← All articles Compliance

CMMC Phase 2 Suspended: What Defense Contractors Must Do During DoD's 60-Day Review

On July 13, 2026, the Department of Defense suspended the CMMC Phase 2 third-party certification requirement that was set to take effect November 10, 2026, and opened a 60-day review by a new CMMC Reform Task Force. Nothing else changed: your DFARS 252.204-7012 duty, your Phase 1 self-assessment in SPRS, and your False Claims Act exposure all remain in force. The audit clock paused. The compliance clock did not.

I spent eighteen years in federal acquisition as a Contracting Specialist and Contracting Officer at GSA, IRS, DoD, and DOI. When a rule like this gets suspended, the contractors who get hurt are the ones who read the headline and stop working. Let me tell you what the memo actually says, and what I would do if I were sitting across the desk from your offer today.

What exactly did DoD suspend on July 13, 2026?

DoD suspended the Phase 2 transition — the requirement for a Certified Third-Party Assessment Organization (C3PAO) to verify your CMMC Level 2 compliance as a condition of award. It also froze all pending and future CMMC implementation milestones "until further notice." It did not repeal the CMMC Program rule, and it did not amend the DFARS.

The suspension came from DoD Chief Information Officer Kirsten A. Davies, in support of Secretary Pete Hegseth's directive to reduce compliance barriers for small and medium-sized businesses. Davies wrote that "the combination of prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines is actively forcing innovative new entrants and small businesses to opt out of [DoD] contracts."

Here is the precise scope of what moved and what did not:

RequirementStatus after July 13What it means for you
CMMC Phase 2 third-party (C3PAO) certificationSuspendedThe November 10, 2026 milestone is on hold; no external assessment is required for now.
CMMC Phase 3 and Phase 4 milestonesSuspendedAll future implementation phases are frozen until further notice.
CMMC Phase 1 self-assessment (Levels 1 and 2)In forceRequired since November 10, 2025. Self-assessment is now the primary mechanism.
DFARS 252.204-7012In forceSafeguard covered defense information and report cyber incidents within 72 hours, unchanged.
NIST SP 800-171 Rev 2 (110 controls)In forceThe security baseline is unchanged. Level 2 still needs a SPRS score of at least 88 of 110.
SPRS score and annual affirmationIn forceKeep it current, accurate, and backed by evidence you can produce.
False Claims Act exposure (DOJ Civil Cyber-Fraud Initiative)In forceAn inaccurate self-attestation carries more weight now, not less.

You can read the announcement directly on the Department's site: the release "Department of War Suspends CMMC Phase II Requirements."

Is CMMC cancelled, or just paused?

CMMC is not cancelled. DoD suspended its exercise of discretion to require third-party certification on new contracts — it did not strike the CMMC Program rule at 32 CFR Part 170 or the DFARS clauses at 48 CFR. The 60-day Reform Task Force is meant to redesign the program, not end it. Expect Phase 2 to return in a revised form, likely lighter on third-party audits for smaller firms.

The task force has been directed to build a framework that "prioritizes speed to capability, lowers barriers for small, medium, and non-traditional businesses, and replaces prohibitive, third-party compliance models with scalable, realistic security measures." Its report is due roughly mid-September 2026, 60 days from the July 13 announcement.

From the acquisition seat, I read this as a pause on the enforcement mechanism, not a retreat on the security requirement. The government still wants your Controlled Unclassified Information (CUI) protected. It simply decided the C3PAO bottleneck was pushing good suppliers out of the Defense Industrial Base faster than it was raising security.

What are you still legally required to do right now?

Three obligations survived the suspension untouched: implement the 110 controls in NIST SP 800-171 Rev 2, maintain a current and accurate self-assessment score in the Supplier Performance Risk System (SPRS) under DFARS 252.204-7019 and 7020, and safeguard covered defense information under DFARS 252.204-7012. None of these depend on a C3PAO.

Walk through the live requirements in order:

  1. DFARS 252.204-7012. If you handle covered defense information, you must apply NIST SP 800-171 and report cyber incidents to DoD within 72 hours. This clause predates CMMC and was never touched by the pause.
  2. NIST SP 800-171 Rev 2. The 110 controls are the security baseline underneath CMMC Level 2. A passing SPRS assessment is 88 or higher on the 110-point scale, with a Plan of Action and Milestones (POA&M) for anything not yet met.
  3. SPRS self-assessment and annual affirmation. Under DFARS 252.204-7019 and 7020, you post your Basic Assessment score in SPRS and refresh it. That number is visible to every prime and every Contracting Officer evaluating you.

When I reviewed offers on the government side, a missing or stale SPRS score was an instant flag. It told me the offeror either did not understand its obligations or hoped no one would check. Both readings hurt you at evaluation.

The Short Version

The third-party audit is off the table for now. Your self-attestation is not — and with no assessor scheduled to catch your mistakes, that self-attestation now stands entirely on its own. That makes documentation the whole game. Keep your CUI boundary mapped, your SPRS score honest, and the evidence behind every control ready to produce on demand.

Why does the suspension raise your False Claims Act risk instead of lowering it?

Because removing the C3PAO removes the one checkpoint that would have caught an inflated score before the government relied on it. Your SPRS number is now the sole official window into your security posture, and the Department of Justice Civil Cyber-Fraud Initiative has been pursuing inaccurate self-attestations under the False Claims Act since October 2021.

These are not hypothetical cases. A California defense contractor settled for $9 million in 2022 over alleged misrepresentation of NIST SP 800-171 compliance. A university settled for $1.25 million in 2024. In mid-2026, another California contractor and its private equity owner settled for $1.75 million over self-disclosed cybersecurity violations. Every one of them shares a pattern: a self-certified score with no evidence behind it when the government asked.

The reassuring part is that the False Claims Act turns on knowing or reckless misrepresentation, not honest mistakes. A documented, good-faith assessment that fell short on a handful of controls sits in a very different legal place than a 110 posted on nothing. The practical rule from the CO seat: keep the artifacts that show how you reached your number.

Should you stop a C3PAO assessment you already started?

No. If you are mid-assessment or close to certification, finish it. Several DoD solicitations released this year have scored C3PAO-certified offerors more favorably than self-assessed ones — in some cases weighting certification up to three times higher. A completed certification is a live competitive differentiator precisely because your competitors are pausing.

Think about the incentive. During a 60-day freeze, most firms will sit still. If you are the offeror who walks in with an actual C3PAO certificate while the field self-attests, you have a discriminator the evaluation team can point to. I have watched source-selection decisions turn on exactly that kind of tangible, verifiable evidence.

How should you scope your CUI boundary for a defensible self-assessment?

Start by defining what CUI you hold and where it lives, because a score built on a wrong boundary is wrong no matter how well the controls are implemented. Map the systems, people, and data flows that touch covered information, document the boundary, and keep it current as contracts and staff change.

  1. Identify the CUI. Pull the CUI markings and DD Form 254 or contract language that tells you what covered information each contract carries.
  2. Draw the boundary. Diagram every system, cloud service, and endpoint that stores, processes, or transmits that data — including the enclave and any shared IT.
  3. Assess controls inside the boundary. Score the 110 NIST 800-171 controls against that scope, not against your whole company.
  4. Re-baseline on change. New contracts, new hires, and expanding systems move the boundary. A map that was right 18 months ago probably is not right today.

Contractors who scope informally almost always overstate their score. A control can be technically implemented and still miss if the boundary around it is drawn wrong — and that gap carries the same False Claims Act exposure as bad control documentation.

What should primes and subcontractors do during the pause?

Do not assume the pressure is off. Large primes set their own security bar independent of DoD's timeline, and your SPRS score plus supporting artifacts remain table stakes for most prime relationships. If you are a subcontractor and your prime has gone quiet, reach out — flowdown obligations under DFARS 252.204-7012 do not pause with the CMMC milestone.

Primes carry the accountability for their supply chain's security. Many of the largest ones treated CMMC as a floor, not a ceiling, and they will keep asking for evidence regardless of what the task force concludes. The pause changes the government's audit posture, not your prime's risk tolerance.

How can you influence the final CMMC rule before it returns?

DoD opened a public Request for Information alongside the suspension, with responses due August 14, 2026. If the future shape of CMMC affects your business, that comment window is your leverage. Submit specifics on assessment cost, capacity, and workable alternatives for small firms — the task force is explicitly looking for scalable models.

I rarely see small contractors use comment periods, and it is a missed opportunity. Agencies read these submissions. When the record shows real cost data from real suppliers, it shapes the rule that comes back. You can review the underlying regulatory framework at the CMMC Program rule (32 CFR Part 170) and track the DFARS safeguarding clause at DFARS 252.204-7012.

What Should You Do Now?

If you sell to civilian agencies through a GSA Schedule and you are trying to figure out how DoD's cybersecurity posture intersects with your MAS contract terms, that is exactly the kind of cross-agency compliance question I handle every week. Across our 70+ proven GSA contract awards, the contractors who stay ahead of these shifts are the ones who treat a "pause" as time to tighten documentation, not to relax. If you want a second set of eyes on how this affects your federal footprint, start with our GSA Schedule services.

Frequently Asked Questions

Is CMMC cancelled?

No. Only Phase 2, the third-party C3PAO certification requirement, is suspended pending a 60-day review. The CMMC Program rule at 32 CFR Part 170 and the DFARS clauses remain on the books, and CMMC Phase 1 self-assessment requirements stay fully in force.

Is CMMC Phase 1 still required?

Yes. Phase 1 has been in effect since November 10, 2025. You must still self-assess against the 110 controls in NIST SP 800-171 Rev 2 and maintain a current score in the Supplier Performance Risk System (SPRS).

Does the suspension change my DFARS 252.204-7012 obligations?

No. Your duty to safeguard covered defense information and report cyber incidents within 72 hours is unchanged. DFARS 252.204-7012 predates CMMC and was not touched by the July 13, 2026 suspension.

Can I still face False Claims Act liability if there is no third-party audit?

Yes, and the risk is arguably higher. With no C3PAO to catch errors, your SPRS self-attestation stands alone. The DOJ Civil Cyber-Fraud Initiative has pursued inaccurate self-attestations since October 2021, with multiple settlements running into 2026.

When is the CMMC Request for Information due?

DoD opened a public RFI alongside the suspension, with responses due August 14, 2026. It is your opportunity to give the CMMC Reform Task Force real cost and capacity data before the program is redesigned.

When will the CMMC Reform Task Force report?

Within 60 days of the July 13, 2026 announcement, placing its recommendations on or about mid-September 2026. DoD has said all pending and future CMMC milestones are frozen until further notice in the meantime.

Should I stop preparing for CMMC certification?

No. Keep your NIST 800-171 posture current and finish any C3PAO assessment already in progress. Certification is a competitive discriminator right now, and Phase 2 is expected to return in a revised form after the review.

Work With a Former CO Who's Been There

Navigating GSA Schedule strategy doesn't have to be a guessing game. Book a free strategy call with Pedro and let's talk about where you stand.

Book a Free Consultation →