CMMC Phase 2 Is Suspended. The Underlying Work Is Not.
Resources/Blog

CMMC Phase 2 Is Suspended. The Underlying Work Is Not.

CMMC Phase 2 Is Suspended. The Underlying Work Is Not.
Compliance CISO
August 13 2026
7 min read

CMMC Phase 2 Is Suspended. The Underlying Work Is Not.

CMMC Phase 2 Is Suspended. The Underlying Work Is Not.

On July 13, 2026, the Pentagon announced the immediate suspension of Phase 2 of CMMC implementation, which had been scheduled to take effect on November 10, 2026. The action came through two memoranda issued under publication case 26-P-1023, a policy memorandum from the Chief Information Officer and an implementation memorandum from the acquisition and sustainment side. A CMMC Reform Task Force was established to conduct a 60-day review, with industry feedback collected through a public request for information.

The suspension is broader than the headline suggests. Pending and future CMMC implementation milestones across solicitations and contracts were held in abeyance until further notice, which reaches beyond Phase 2 alone.

For contractors who had been working toward a November deadline, the natural reading is that the pressure is off. That reading is understandable and it is incomplete in a way that carries real risk.

What Was Actually Suspended

Phase 2 would have expanded requirements for CMMC Level 2 certification assessments performed by accredited third-party assessment organizations for contractors handling Controlled Unclassified Information. That expansion is what has been paused.

The stated reason was capacity. Officials cited a significant imbalance between the number of defense industrial base businesses requiring third-party assessment and the number of accredited assessors available to perform them. The arithmetic did not support the timeline.

For existing contracts and agreements that already contain these requirements, contracting and agreements officers are directed to remove them by modification before the next option period or at the next scheduled administrative modification.

What Was Not Suspended

Phase 1 self-assessment requirements remain in force. Contractors' existing obligations under DFARS clause 252.204-7012 are unchanged. The underlying NIST SP 800-171 Revision 2 control set is unchanged. The requirement to maintain a System Security Plan and a Plan of Action and Milestones is unchanged. Supplier Performance Risk System score postings and annual affirmations continue without interruption.

There is a further point that has drawn less attention and deserves more. The suspension was effected by memoranda, not by rulemaking. No Federal Register document was issued, 32 CFR Part 170 was not amended, and no DFARS class deviation was published. The CMMC Program rule and DFARS 252.204-7021 remain in force as written. What was suspended is the Department's exercise of its discretion to impose higher assessment levels, not the underlying regulations.

Officials framed the action as reducing certification burden rather than lowering the cybersecurity baseline. Read plainly, the audit came off the table. The controls did not.

The suspension removed the entity that would have independently verified your compliance. It did not remove your obligation to be compliant, and it did not remove your obligation to say so.

The Risk That Went Up, Not Down

This is the part worth sitting with. Under Phase 2, an accredited third-party assessor would have reviewed your implementation before an inaccurate claim became a lasting problem. That routine check is now absent for most contractors, though the Department has indicated it intends to enforce the NIST SP 800-171 Revision 2 standard during the suspension through self-assessments and selected government-led assessments.

What remains is self-assessment, affirmed by a senior company official, with a score reported to the government. Misrepresentations about cybersecurity compliance in federal contracting have been an active enforcement area under the civil False Claims Act for several years, and that exposure is not affected by the CMMC suspension.

A contractor who self-attests to controls that are not actually implemented is now carrying that risk without an intermediate check that would likely have surfaced the discrepancy. Less process does not necessarily mean less exposure. In this case it may mean more, concentrated on whoever signs.

What Prime Contractors Are Likely to Do

There is a second dynamic worth anticipating. Primes flow security requirements down to subcontractors through contract terms, and those terms do not automatically relax because a government implementation phase was paused. A prime that has built its supply chain risk program around expected certification may continue requiring evidence of control implementation from subs regardless of what the Pentagon requires this year.

If you are a subcontractor, the operative question may be what your prime requires rather than what the current phase schedule says.

Contractors working across both defense and civilian agencies should also note that this action does not affect the governmentwide treatment of Controlled Unclassified Information outside the Department. A pause on one program does not create relief across a mixed contract portfolio.

What to Do With the Time

One useful way to treat this period is as breathing room rather than a reprieve. The work that would have prepared you for a third-party assessment is the same work that makes your self-assessment accurate.

A gap assessment against NIST SP 800-171 tells you where you actually stand across the control families. A current System Security Plan documents how each control is implemented in your specific environment. A realistic Plan of Action and Milestones documents what is not yet implemented and when it will be. An accurate SPRS score reflects that reality rather than an aspirational version of it.

Contractors who use this window to close real gaps will be positioned for whatever emerges from the review. Contractors who treat the suspension as permission to stop will be in a worse position, holding an affirmation they cannot fully support, and with less time when requirements return in some form.

Sources: Department memoranda issued July 13, 2026 under publication case 26-P-1023, and the accompanying request for information. Details of the suspension, its scope, and the treatment of active solicitations and existing contracts reflect the memoranda and contemporaneous legal analysis. Verify current status directly, as the 60-day review may change requirements.

This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

Tags:

CMMCNIST 800-171DFARSDefense ContractingCybersecurity

Get Your NIST 800-171 Posture Accurate Before You Attest to It

Compliance CISO brings Fortune 500 security expertise, including programs at Equifax, Capital One, and Visa, to fintech companies and credit unions building security and compliance programs. Schedule a free consultation at complianceciso.com/contact.

Recent Posts