What Happened
On July 13, 2026, the Department of War — as the Department of Defense is now designated — announced the immediate suspension of the CMMC Phase 2 requirements, which had been scheduled to take effect November 10, 2026. The suspension also covers "pending and future CMMC implementation milestones" across DoD solicitations and contracts.
The department's CIO is standing up a CMMC Reform Task Force to conduct what the release calls a "comprehensive top-to-bottom review" of the certification program, with a final report due to the CIO within 60 days. The stated goals: lower compliance barriers for small and non-traditional businesses and replace "bureaucratic compliance with scalable, resilient cybersecurity measures." The stated reason: compliance costs and assessor bottlenecks were pushing companies out of the defense industrial base.
What Is Suspended
- The Phase 2 transition — applicable new CUI solicitations will not require third-party C3PAO certification as a condition of award on the November 10, 2026 schedule
- Pending and future CMMC implementation milestones — across DoD solicitations and contracts, effective immediately
One open question the release doesn't answer: how contracting officers will handle CMMC clauses in contracts that were already awarded. If you hold one, that's a conversation with your contracting officer — not an assumption in either direction.
What Still Applies
- Phase 1 self-assessments — the release states these "remain firmly in place"
- DFARS 252.204-7012 — every defense contractor and subcontractor handling covered defense information remains contractually obligated to safeguard it, which means implementing NIST SP 800-171
- NIST SP 800-171 Rev 2 enforcement — during the review, DoD says it will enforce the standard "through self-assessments and select government-led assessments"
- SPRS accuracy — DFARS 252.204-7019/7020 still require a current score, and an inflated one still carries False Claims Act exposure; government-led assessments are exactly where discrepancies surface
What It Means for You
If you handle CUI today: nothing about your security obligations changed. What changed is the verification model — from a scheduled third-party certification to self-assessment plus the possibility of a government-led assessment. That shifts the immediate risk from "failing a C3PAO assessment" to "defending your SPRS score," which is a documentation and evidence problem as much as a technical one.
If you were preparing for a C3PAO assessment: certification is no longer a near-term condition of award, and how the requirement returns — reshaped, rescheduled, or replaced — is what the task force will decide. Watch your primes, though: flow-down requirements are contractual, and some primes may keep asking for more than the government currently does.
If you'd paused or never started: the requirements that drove CMMC didn't go anywhere. NIST 800-171 is contractually required now, under a clause that predates CMMC — and every serious proposal for what replaces Phase 2 builds on the same 110 controls. Work done now carries forward regardless of what the review produces.
What Happens Next
The task force's report is due to the DoD CIO within roughly 60 days of the announcement — mid-September 2026. It will synthesize industry feedback from the department's public Request for Information on compliance challenges and recommend "realistic, scalable security measures." Expect changes to how compliance is verified rather than a simple reinstatement or cancellation — and expect short notice either way. We'll update this page when the review lands.
In the meantime, the sensible posture is the boring one: keep implementing NIST 800-171, keep your SSP and evidence current, and keep your SPRS score accurate. A gap analysis tells you where you actually stand; our 800-171 services close the gaps; a mock assessment proves you can defend it under questioning — government-led or otherwise.
Frequently Asked Questions
Is CMMC cancelled?
No. The July 13, 2026 announcement suspended the Phase 2 requirements and pending implementation milestones while a task force conducts a top-to-bottom review of the program. Phase 1 self-assessment requirements remain firmly in place, and the department has said cybersecurity requirements will continue — the review is about reshaping how compliance is verified, not eliminating it.
Do we still have to comply with NIST 800-171?
Yes. DFARS 252.204-7012 contractually obligates contractors and subcontractors handling covered defense information to implement NIST SP 800-171 — the announcement states this explicitly. During the interim, DoD is enforcing the standard through self-assessments and select government-led assessments, and DFARS 252.204-7019/7020 still require a current, accurate SPRS score.
What happened to the November 10, 2026 Phase 2 date?
It is no longer in effect. Phase 2 — which would have let applicable CUI solicitations require third-party C3PAO certification as a condition of award — was suspended effective July 13, 2026, along with pending and future CMMC implementation milestones. The CMMC Reform Task Force reports to the DoD CIO within 60 days; any new timeline will come out of that review.
Should we pause our CMMC preparation?
The work behind CMMC Level 2 is implementing NIST SP 800-171 — and that obligation is still in your contracts under DFARS 252.204-7012, still enforced through self-assessments and select government-led assessments, and still the likely substance of whatever verification model replaces Phase 2. Pausing certification-specific spending while the review runs can be reasonable; pausing 800-171 implementation is not.