On July 13, 2026, the Department of Defense (DoD) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase 2, which had been scheduled to take effect on November 10, 2026. Phase 2 would have made third-party assessment organization (C3PAO) certification at CMMC Level 2 a condition of award for applicable contracts involving controlled unclassified information (CUI). The suspension is broader than the headline suggests. Phases 3 and 4 and all future implementation milestones are frozen until further notice.

Before you pause your compliance spend, ask the right questions:

  • With no third-party assessor, whose signature now carries the legal risk? Yours.
  • Does your prime contract care what the Pentagon announced? No, and it still binds you.
  • That gap assessment in your files documenting your shortfalls? It did not evaporate.
  • Why a memo instead of a regulation? Because a memo can be reversed just as fast.

A new CMMC Reform Task Force, reporting to the DoD Chief Information Officer (CIO), will review the program and report within 60 days, drawing on responses to a public request for information due August 14, 2026. DoD’s CIO stated that Small Business Administration data suggest future CMMC phases could cost small and midsize businesses more than $7 billion annually. Expectations are also misaligned due to an assessor shortage, with more than 100,000 companies needing assessments and roughly 100 authorized C3PAOs. Officials declined to rule out ending the program entirely, and the Cyber AB was not told before the announcement.

Key Takeaways

  • DoD suspended CMMC Phase 2 and froze future implementation phases, but it did not repeal the CMMC Program rule or amend the DFARS.
  • This is a policy pause, not a regulatory change. Until a class deviation, DFARS rule, or amendment to 32 C.F.R. Part 170 issues, the existing legal framework remains in effect.
  • Contracts—not headlines—control. Existing CMMC clauses, DFARS cybersecurity requirements, and prime contractor flowdowns remain enforceable unless and until they are modified.
  • Government contractors handling CUI should continue implementing NIST SP 800-171, maintain accurate SPRS records, and proceed with compliance efforts unless a deliberate business decision supports a different course.
  • Treat this as a pause, not a repeal. Watch for the August 14 RFI, the Task Force recommendations, and any class deviation or DFARS rulemaking that actually changes the law.

This Is a Memo, Not a Rule

The suspension was affected by two memorandum released July 13 under publication case 26-P-1023—a policy memorandum from the DoD CIO and an implementation memorandum from the undersecretary of defense for acquisition and sustainment—not a rule. No Federal Register document has been issued, 32 C.F.R. Part 170 is unamended, and no DFARS class deviation has been published. The CMMC Program rule and DFARS 252.204-7021 remain in force exactly as written. What is suspended is the department’s exercise of its discretion to designate higher CMMC levels—not the regulations. Until a class deviation, a DFARS rule, or an amendment to 32 C.F.R. Section 170.3(e) issues, plan against the codified text.

What Has Changed

Program managers and requiring activities may now designate only CMMC Level 1 (Self) or Level 2 (Self). They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC) during the suspension. Where a requirements package included a higher requirement, purchasing activities must amend active solicitations as soon as practicable, and contracting officers are directed to remove it from existing contracts by modification before the next option exercise or during the scheduled administrative modification. No CMMC waivers will be granted during the review.

Do not treat the memo as self-executing relief. Some program offices require C3PAO assessments ahead of the November deadline, so higher designations may appear where you would not expect them. Until a modification issues, the clause in your contract is your contract, and DFARS 204.7503(c) still bars option exercise unless your required CMMC status is current in SPRS. Request the modification in writing.

What CMMC Requirements Still Apply

Contractors handling CUI must still implement NIST SP 800-171 Revision 2 (per the May 2, 2024, class deviation, confirmed as the interim baseline) under DFARS 252.204-7012, which still requires 72-hour incident reporting to DIBNet and unaltered flowdown. DFARS 252.204-7019 still conditions award on a current assessment score in SPRS, and 252.204-7020(c) still obligates access for Medium and High assessments. The promised “select government-led assessments” means DIBCAC, and that authority is untouched.

Phase 1 also remains fully in effect, and it is not aspirational. Under DFARS 204.7503(b), a contracting officer must check SPRS and may not award without current CMMC status at the required level. Phase 1 is a codified condition of award.

Your Self-Certification Just Got Heavier

Removing the third-party assessor relocates the assurance onto your own signature. Phase 1 requires an annual affirmation of continuous compliance, entered in SPRS by a named senior Affirming Official. Your affirmation is a certification, and false cybersecurity certifications are the express target of DOJ’s Civil Cyber-Fraud Initiative. The compliance burden went down; the weight on your affirmation went up. Only one of those carries treble damages. An inflated SPRS score was a business risk under the C3PAO model. Under self-attestation plus government audits, it is a litigation risk, and DIBCAC digs deeper than a C3PAO ever did.

Many contractors have also already created a paper trail. Initiating a C3PAO assessment triggered government notification, and gap assessments documented deficiencies in writing. Those records survive the suspension. Remediate on a defensible timeline rather than shelving the report.

What Might Be Missed

Don’t dismantle anything. A reformed requirement could return within months, and government-led assessments continue in the interim. Unwinding and rebuilding a CUI enclave costs more than maintaining one. Do review your compliance vendor and C3PAO agreements now for termination, deferral, and refund rights while you have leverage. That ecosystem is about to consolidate.

Recall that DoD tied interim enforcement to Revision 2, not the Revision 3 published in 2024. That should be read as breathing room on a Revision 3 transition; budget accordingly. This pause was not the news many were expecting.

A completed certification retains real value. From the Cyber AB’s May 2026 town hall, 1,391 Final Level 2 certificates had been issued as of May, and nothing invalidates them. DFARS 252.204-7021(d)(1)(i) requires the stated level “or higher,” so a Level 2 (C3PAO) status satisfies any lesser designation during the suspension. Certification also remains a differentiator with primes and in M&A diligence. If you’ve got it, flaunt it!

Proceed Apace

For most contractors, continue your current compliance plans. This is a speed bump, not a stop sign. Organizations implementing 800-171 or preparing for assessment should not step out of line. Those with C3PAO assessments scheduled or underway should proceed unless cost considerations warrant revisiting the timeline; completing the assessment validates your program and carries the “or higher” contractual value above.

Subcontractors should be especially cautious. The memo binds DoD personnel, not your prime’s subcontract terms. DFARS 252.204-7021(f) requires primes to flow down the substance of the clause, and a prime managing its own liability may keep the higher requirement. Relief does not automatically flow downhill. Confirm any change to your flowdowns in writing before altering assessment plans.

What Government Contractors Should Do Right Now

  • Inventory contracts and pending proposals for CMMC clauses and confirm treatment with your contracting officers in writing.
  • Audit prime flowdowns and supplier portals before changing assessment plans.
  • Validate that your SPRS score is accurate and defensible today; if it isn’t, correct it.
  • Preserve your 800-171 momentum. Proceed with assessments underway; defer to new scheduling only if costs demand it.
  • Calendar August 14 (RFI deadline) and mid-September (task force report) and submit an RFI response if the outcome affects your costs.

What’s Next for CMMC Phase 2

Put plainly, DoD has paused Phase 2; it has not eliminated CMMC. Watch for three things. First, the RFI window closes on August 14. With five of the seven RFI questions seeking industry input on burdens to implementing and complying with the CMMC framework, this is the rare moment when contractor cost data can actually move policy, and small and midsize voices will be underrepresented unless they file. Second, keep an eye open for a class deviation, DFARS rule, or amendment to 32 C.F.R. Section 170.3(e) – anything that changes the actual law; a memo changes only discretion. Third, remember, this action does nothing to the governmentwide CUI rule, now folded into the June 23, 2026, FAR Overhaul rulemaking. Mixed defense and civilian contractors get no reprieve from a CMMC Phase II pause.