protection
Certificate-based authentication and public key infrastructure protect communications and reduce reliance on passwords. Where passwords remain in use, MyID PSM checks them continuously against a database of more than 11 billion breached credentials, in line with NIST 800-63B.
Personnel Security and Lifecycle Management
MyID automates credential provisioning, renewal, suspension, and revocation, so access rights stay correct through every stage of the employee lifecycle. When someone leaves, their credential is revoked in seconds rather than lingering as an open door.
Contractors who invest in identity now will be ready when assessment returns
The review does not remove a single obligation. Defense contractors are still responsible for protecting Controlled Unclassified Information and implementing NIST SP 800-171. When third-party assessment resumes, and the Task Force review points to it returning in some form, the organizations that built strong identity, authentication, and credential management during the pause will be ready. Those treating the suspension as a reason to stop will have further to travel.
Intercede has spent more than 20 years issuing and managing high-assurance credentials for governments, defense contractors, and financial institutions. MyID gives defense suppliers a proven way to meet the identity and authentication controls that NIST SP 800-171 and CMMC both demand.
Get ready for CMMC before assessment returns. See how MyID covers the identity and authentication controls at the heart of NIST SP 800-171 and CMMC, from passwords through to PKI.