← Back to resources
CMMC

CMMC Phase 2 Suspended: What Defense Contractors Should Do Now

On July 13, 2026, the Department of War (formerly the Department of Defense) announced the immediate suspension of CMMC Phase 2 — the transition, scheduled for November 10, 2026, that would have required contractors handling Controlled Unclassified Information (CUI) to pass a third-party CMMC Level 2 assessment as a condition of new contract awards. Pending and future CMMC implementation milestones across solicitations and contracts are suspended along with it.

If you're in the defense industrial base, here's what actually changed, what didn't, and what to do about it.

What was suspended

Phase 2 of the CMMC rollout. Under the phased implementation plan, Phase 2 would have made CMMC Level 2 certification — an assessment by a Certified Third-Party Assessor Organization (C3PAO) — a condition of award for contracts involving CUI, starting November 10, 2026. That deadline, and the milestones behind it, are on hold while the Department reviews the program.

The stated reason: compliance burden. The Department cited the cost that future CMMC phases would impose on small and midsize businesses — figures reported in the billions annually — as disproportionate, particularly for small and non-traditional contractors it wants to attract into the industrial base.

What is NOT suspended

This is the part that's getting lost in the headlines. The suspension pauses the certification mandate — not the underlying security obligations. Still fully in effect:

  • Phase 1 self-assessment requirements. In effect since November 2025. Applicable new contracts still require a current CMMC self-assessment and an affirmation in SPRS.
  • DFARS 252.204-7012. The clause requiring contractors to safeguard covered defense information and report cyber incidents hasn't gone anywhere.
  • NIST SP 800-171 Rev 2. The 110 security requirements remain the standard, enforced through self-assessments and government-led assessments.
  • False Claims Act exposure. A self-attested SPRS score you can't substantiate was a liability before this announcement, and it still is.

The 60-day review

The Department stood up a CMMC Reform Task Force to review the program and deliver a final report within 90 days — which puts its conclusions on roughly a mid-September 2026 timeline. Alongside it, a public Request for Information asked industry how to reform CMMC using existing commercial cybersecurity capabilities, better self-attestation, and streamlined compliance requirements, with responses due August 14, 2026.

Nobody outside the task force knows what comes back. The plausible range runs from a leaner certification regime with a later start date to a heavier reliance on self-attestation with government spot-checks. Plan for the range, not a prediction.

What you should do now

The wrong takeaway is "CMMC is dead, stop spending." Here's the sequence that holds up no matter what the task force recommends:

  • Keep implementing NIST 800-171. Every reform option on the table keeps 800-171 as the baseline. Work done now counts under any outcome.
  • Keep your SPRS score current and defensible. Phase 1 is still live — a stale or unsupportable score can still cost you awards today.
  • Maintain your SSP and POA&M. These documents are required by the self-assessment regime that remains in force, and they're the first thing any future assessor — third-party or government — will ask for.
  • Revisit C3PAO timing, not readiness. If you had an assessment scheduled primarily to beat the November deadline, the calendar pressure is off. If a prime is contractually requiring certification, that flow-down — not the Department's phase schedule — governs your timeline. Check before canceling anything.
  • Watch mid-September. The task force report will set the new shape of the program. Decisions that can wait 60 days probably should.

The bottom line

The certification deadline moved; the security requirements didn't. Contractors who treat this as a pause on paperwork — not a pause on security — will be ready for whatever the reformed program requires, and safer in the meantime.

Working through 800-171 implementation, an SSP, or a SPRS self-assessment? See our CMMC & NIST 800-171 readiness services, or start a conversation.

Not ready to talk to anyone yet?

Tell us the requirement you are facing, your deadline, and what is blocking you. We will come back with where to start, the likely sequence of work, and whether you actually need outside help.

Personal reply within one business day.