MSPowerhouse — Your Strategic IT PartnerMSPowerhouse

Cybersecurity

CMMC Phase 2 Is Suspended. Here Is What Defense Contractors Still Have to Do.

The Department of War suspended CMMC Phase 2 on July 13, 2026, along with every milestone after it. Phase 1 self-assessments, NIST 800-171 and your SPRS score still apply. Here is what changed, what did not, and the August 14 deadline most contractors have missed.

AUTHOR:

Tanya Izz

PUBLISHED:

August 4, 2026

READ TIME:

7 min read

SHARE

CMMC Phase 2 Is Suspended. Here Is What Defense Contractors Still Have to Do.

On July 13, 2026, the Department of War suspended CMMC Phase 2. The requirement that most contractors handling Controlled Unclassified Information obtain a third-party certification before contract award, scheduled to begin November 10, was halted, along with all pending and future CMMC milestones.

If your team has spent the last eighteen months preparing for a C3PAO assessment, that news probably landed somewhere between relief and frustration.

It should land as neither. The announcement changed the enforcement mechanism. It did not change your obligation to protect federal data, and it did not remove a single requirement from the contracts you already hold.

Here is what actually happened, what is still in force, and what to do between now and mid-September.

What was announced on July 13

The suspension came through two memoranda issued under publication case 26-P-1023: a policy memorandum from the Department of War Chief Information Officer, Kirsten Davies, and an implementation memorandum from the Under Secretary of Defense for Acquisition and Sustainment (Government Contracts Law).

Four things took effect immediately.

Phase 2 was suspended. Level 2 certification by an accredited third-party assessment organization is no longer scheduled to become a condition of award in November.

All remaining milestones were paused. That includes Phase 3, planned for November 2027, and full implementation in 2028.

Solicitation rules changed. During the review period, new solicitations can designate only CMMC Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) requirements are being removed from active solicitations and existing contracts.

Waivers stopped. The Department will not grant waivers under the CMMC Program while the review is under way.

A CMMC Reform Task Force was established under the CIO, charged with reviewing the entire program and delivering recommendations within 60 days, which places its report around mid-September 2026 (Holland & Knight).

The stated reason was cost. Officials pointed to the burden third-party assessments place on smaller firms, and the CIO cited an assessment capacity problem: more than 100,000 companies requiring assessment against roughly 100 accredited C3PAOs (A-LIGN).

What did not change

This is the part getting lost in the coverage, and it is the part that affects your next contract.

Phase 1 is still in force

Self-assessment requirements took effect on November 10, 2025 and remain fully applicable. Contracting officers can continue inserting Phase 1 self-assessment requirements into new solicitations throughout the review period.

NIST SP 800-171 Rev 2 is still the standard

In the interim, the Department will enforce cybersecurity compliance through self-assessments and selected government-led assessments against the same standard (DefenseScoop). The bar did not move. Only the party checking it did.

Your existing obligations are unchanged

You still need a System Security Plan. You still need a Plan of Action and Milestones for anything not yet implemented. You still need a current score posted in SPRS, and you still need to submit your annual affirmation.

A suspension is not a repeal

Both documents issued on July 13 were memoranda, not rules. A memorandum directs how the Department exercises discretion. What would change the law is a class deviation, a DFARS rule, or an amendment to 32 CFR 170.3(e) (Government Contracts Law). Until one of those appears, the CMMC Program finalized in October 2024 under 32 CFR Part 170 remains the regulation on the books.

Your primes have not paused anything

Most prime contractors are holding their flow-down requirements steady, because their own contract risk did not change on July 13. Where several primes are involved, the strictest requirement governs (A-LIGN). Prime contractors have been advised to evaluate whether existing flow-down provisions remain appropriate and to communicate clearly with subcontractors about continuing obligations (Holland & Knight).

The trap for small subcontractors

The most expensive misreading of this announcement is simple: assume CMMC is off, cancel the security work, and reallocate the budget.

That decision looks reasonable in August. It looks very different when the task force reports in September, when a prime sends a flow-down requirement in October, or when you find yourself bidding against a competitor who kept going.

There is a second exposure worth naming. Executives who sign annual affirmations carry personal and organizational risk under the False Claims Act, and legal counsel is advising contractors to review that exposure now that self-attestation is carrying more of the enforcement weight. An inflated SPRS score was always a liability. It is a larger one today.

The August 14 deadline nobody is talking about

Alongside the suspension, the Department published a Request for Information titled Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base. It asks seven questions covering cost drivers, which controls deliver real risk reduction, which impose burden without it, what commercial security capabilities the Department could accept instead, and how self-assessment could be streamlined (Sheppard Mullin).

Responses are due by 12:00 p.m. ET on Friday, August 14, 2026, and are accepted by email only.

This is worth your time for one reason. The responses feed directly into the task force recommendations. Large primes will file detailed submissions. Small and mid-size firms usually do not, which means the cost data shaping the next version of this program will over-represent organizations that can absorb the cost. If your compliance spend has been painful, this is a narrow window where documenting that has a chance of mattering.

What to do between now and mid-September

Keep going

If you are mid-remediation, finish. Every control you implement now is one you do not implement under deadline pressure later. The underlying standard is not in question, and scoping work, your System Security Plan and your evidence library carry over directly to whatever framework replaces Phase 2.

Make your SPRS score accurate

Self-assessment is now the primary enforcement mechanism, with select government-led assessments alongside it. Accuracy matters more when nobody else is checking your work first.

Check your awarded contracts

If a CMMC requirement already appears in a contract you hold, raise it with your contracting officer rather than assuming the suspension removed it. Requirements are contract-specific, and the memo directs contracting officers on handling existing procurements.

Do not buy on the November deadline

If a vendor is selling certification readiness on urgency tied to November 10, that argument no longer holds. Buy on the security value, not on a date that has been suspended.

Watch for the right signal

Ignore commentary and watch for a class deviation, a DFARS rule, or an amendment to 32 CFR Part 170. Anything short of that changes discretion, not law.

Where MSPowerhouse fits


MSPowerhouse is a Microsoft Partner in Stafford, Virginia working with growing organizations across Northern Virginia on cybersecurity, Microsoft 365 and managed IT. You can see the sectors we work in or read more on our blog

If you want a straight answer on where your Microsoft 365 environment stands, book a free review. Thirty minutes, no obligation.


Sources

Pentagon suspends CMMC phase two requirements, launches review of program (Federal News Network)

DOD halts cybersecurity requirements for CMMC Phase 2 (DefenseScoop)

DOW Suspends CMMC Phase II Requirements (Holland & Knight)

DoW Hits Pause on CMMC: What Contractors Need to Know Now (Sheppard Mullin)

DoD Suspends CMMC Deadlines and Seeks to Reassess Requirements (Greenberg Traurig)

DoD Suspends CMMC Phase 2: What Contractors Need to Know (Government Contracts Law)

What the CMMC Phase II Suspension Means for Defense Contractors (A-LIGN)

DoW Requests Information for CMMC Reform Task Force (SBA Office of Advocacy)

This article is general information, not legal advice. Contractors should confirm contract-specific obligations with their contracting officer or counsel.

Frequently asked questions