CMMC Phase 2 Suspended: What It Means for Defense Contractors

On July 13, 2026, DoD suspended the CMMC Phase 2 requirements pending a 60-day program review. Here's what's actually suspended, what still binds you, and what to do about it — without the panic or the spin.

What Happened

On July 13, 2026, the Department of War — as the Department of Defense is now designated — announced the immediate suspension of the CMMC Phase 2 requirements, which had been scheduled to take effect November 10, 2026. The suspension also covers "pending and future CMMC implementation milestones" across DoD solicitations and contracts.

The department's CIO is standing up a CMMC Reform Task Force to conduct what the release calls a "comprehensive top-to-bottom review" of the certification program, with a final report due to the CIO within 60 days. The stated goals: lower compliance barriers for small and non-traditional businesses and replace "bureaucratic compliance with scalable, resilient cybersecurity measures." The stated reason: compliance costs and assessor bottlenecks were pushing companies out of the defense industrial base.

What Is Suspended

One open question the release doesn't answer: how contracting officers will handle CMMC clauses in contracts that were already awarded. If you hold one, that's a conversation with your contracting officer — not an assumption in either direction.

What Still Applies

What It Means for You

If you handle CUI today: nothing about your security obligations changed. What changed is the verification model — from a scheduled third-party certification to self-assessment plus the possibility of a government-led assessment. That shifts the immediate risk from "failing a C3PAO assessment" to "defending your SPRS score," which is a documentation and evidence problem as much as a technical one.

If you were preparing for a C3PAO assessment: certification is no longer a near-term condition of award, and how the requirement returns — reshaped, rescheduled, or replaced — is what the task force will decide. Watch your primes, though: flow-down requirements are contractual, and some primes may keep asking for more than the government currently does.

If you'd paused or never started: the requirements that drove CMMC didn't go anywhere. NIST 800-171 is contractually required now, under a clause that predates CMMC — and every serious proposal for what replaces Phase 2 builds on the same 110 controls. Work done now carries forward regardless of what the review produces.

What Happens Next

The task force's report is due to the DoD CIO within roughly 60 days of the announcement — mid-September 2026. It will synthesize industry feedback from the department's public Request for Information on compliance challenges and recommend "realistic, scalable security measures." Expect changes to how compliance is verified rather than a simple reinstatement or cancellation — and expect short notice either way. We'll update this page when the review lands.

In the meantime, the sensible posture is the boring one: keep implementing NIST 800-171, keep your SSP and evidence current, and keep your SPRS score accurate. A gap analysis tells you where you actually stand; our 800-171 services close the gaps; a mock assessment proves you can defend it under questioning — government-led or otherwise.

Frequently Asked Questions

Is CMMC cancelled?

No. The July 13, 2026 announcement suspended the Phase 2 requirements and pending implementation milestones while a task force conducts a top-to-bottom review of the program. Phase 1 self-assessment requirements remain firmly in place, and the department has said cybersecurity requirements will continue — the review is about reshaping how compliance is verified, not eliminating it.

Do we still have to comply with NIST 800-171?

Yes. DFARS 252.204-7012 contractually obligates contractors and subcontractors handling covered defense information to implement NIST SP 800-171 — the announcement states this explicitly. During the interim, DoD is enforcing the standard through self-assessments and select government-led assessments, and DFARS 252.204-7019/7020 still require a current, accurate SPRS score.

What happened to the November 10, 2026 Phase 2 date?

It is no longer in effect. Phase 2 — which would have let applicable CUI solicitations require third-party C3PAO certification as a condition of award — was suspended effective July 13, 2026, along with pending and future CMMC implementation milestones. The CMMC Reform Task Force reports to the DoD CIO within 60 days; any new timeline will come out of that review.

Should we pause our CMMC preparation?

The work behind CMMC Level 2 is implementing NIST SP 800-171 — and that obligation is still in your contracts under DFARS 252.204-7012, still enforced through self-assessments and select government-led assessments, and still the likely substance of whatever verification model replaces Phase 2. Pausing certification-specific spending while the review runs can be reasonable; pausing 800-171 implementation is not.

Sort Out What This Means for You

Whether you're starting from scratch or preparing for a formal assessment, let's talk through where you stand and what it takes to get compliant. Every inquiry starts with a free 30-minute consultation — no obligation.

Senior-led, capacity-limited. Every engagement is led personally by a Lead Certified CMMC Assessor (LCCA) — never handed off to junior staff. To protect that standard, I take on a limited number of clients at a time. Most inquiries get a reply within 1–2 business days.
Book Your Free 30-Minute Consultation

Pick a time that works for you — no back-and-forth email.

Your information is kept confidential and never shared. See our privacy policy.

Message sent!

Thanks for reaching out. Neal will be in touch within 1–2 business days.