Last reviewed: 2026-07-14. This is a fast-moving situation; verify current state against the DoD CIO CMMC Program Office before making contract or investment decisions.
What Happened
On July 13, 2026, the Defense Department announced an immediate suspension of CMMC Phase 2 — the phase that would have made a third-party (C3PAO) certification a mandatory condition of contract award, scheduled to begin November 10, 2026. At the same time, it stood up a CMMC Reform Task Force to review the entire program and report findings and recommendations within 60 days.
The one-line version: You do not currently need a third-party CMMC certification to win a contract. You do still have to safeguard Controlled Unclassified Information, implement NIST SP 800-171, complete a Level 2 self-assessment, and keep a current score in SPRS. The certification is suspended; the standard is not.
What Was Suspended vs. What's Still in Force
This is the distinction that matters, and it's the one most easily lost in the headlines. Only the third-party assessment layer was paused. Every underlying obligation remains fully enforceable.
Paused pending the 60-day review
- The mandatory C3PAO third-party certification milestone (was set for Nov 10, 2026)
- Certification as a condition of contract award for prioritized CUI
- The near-term Phase 2 / Phase 3 rollout schedule as previously published
Unchanged by the suspension
- DFARS 252.204-7012 — safeguarding of covered defense information
- NIST SP 800-171 — the 110-control security standard
- Level 2 self-assessment and the senior-official affirmation
- SPRS score posted prior to contract award (DFARS 7019/7020)
Why It Happened
The suspension was driven by cost and capacity — the same pressures small contractors have been raising since the Final Rule took effect:
- Cost to small business. SBA analysis suggested the coming phases could cost small and mid-sized firms more than $7 billion per year, with individual compliance bills approaching $600,000.
- Assessor capacity. More than 100,000 Defense Industrial Base companies would need certification from a pool of only roughly 100 approved assessment organizations — a bottleneck with no realistic path to clear on schedule.
- Market access. Officials cited concern that the combination of cost, capacity shortfalls, and timeline complexity was pushing innovative new entrants and small suppliers out of the defense market.
What It Means for You
Your situation depends on where you were in the process:
- You were racing toward a C3PAO assessment for a November deadline: the deadline pressure is off, but do not cancel your readiness work. The self-assessment obligation is live now, and certification is likely to return in some form after the review.
- You handle CUI on an active contract: nothing about your DFARS 7012 and 800-171 obligations changed. If you don't have a current SPRS score, you are still at risk today — that requirement was never part of Phase 2.
- You were told "CMMC is dead, we can stand down": that's the costly misread. The standard is intact and enforced through existing clauses; only the third-party certification step is paused.
- You are bidding new work: read each solicitation. Self-assessment and SPRS requirements still appear in contracts under Phase 1.
What to Do Now
- Keep (or get) your SPRS score current. This is the live, enforceable requirement and the cheapest thing to get wrong.
- Finish your System Security Plan and self-assessment. The work that made you certification-ready is the same work that makes you self-assessment-compliant today — none of it is wasted.
- Treat readiness as insurance. With certification likely to return after the review, staying prepared is the low-cost hedge; standing down and restarting later is the expensive path.
- Watch the 60-day clock. The task force's recommendations, expected around mid-September 2026, will define the next phase. Don't make irreversible decisions on the assumption the requirement is gone for good.
Bottom line: Nothing about your day-to-day compliance obligation changed on July 13. What changed is the deadline pressure around one step — the third-party audit. The contractors who stay ready will be the ones positioned to win, whatever the task force decides.
What's Next
The CMMC Reform Task Force has roughly 60 days to review the program and recommend a path forward. Possible outcomes range from a revised, lower-cost certification model, to expanded self-attestation, to a delayed reintroduction of third-party assessment. We will update this page as the picture clarifies. Until then, plan for the standard to persist and for some form of verification to return.
Sources
- DefenseScoop — DOD halts cybersecurity requirements for CMMC Phase 2
- Washington Technology — DoD suspends CMMC Phase 2, launches 60-day reform review
- Federal News Network — Pentagon suspends CMMC Phase 2 requirements, launches review
- Crowell & Moring — Immediate suspension of CMMC Phase II, 60-day reform review
This page is provided for general information and reflects reporting as of the date shown. It is not legal advice. Confirm your specific obligations against your contract clauses and the DoD CMMC Program Office.