Blog · 9 min read ·
ShareCMMC Phase 2 suspended: what defense contractors should do
CMMC Phase 2 (the Nov 10, 2026 C3PAO assessment mandate) was suspended July 13, 2026. The audit is paused — DFARS 252.204-7012 and your NIST 800-171 self-attestation are not. The reform RFI closed August 14 with no results published; no replacement date is set.
If you run IT or security for a defense contractor, the CMMC deadline you have been planning around just moved — or at least paused. On July 13, 2026, the Department of War (the renamed Department of Defense) signed a memo suspending Phase 2 of the CMMC rollout and announced it the same day. Phase 2 was the part that mattered most on the calendar: starting November 10, 2026, Defense solicitations would have required a third-party C3PAO assessment at Level 2 at contract award, instead of a self-attestation. That requirement is now on hold, along with the Phase 3 and Phase 4 milestones behind it.
Before anyone in the room exhales, read the next sentence carefully, because it is the whole point of this post: the audit paused; the obligation did not. This is our read on what actually changed, what explicitly did not, and why — for a mid-market GovCon shop — the right response is to keep hardening your posture, not to stand the project down.
What actually changed on July 13
The memo, signed by DoW Chief Information Officer Kirsten Davies, does three things:
- Suspends the Phase 2 mandate. The requirement to include a C3PAO Level 2 assessment as an award gate in solicitations — scheduled to begin November 10, 2026 — is suspended. Pending and future CMMC implementation milestones in solicitations and contracts are paused.
- Freezes Phases 3 and 4. The later phases of the phased rollout (which would have expanded the assessment requirement across more contract types and up to Level 3 government assessment) are halted alongside Phase 2.
- Orders a 60-day review. A CMMC Reform Task Force is to conduct a comprehensive review and deliver recommendations to the DoW CIO within 60 days. A public Request for Information closed on August 14, 2026 and drew, per the DoW CIO, over 1,100 responses; as of September 13, 2026 no task force results or replacement rule have been published.
The stated rationale is cost and friction. The department's own framing is that CMMC had "created prohibitive compliance costs and bureaucratic burdens" and was "forcing innovative companies out of the defense industrial base" — a nod to the reality that thousands of small and mid-sized contractors face six-figure readiness bills and a thin supply of accredited assessors. The RFI leans directly into that: it asks which NIST 800-171 controls actually reduce risk, and how the department might recognize commercial security tools and managed services in place of separate assessments. Read the RFI questions and you can see the direction of travel — this is reform, not abolition.
What explicitly did not change
This is the part that gets lost in the headline, and it is the part that keeps your compliance program alive:
- DFARS 252.204-7012 still binds. The official release states the suspension "does not eliminate the requirement for companies to protect federal data," and that contractors "remain contractually obligated to safeguard covered defense information" under the DFARS clause. That clause — the safeguarding and incident-reporting requirement — is in your existing contracts and is unaffected by the pause.
- NIST SP 800-171 self-attestation is the interim standard. With third-party assessment paused, the self-assessed 110-control score you post in the Supplier Performance Risk System (SPRS) is once again the representation the government relies on at award. That score has to be real.
- The CMMC Program Rule was not repealed. This is a suspension of implementation milestones by memo, not a rescission of the underlying rule. The framework can return — in the same or a revised form — without new rulemaking to re-enable much of it.
Why this raises your legal exposure, not lowers it
Here is the counterintuitive part that a mid-market contractor should not miss. A third-party assessment is, in one sense, a shield: an independent assessor signs off on your posture. Take that away and put the weight back on your own posted self-score, and the exposure shifts to you.
The Department of Justice's Civil Cyber-Fraud Initiative has, since 2021, treated a knowingly false or inflated cybersecurity representation to the government as a potential False Claims Act violation. That carries treble damages and qui tam whistleblower liability — meaning a disgruntled employee or subcontractor who knows your SPRS score is fiction can file suit on the government's behalf and share in the recovery. Several settlements over inflated 800-171 scores are already on the books. With the audit paused, your SPRS number is the primary thing the government is relying on — which makes an unbacked score a larger liability, not a smaller one.
The overlap with cyber-insurance underwriting is exact, and worth noticing: both the government and your carrier now ask you to attest to controls and increasingly check the attestation against evidence. The failure mode is the same in both — the gap between "we said we enforce it" and "we can prove we enforce it." We wrote about that pattern on the insurance side in cyber-insurance readiness for the mid-market; the CMMC suspension makes the self-attested version of it the live risk for GovCon.
What a defense contractor should actually do now
Our advice to the mid-market GovCon shops we work with is simple: use the pause, don't waste it. The pressure to pass an assessor on a fixed date is off; the reason to have a clean, defensible posture is not. Concretely:
- Make your SPRS self-score honest. If your posted score assumes controls that aren't actually enforced, fix the score or fix the controls — before the number is the only thing between you and a False Claims Act problem. A senior-led 800-171 gap register against the real environment is the deliverable that makes the score defensible.
- Keep the SSP and POA&M current. The System Security Plan and Plan of Action & Milestones are what a self-attestation is built on and what a returning assessment would ask for first. They don't expire because the audit paused.
- Don't rip out GCC High plans mid-flight. If your data classification requires GCC High, that requirement didn't change — CUI and ITAR data still live where they have to live. If you were mid-eligibility decision, finish it; a stalled half-migration is worse than either endpoint.
- Treat the readiness work as insurance, not compliance theater. An accurate score, an SSP, and a closed-out POA&M protect you from FCA exposure today and position you to move fast if the assessment mandate returns. That is the opposite of wasted spend.
This is exactly the fixed-scope, evidence-first work we describe in our CMMC Level 2 pre-assessment and GCC High before CMMC write-ups. The suspension doesn't retire that work — it changes why you do it. You're no longer racing an assessor to a November date; you're making a legal representation to the government true, and keeping a returning mandate from catching you flat.
The RFI is a reform signal — read it that way
The most useful thing in the July 13 action isn't the pause; it's the questions the department asked. The RFI (which closed August 14, 2026) asked industry which 800-171 controls actually reduce risk and whether commercial tools and managed services could substitute for separate assessments. That is a fairly clear signal that what comes back will be a streamlined assessment regime — fewer redundant checks, more credit for controls you can already demonstrate — not a world with no bar at all. Contractors with a clean, evidenced 800-171 posture are the ones best placed under almost any version of the reform. Contractors betting on "CMMC is dead, we can stand down" are reading the memo they wanted, not the one that was signed.
Related reading
- The fixed-fee CMMC Level 2 scoping engagement that produces the SSP, POA&M, and 800-171 gap register: CMMC L2 pre-assessment: what $15K buys you (updated for the suspension).
- Whether your data actually requires GCC High, and the migration timeline if it does: GCC High before CMMC Phase 2 (updated for the suspension).
- The same attest-then-prove pattern on the insurance side: Cyber-insurance readiness for the mid-market (2026).
- Who does the remediation when your own team is stretched thin: IT layoffs, stalled migrations, and the senior bench.
- Service detail: GCC High Migration & CMMC Level 2 Readiness.
Sources and further reading
- Department of War — official release suspending CMMC Phase II (July 2026)
- Federal News Network — Pentagon suspends CMMC Phase 2, launches review
- DFARS 252.204-7012 — Safeguarding Covered Defense Information (still in effect)
- DoD CIO — Cybersecurity Maturity Model Certification
- NIST SP 800-171 — Protecting Controlled Unclassified Information
- DefenseScoop — Pentagon pores over heaps of industry feedback on CMMC reform (Sept. 9, 2026)
- DOJ Office of Public Affairs — Honeywell Aerospace settles False Claims Act cybersecurity allegations (Sept. 1, 2026)
The 30-second version
On July 13, 2026 the Department of War suspended CMMC Phase 2 — the November 10, 2026 requirement for a third-party C3PAO assessment at contract award — and paused Phases 3 and 4. A 60-day reform review is underway and its public RFI closed August 14, 2026. But the suspension explicitly "does not eliminate the requirement to protect federal data": DFARS 252.204-7012 still binds, and NIST 800-171 self-attestation posted in SPRS is the enforceable interim standard. With third-party assessment paused, your self-score is what the government relies on — and under the DOJ's Civil Cyber-Fraud Initiative, a false score is a False Claims Act liability with treble damages. The move for a mid-market GovCon shop is to keep the readiness work going: make the SPRS score honest, keep the SSP and POA&M current, finish any GCC High decision, and treat it as legal insurance and a hedge against the mandate returning.
If you want a senior engineer to validate your 800-171 posture and SPRS score against the real environment, the project intake form takes about three minutes. We'll come back with scope and a fixed-fee range.
Pro IT NW handles GCC High migration and CMMC Level 1 / 2 / 3 readiness for mid-market defense contractors. Vendor-neutral, labor-only. We don't resell GCC High licensing or C3PAO assessments — we validate your 800-171 controls, draft the SSP and POA&M, and make your self-attestation defensible. Nothing here is legal advice; for False Claims Act exposure, talk to counsel.
Questions we get asked
- Is CMMC cancelled?
- No. On July 13, 2026 the Department of War (the renamed Department of Defense) signed a memo suspending Phase 2 of the CMMC rollout — the requirement, which was to begin November 10, 2026, for a third-party C3PAO assessment at contract award — and also paused the Phase 3 and Phase 4 milestones. But the underlying CMMC Program Rule and the DFARS 252.204-7012 clause were not repealed. A CMMC Reform Task Force is reviewing the program over 60 days, and its public Request for Information closed on August 14, 2026. At the Billington CyberSecurity Summit on September 9, 2026, DoW CIO Kirsten Davies said the RFI drew over 1,100 responses and that department staff are still reading through it; as of September 13, 2026 no task force recommendations or reform decision have been published. This is a pause on the assessment mandate, not a repeal of the cybersecurity obligation.
- Do defense contractors still have to protect CUI after the suspension?
- Yes. The official release is explicit that the suspension 'does not eliminate the requirement for companies to protect federal data,' and that contractors remain contractually obligated to safeguard covered defense information under DFARS 252.204-7012. NIST SP 800-171 self-attestation, scored and posted in SPRS, is the enforceable interim baseline. The controls you had to implement before July 13 are still the controls you have to implement — you just aren't (for now) proving them to a third-party assessor at award.
- Does the CMMC suspension reduce my legal risk?
- No — in some respects it raises it. With third-party assessment paused, your posted SPRS self-score becomes the primary representation the government relies on. The Department of Justice's Civil Cyber-Fraud Initiative treats a false or inflated self-score as a potential False Claims Act violation, which carries treble damages and whistleblower (qui tam) exposure. A self-attestation you can't back with evidence is a bigger liability when it's the only thing standing between you and the contract. NIST 800-171 obligations are already being enforced through the False Claims Act, pause or no pause: on September 1, 2026 the Department of Justice announced Honeywell Aerospace had agreed to pay $2,042,518 to resolve False Claims Act allegations that a business unit failed to meet NIST SP 800-171 requirements on one of its networks, for conduct from April 2020 through December 2023 — predating the suspension — with $375,823 of the settlement going to a former Honeywell employee. DOJ's release states plainly that 'the claims resolved by the settlement are allegations only and there has been no determination of liability,' but the case shows the government is actively pursuing 800-171 gaps under the False Claims Act, independent of the CMMC pause.
- Should we stop our CMMC / GCC High preparation?
- We'd advise against standing down. Three reasons: your 800-171 self-attestation still has to be accurate and defensible; the assessment mandate is under review, not gone, and could return in a revised form; and the readiness work — an honest SPRS score, an SSP, a POA&M, GCC High eligibility — is exactly what a self-attestation needs and what protects you from a False Claims Act problem. Pausing the audit is a good reason to fix the score quietly, not a reason to let it drift.
- When will we know what replaces CMMC Phase 2?
- The memo directed a 60-day CMMC Reform Task Force review with recommendations to the DoW CIO. The public RFI closed on August 14, 2026, and the derived 60-day mark — roughly September 11, 2026 — has now passed with no task force report, no replacement rule, and no amendment to 32 CFR Part 170 published. The RFI asked industry which NIST 800-171 controls deliver meaningful risk reduction and how the department might recognize commercial cybersecurity tools and managed services in lieu of separate assessments — which signals the direction of reform. At the Billington CyberSecurity Summit on September 9, 2026, DoW CIO Kirsten Davies said the RFI drew over 1,100 responses — some representing groups such as the Cloud Security Alliance — and that department staff, not AI, are reading all of it; she gave no date for when recommendations would be ready. As of September 13, 2026, the DoW CIO's own CMMC page shows nothing newer than the July 13 suspension and the Federal Register has published no CMMC-related document since September 1, 2026. Expect the shape of the replacement to emerge later in the fall of 2026; treat any specific new date as unconfirmed until a rule or memo sets it.
Related service
GCC High & CMMC serviceWritten by the team at Pro IT NW · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.