If you hold defense contracts or sit anywhere in a defense supply chain, you probably saw the headline before you finished your first cup of coffee. On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase 2, the requirement that would have made third-party certification a condition of contract award starting November 10, 2026. Within hours, the interpretations started flying. Some contractors read it as CMMC being cancelled. Others read it as a temporary pause. A few decided it meant they could stop spending money on compliance altogether.
None of those interpretations are quite right, and the gap between what the announcement said and what many people heard is exactly where expensive mistakes get made. So, let’s walk through what actually changed, what stayed exactly the same, and what a sensible path forward looks like while the dust settles.
What the Department of War Actually Announced
The announcement did three specific things. First, it suspended the transition to CMMC Phase 2 requirements, along with all pending and future CMMC implementation milestones across Department of War solicitations and contracts. Phase 2 would have introduced mandatory third-party assessments, conducted by authorized C3PAOs, for contracts involving Controlled Unclassified Information. That rollout is now on hold.
Second, it launched a 60-day comprehensive review of the entire CMMC program. A newly formed CMMC Reform Task Force will gather industry feedback through a public Request for Information, with responses due August 14, 2026, and deliver recommendations to the Department CIO by roughly mid-September. The stated goal is to reduce compliance costs and lower barriers for small and midsize businesses in the defense industrial base.
Third, and this is the part that got lost in most of the coverage, the announcement explicitly stated that Phase 1 requirements remain firmly in place. During the interim period, the Department will enforce cybersecurity compliance with NIST SP 800-171 through self-assessments and select government-led assessments. Every defense contractor and subcontractor remains contractually obligated to safeguard covered defense information under DFARS 252.204-7012.
In plain terms, the government suspended a verification mechanism. It did not suspend the requirement to protect its information.
Is CMMC Going Away?
This is the question underneath every other question, so it deserves a direct answer. Based on everything in the official memo, no. The program was suspended, not cancelled. The review is examining how compliance gets verified and what it costs, not whether defense contractors should protect Controlled Unclassified Information.
There’s a meaningful difference between the tone of the public messaging and the text of the memo itself. The messaging emphasized cutting red tape and easing burdens on small business. The memo, which went through the Department’s lawyers, preserved every underlying security obligation. When the speech and the document disagree, the document is what governs your contracts.
History also offers some perspective here. CMMC has already been overhauled once, when CMMC 1.0 became CMMC 2.0 under a new Department CIO. A new CIO reviewing the program and reshaping it is not the program dying. It’s the program doing what it has done before. The most likely outcomes of the review are adjusted timelines, changes to how smaller businesses demonstrate compliance, and potential relief on some of the costlier infrastructure requirements. The requirement to meet NIST SP 800-171 is written into contracts through DFARS, and that isn’t touched by any of this.
Do I Still Have to Comply with CMMC Level 2 Requirements?
Yes, and this is where the “we’re off the hook” reading falls apart. If your contracts involve CUI, the Level 2 requirements still apply. What changed is who verifies your compliance. Instead of a third-party assessor confirming that you meet the controls, you now attest to it yourself.
That sounds easier. In one important way, it’s riskier.
A self-assessment at Level 2 is not a checkbox exercise. NIST SP 800-171 contains 110 security requirements, but each requirement breaks down into assessment objectives defined in NIST SP 800-171A, roughly 320 individual items in total. To meet a requirement, you have to meet every objective underneath it. Take multi-factor authentication as an example. Most companies turn on MFA for their cloud accounts and consider it done. The assessment objectives ask whether MFA is enforced for network access and for local access to systems. Miss one objective and you haven’t met the requirement, no matter how confident your answers feel.
When your organization self-attests, a senior company official affirms compliance in the government’s SPRS system, and that affirmation is not a single signature at the bottom of a form. It’s an item-by-item declaration that your company meets each requirement. If a government audit later finds that the attestation was inaccurate, the exposure runs through the False Claims Act, which can carry penalties of up to three times the contract value. This is not a theoretical risk. In June 2026, just weeks before this announcement, a defense contractor paid over half a million dollars to settle False Claims Act allegations tied to cybersecurity requirements in Navy contracts. The government has signaled it intends to keep enforcing accuracy in these attestations, and the Department’s own interim guidance specifically mentions government-led assessments continuing during the pause.
The pattern worth watching here is compliance drift. Companies that treated CMMC preparation as a one-time project, or that assumed their IT provider had everything handled, often have a gap between what their documentation says and what their systems actually do. Under third-party assessment, an assessor would catch that gap before it became a legal problem. Under self-attestation, the gap becomes your CEO’s signature.
What About My Prime Contractors?
Here’s the practical reality that matters more than anything the Pentagon announced: your prime contractors set the requirements for your contracts, and so far, primes have not walked back their expectations.
Prime contractors are responsible for their entire supply chain. If a government audit finds a subcontractor out of compliance, the prime absorbs the consequences on its contract. That’s why many primes were already requiring C3PAO certification from their subs ahead of the government deadline, and why the early indications are that they’ll keep doing so. Some may relax their timelines now that November 10 is no longer a hard federal date. Very few have any incentive to drop the requirement entirely, because a certified sub is a de-risked sub.
The right move is straightforward. Before you change anything about your compliance plans, have a direct conversation with each prime you work under. Ask what they will require and on what timeline. Their answer governs your business, regardless of what the Department of War does over the next sixty days. One more detail worth knowing: the Department clarified shortly after the announcement that active solicitations already containing Level 2 certification requirements would be amended, so if you’re mid-pursuit on a contract, confirm the current requirement in writing rather than assuming either direction.
Should I Pause My Compliance Work?
It’s a fair question, especially if you were staring down a significant remediation budget. The honest answer is that the announcement changed your timeline pressure, not your obligations, and it may have handed you a strategic opportunity if you use it deliberately.
Consider what the pause actually gives you:
- Breathing room on spend. If you were compressing an expensive remediation into a few months to hit November, you may now be able to sequence that work over additional quarters without missing a contractual deadline. Spreading the investment is a legitimate strategy. Abandoning it is not, because the requirements you’d be remediating toward are still in your contracts.
- Time to fix the documentation half. Many companies invested in technology first and let policies, procedures, and their System Security Plan lag behind. A self-attestation regime makes that documentation more important, not less, because it’s the evidence standing behind your affirmation.
- A differentiation window. While competitors slow down or wait for clarity, contractors who continue toward assessment readiness, or who complete a voluntary C3PAO assessment, will have something concrete to show primes and contracting officers. Companies that certified early have already used it as a wedge to win relationships with larger contractors, and a completed third-party assessment is also strong protection against False Claims Act exposure, since an independent expert validated your compliance rather than your own team grading its own homework.
What the pause does not give you is permission to answer “not applicable” your way out of hard requirements, or to self-attest based on a quick read of the 110 controls. The contractors who get into trouble during this period won’t mostly be the dishonest ones. They’ll be the ones who genuinely believed they were compliant because nobody with assessment experience ever tested that belief.
What Should Defense Contractors Do During the 60-Day Review?
The review period ends in mid-September, and the most likely outcome is a revised program with adjusted timelines rather than a repeal. Between now and then, a measured plan looks like this. Confirm your prime contractors’ requirements in writing, because those requirements are unaffected by the suspension. Keep your DFARS 252.204-7012 obligations and your SPRS score current, since both remain fully enforceable today. If you haven’t validated your self-assessment against the full set of NIST SP 800-171A objectives, do that before anyone in your company affirms compliance in SPRS. And if you have a voice in this, respond to the Department’s RFI before August 14, because this is a rare window where cost data from small and midsize contractors can actually shape the program you’ll be living with.
The companies that come out of this period ahead won’t be the ones that guessed right about what the Pentagon decides in September. They’ll be the ones whose security posture and documentation were solid enough that the decision didn’t matter much either way.
If you’re weighing what this means for your own contracts, your compliance budget, or a remediation plan that was built around the November deadline, that’s a conversation worth having with someone who can look at your specific environment rather than the headlines. We’re glad to walk through where you stand and what a sensible sequence looks like from here.


