The Department of War (DoW), formerly the Department of Defense, has temporarily suspended the planned Phase II rollout of the Cybersecurity Maturity Model Certification (CMMC) program, including the transition that would have made third-party C3PAO Level 2 assessments mandatory for applicable contracts and solicitations beginning November 10, 2026.
For companies in the Defense Industrial Base, however, the announcement should not be interpreted as a suspension of cybersecurity requirements.
The distinction is important:
The government has suspended the third-party verification requirement. It has not suspended the underlying obligation to protect Controlled Unclassified Information (CUI).
Both Level 1 and Level 2 Self-assessments are still required under Phase 1 of CMMC.
San Francisco Circuits achieved final CMMC 2.0 Level 2 status in May 2026 following an independent assessment by an accredited Certified Third-Party Assessment Organization (C3PAO). The Level 2 suspension doesn't change the work we've completed, the controls we've implemented, or the value of independently validated cybersecurity for our customers.

On July 13, 2026, the Department announced the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect November 10, 2026.
The Department also established a 60-day CMMC Reform Task Force to conduct a comprehensive review of the program. The review is focused in part on reducing the cost and administrative burden of CMMC, particularly for small, medium-sized and non-traditional businesses participating in the Defense Industrial Base.
The stated goal isn't to step back from cybersecurity. It's to find a more efficient approach while maintaining strong cybersecurity and operational resilience.
During the review, the Department has suspended the transition to Phase II and pending or future CMMC implementation milestones. At the same time, it has stated that cybersecurity requirements will continue to be enforced through self-assessments and select government-led assessments.
The eventual CMMC program will likely be streamlined, revised, or placed on a different implementation schedule. For now, those questions remain open.
The underlying cybersecurity obligations remain.
Where incorporated into an applicable contract, DFARS 252.204-7012 continues to require defense contractors and subcontractors to safeguard covered defense information and implement the applicable NIST SP 800-171 security requirements specified by contract.
In other words, delaying third-party verification is not permission to delay cybersecurity.
Phase I self-assessment requirements also remain in effect. Contractors must continue to maintain accurate assessment information and, where required, report assessment scores through the Supplier Performance Risk System (SPRS).
Nor should a self-assessment be treated as a paperwork exercise. Companies are making representations about the security controls they have implemented, and those representations may ultimately need to be substantiated.
Although the suspension does not require businesses to pursue 3rd party certification, they are still encouraged to continue assessing and working toward certification. Due to a shortage of certified CMMC auditors, a significant backlog has formed, pushing audit availability dates further into the future.
The potential consequences are real. The Department of Justice has continued pursuing Civil Cyber-Fraud cases involving alleged failures to meet federal cybersecurity obligations or accurately represent cybersecurity practices. In September 2025, for example, Georgia Tech Research Corporation agreed to pay $875,000 to resolve allegations involving cybersecurity requirements on certain defense contracts. As the Justice Department noted, the settlement resolved allegations and did not constitute a determination of liability.
CMMC was designed to give the government and defense customers greater confidence that contractors were actually implementing the cybersecurity practices they said they had implemented.
Suspending the Phase II third-party assessment requirement changes how that compliance may be verified in the near term. It doesn't make the underlying security risks disappear.
The Department has emphasized that robust cybersecurity remains critical to the Defense Industrial Base. During the review period, it plans to continue enforcing applicable cybersecurity requirements through self-assessments and select government-led assessments.
The eventual CMMC program may look different. But protecting CUI, controlling access to sensitive information, maintaining secure systems and accurately representing cybersecurity posture aren't issues that began with CMMC Phase II.
They remain important regardless of the implementation schedule.
For buyers of mission-critical boards, cybersecurity should be at the forefront of vendor requirements. No compromise should be made when evaluating PCB manufacturing and assembly partners. Select a company that has already achieved CMMC Level 2 C3PAO certification and prioritizes the security of sensitive data.
We are CMMC Level 2.0 Certified. As part of our comprehensive cybersecurity policies, our website security is monitored and independently audited through SecurityScorecard.
San Francisco Circuits began preparing for stronger cybersecurity requirements years before CMMC Level 2 became an immediate contract milestone.
We made that investment because independently validated cybersecurity is increasingly important to defense and aerospace customers choosing manufacturing partners that may handle sensitive program information.
On May 8, 2026, San Francisco Circuits achieved final CMMC 2.0 Level 2 status following an independent C3PAO assessment of the systems, processes and security requirements within our applicable CUI environment.
We completed that assessment before the Phase II suspension was announced. Our CMMC Level 2 achievement and perspective on the suspension were also recently featured in the August 2026 issue of SMT007 Magazine.
For customers evaluating potential PCB manufacturing partners, we believe that matters.
There is a meaningful distinction between relying primarily on a supplier's self-assessment and working with one that has already completed an independent C3PAO Level 2 assessment. CMMC Level 2 certification gives you peace of mind, providing additional, independently validated evidence that a supplier may be entrusted with sensitive program information.
That value doesn't disappear simply because the government has suspended when third-party verification becomes mandatory. The CMMC timeline may change. Our commitment to protecting our customers' information won't.

"San Francisco Circuits CEO Alex Danovich was interviewed by CompanyWeek, a publication from parent company Sustainment that highlights stories from American manufacturers."

"The global integrated circuits / chip shortage has impacted many industries across the globe, and though it does seem to slowly be getting better, we’re still a ways out from things stabilizing and turning back to normal."

"We are pleased to announce we have achieved NIST 800-171 compliance–meaning we are able to protect sensitive government data and information following federal guidelines from the National Institute of Standards and Technology (NIST) "

"The Health Officers of the Counties of San Francisco, Santa Clara, San Mateo, Marin, Contra Costa and Alameda have made an announcement that would impact our day-to-day work. Here’s information you need to know that could affect you."

"San Francisco Circuits is honored to have been chosen as the top PCB supplier in the industry and featured on an episode of National Television's "World's Greatest!" View the video here."

"New office, new staff - same great technology. We opened our second location in sunny San Diego on February 1st. We're excited to now have two offices that work tirelessly to meet your needs."
