What Happened
In a memo signed July 13, 2026, the Department of War CIO immediately suspended CMMC Phase 2 — the requirement, scheduled to take effect November 10, 2026, that contractors handling Controlled Unclassified Information obtain a third-party Level 2 certification from a C3PAO — along with all later phases and future implementation milestones.
The department's stated reasoning: compliance costs and a severe shortage of assessment capacity were pushing small businesses out of the defense industrial base. Roughly 100,000 companies needed third-party assessments, with only about 100 authorized C3PAOs available to conduct them. During the suspension, DoW program managers may designate only Level 1 (Self) or Level 2 (Self) in solicitations — not Level 2 (C3PAO) or Level 3 (DIBCAC).
Alongside the suspension, the department stood up a CMMC Reform Task Force to conduct a top-to-bottom review of the program and report within 60 days — roughly mid-September 2026 — and published a public Request for Information with responses due August 14, 2026.
What's Suspended vs. What Still Applies
This is the distinction the headlines blur: the certification mechanism is paused; the security requirements are not.
Suspended
- Level 2 C3PAO certification mandate (was scheduled for Nov 10, 2026)
- Level 3 DIBCAC certification designations
- CMMC Phases 3 and 4 rollout milestones
- New CMMC certification requirements in DoW solicitations
Still Fully in Force
- DFARS 252.204-7012 safeguarding & incident reporting
- All 110 NIST SP 800-171 Rev 2 requirements for CUI
- Level 1 and Level 2 self-assessments
- SPRS scores and annual senior-official affirmations
- Prime-to-subcontractor flowdown obligations
- Government-led DIBCAC audits
- Government-wide CUI safeguarding under the FAR
The Part Nobody Should Miss: Self-Attestation Shifts the Risk to You
Under the C3PAO model, an independent assessor validated your compliance before you certified it. Under self-assessment, your SPRS affirmation stands alone as a representation to the federal government — signed by a senior company official.
The Department of Justice's Civil Cyber-Fraud Initiative has already used the False Claims Actagainst contractors whose cybersecurity attestations didn't match reality, with settlements reaching into the millions — and whistleblower provisions that reward employees who report gaps. The suspension didn't lower that exposure; it removed the independent checkpoint that stood in front of it.
The practical takeaway: a self-assessment you can defend — every control determination linked to current evidence, every affirmation backed by a documented review — is now your primary legal protection. An affirmation without an evidence trail is a liability with your signature on it.
What Defense Contractors Should Do Now
Don't dismantle your compliance program
The requirements you were preparing for are still contract conditions. A reformed certification requirement could return within months, and rebuilding a paused program costs far more than maintaining one.
Treat your self-assessment like an audit record
Score all 110 requirements honestly, link evidence to every determination, keep your SSP current, and track gaps in a POA&M with real milestones. This is exactly the record that defends an affirmation if it's ever questioned.
Keep your SPRS score and affirmations current
These remain mandatory, and primes are still checking them when they select subcontractors. An accurate, well-documented score is a competitive asset during the uncertainty.
Talk to your primes before changing course
Flowdown obligations continue, and some primes may keep requiring third-party certification contractually even while the DoW mandate is paused. Your primes' expectations — not just the regulation — set your real requirements.
Make your voice heard by August 14
The Reform Task Force is soliciting public input through a Request for Information due August 14, 2026. If compliance costs have shaped your bid decisions, that data is exactly what the review is asking for.
Watch mid-September
The Task Force reports roughly 60 days from the suspension. That report — not the suspension memo — will tell you what the program becomes.
Frequently Asked Questions
Is CMMC going away?
Not yet, and probably not entirely. The July 13, 2026 memo suspended Phase 2 implementation — the third-party assessment mandate — and launched a 60-day reform review. The underlying regulations (32 CFR Part 170, DFARS clauses) were not rescinded, and Level 1 and Level 2 self-assessment requirements remain in force. Officials have not ruled out ending the program, but most legal analysts expect a reformed program rather than elimination.
Do I still have to comply with NIST 800-171?
Yes. DFARS 252.204-7012 remains fully binding, which means implementing all 110 NIST SP 800-171 Revision 2 requirements is still a contract condition for any contractor handling CUI. The suspension paused the certification mechanism, not the security standard.
What exactly was suspended?
CMMC Phase 2 — the requirement, scheduled to take effect November 10, 2026, for third-party (C3PAO) assessments at Level 2 — plus all later phases and future implementation milestones. During the suspension, DoW program managers may only designate Level 1 (Self) or Level 2 (Self) in solicitations. They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC).
Do I still have to submit SPRS scores and annual affirmations?
Yes. Level 1 and Level 2 self-assessments, SPRS score submissions, and annual affirmations by a senior company official remain mandatory. Prime contractor flowdown obligations to subcontractors also continue to apply.
Should I cancel my scheduled C3PAO assessment?
Not automatically. Voluntary Level 2 certification assessments remain available through the Cyber AB ecosystem, and a completed certification is strong evidence of compliance for primes and a hedge against the program returning in reformed shape. Review your assessment contract's deferral and refund terms, weigh the cost against your contract pipeline, and talk to your primes before deciding.
What happens after the 60-day review?
A CMMC Reform Task Force reporting to the DoW CIO will deliver findings and recommendations roughly by mid-September 2026, informed by public RFI responses due August 14, 2026. Possible outcomes range from a restructured phase schedule to a lighter-touch assessment model to broader program changes. Contractors who kept their compliance programs running will be positioned for any of them.
Does the suspension reduce my legal risk if I self-attest?
No — it arguably increases it. With no third-party assessor validating your claims, your SPRS affirmation stands alone as a representation to the government. The Department of Justice's Civil Cyber-Fraud Initiative has pursued False Claims Act cases over inaccurate cybersecurity attestations, and settlements have reached into the millions. Documented, evidence-backed self-assessments are now your primary legal protection.