What the CMMC Phase II Suspension Means for Defense Contractors
Last updated: July 31, 2026 / Originally published: July 14, 2026
Key takeaway: CMMC Phase II is suspended, not canceled or rescinded. Phase I self-assessments, DFARS 252.204-7012, and NIST SP 800-171 Revision 2 remain in force. A CMMC Reform Task Force has been created to review the program and will report back in mid-September.
On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II, which had been scheduled to take effect on November 10, 2026. The announcement prompted many interpretations across the Defense Industrial Base (DIB) about what changes for contractors.
The Department suspended the CMMC certification mechanism, but it did not suspend the underlying requirement to protect federal information. Understanding that distinction is the key to determining what, if anything, should change in your compliance program and CMMC certification plans.
What is the CMMC Phase II suspension?
Phase II is suspended; Phase I is not. All Phase I self-assessment requirements remain in effect, including annual self-assessments, SPRS score submissions, and affirmations.
The suspension extends beyond Phase II. Pending and future CMMC implementation milestones are suspended across DoW solicitations and contracts, including Phase III (November 2027) and full implementation (2028).
NIST SP 800-171 Revision 2 remains. This stays the enforced standard during the interim period, applied through self-assessments and select government-led assessments.
DFARS 252.204-7012 is unchanged. The suspension does not eliminate the requirement to protect federal data. Contractors and subcontractors remain contractually obligated to safeguard covered defense information.
A formal review process has been established. The Department CIO is forming a CMMC Reform Task Force to conduct a comprehensive review of the program, informed by a public Request for Information on compliance challenges. The Task Force must deliver its final report to the CIO within 60 days, placing the deadline in mid-September 2026.
Key dates
| July 10, 2026 | Suspension memo signed. |
| July 13, 2026 | Public announcement and press briefing. |
| August 14, 2026 | RFI responses due. |
| Mid-September 2026 (estimated) | CMMC Reform Task Force reports to the Department CIO. |
| November 10, 2026 | The former Phase II effective date. This date is suspended and should not be treated as an active deadline. |
| Ongoing | Annual self-assessments and affirmations continue on each organization’s existing schedule throughout the review period. |
Why did the Department of War suspend CMMC Phase II?
The DoW cited compliance costs and small-business attrition in the Defense Industrial Base as the primary drivers of the suspension. The Department’s Chief Information Officer said an assessment bottleneck (more than 100,000 companies needing assessment and ~100 C3PAOs) means small businesses won’t be able to reach compliance by the original date (November 10, 2026). However, many dispute this claim and say that readiness for assessment is the key problem, not assessor availability.
Officials also emphasized that the suspension addresses process rather than security expectations: “We are not reducing cybersecurity through this measure. We are reducing the red tape.”
What the suspension does not change
CMMC was developed to verify that contractors have implemented the controls they attested to. Since 2017, DFARS 252.204-7012 has required covered contractors to implement NIST SP 800-171. Starting in 2020, DFARS 252.204-7019 additionally required contractors to self-report a numerical SPRS score. However, there was a gap between self-reported SPRS scores and what government-led assessments found, necessitating the need for third-party validation.
Because CMMC did not create the requirement to protect CUI, suspending the CMMC verification process does not remove that duty.
It shifts responsibility back to each organization, as self-assessments continue to carry the same weight as before the announcement. CMMC Phase I remains in effect, so SPRS scores and annual affirmations have the same accuracy expectations as before July 13.
The stakes behind this attestation are not hypothetical. In a recent case, a contractor reported a perfect SPRS score of 110 while a government-led review of the same environment scored it at negative 170. The resulting False Claims Act settlement cost the contractor $507,000. Government-led assessments will continue through the suspension, and every SPRS score remains a signed representation to the government.
Recommended steps during the suspension
Despite the suspension, organizations should continue the following:
- Continue implementing NIST SP 800-171 Revision 2. It remains the interim standard, and a mature implementation supports every plausible outcome of the Task Force review.
- Maintain an accurate self-assessment. SPRS scores should reflect current conditions and be supported by objective evidence.
- Continue remediating identified gaps, particularly in access control, multifactor authentication, asset inventory, vulnerability management, incident response, logging and monitoring, configuration management, and encryption of CUI at rest and in transit.
- Maintain visibility into the CUI environment, including system boundaries, data flows, asset categorization, and external service provider relationships. This work applies regardless of which certification framework is ultimately adopted.
- Consult the Contracting Officer regarding any CMMC requirement already present in an awarded contract.
- Submit a response to the RFI. The Department is soliciting industry input on compliance cost drivers, administrative burden, and which NIST SP 800-171 controls provide meaningful risk reduction. Responses are due August 14, 2026, and will inform the Task Force’s recommendations.
Talk to your prime
For organizations working through a prime contractor, three things are worth keeping in mind:
- Silence is not a signal to stop. Most primes are holding their flow-down requirements steady because their own contract risk didn’t change on July 13. “Under review” is effectively the same as silence.
- If multiple primes are involved, the strictest requirement wins. A compliance posture can’t be built around the most lenient customer.
- A clause written into an awarded contract governs until the contracting officer modifies it. The suspension may not apply to that contract at all.
Next steps by certification status
The appropriate response to the suspension depends on where an organization currently stands in the CMMC process. Rather than reacting to headlines, two questions sort most organizations onto the right path.
First: Is your assessment already underway or booked? If yes, and the pause doesn’t change your plans, keep going — nothing about the underlying obligation changed, and a completed certificate carries its full three-year validity.
Second: Does a prime contractor or an existing contract require certification? If yes, continue toward certification. The suspension does not override contractual flow-down obligations.
If the answer to both is no, waiting on certification may be reasonable, but waiting still carries a signature. Your SPRS score is attested under False Claims Act exposure right now, and that’s where your attention should go. This pause provides an opportunity to validate your score and build a plan of action before verification returns.
| Already assessed and compliant | Maintain the current affirmation and keep the environment aligned with the evidence supporting it. |
| Not yet started | Treat the suspension as an opportunity: scope the CUI environment and begin remediation before formal milestones resume. |
| Scheduled or in-progress assessment | Continue rather than pause. The security requirements haven’t changed, and stopping typically costs more than it saves. |
| Close to completion | Finish. The hardest phases are behind you, and demonstrated capability keeps you ahead of competitors. |
The right choice still depends on contractual obligations, customer expectations, and available resources, and should be evaluated on an individual basis. For most organizations already underway, however, continuing is the lower-risk and lower-cost path.
Historical context
Third-party verification was not the Department’s first approach. It was introduced because the honor system did not hold up. Beginning in 2017, contractors were required to self-attest to their implementation of NIST SP 800-171 under DFARS 252.204-7012, with no independent check on the accuracy of that attestation. When the government examined contractor environments, actual implementation fell short of what SPRS scores claimed. That gap is what made third-party assessments necessary in the first place. CMMC exists to confirm that a control environment matches the score reported for it, and that underlying problem is unrelated to whether a Phase II milestone is active.
This is not the first time the Department has suspended and revised a CMMC framework. In 2021, the Department suspended CMMC 1.0 and reworked it into CMMC 2.0. The verification model changed, but the underlying DFARS 252.204-7012 obligation and NIST SP 800-171 standard remained in place throughout the transition. Organizations that continued building their security programs during that period entered CMMC 2.0 without losing the value of their prior work.
What the CyberAB is saying
The CyberAB, the official accreditation body for CMMC, made a statement on July 15, 2026 reiterating that the only thing suspended is the phase II implementation requirements and that “all CMMC program elements remain operational and available.”
On July 28, 2026, the CyberAB held a Town Hall to discuss the current state of CMMC. The CyberAB CEO was emphatic that this is a narrow, contractual pause, not a program shutdown. The practical guidance from CyberAB and the ecosystem is consistent: keep going. They reported that ecosystem capacity is healthy (1,866 Level 2 certificates issued, 111 authorized C3PAOs, no supply shortage), so there’s no operational reason to pause a certification already in motion.
Frequently asked questions
Is the CMMC Phase II suspension the same as CMMC being cancelled?
No. The Department suspended the Phase II third-party assessment mandate pending a 60-day review; it did not cancel the program or eliminate the underlying security requirements. Phase I self-assessments remain fully in place, and NIST SP 800-171 Revision 2 continues to be enforced during the interim period.
Do defense contractors still have to comply with NIST SP 800-171?
Yes. DFARS 252.204-7012 has required NIST SP 800-171 implementation since 2017 and is unchanged by the suspension. The release states explicitly that the action does not eliminate the requirement to protect federal data.
Does an issued CMMC certification still count?
Yes. Nothing in the July 13 announcement revoked or invalidated certifications that have already been issued. A completed C3PAO assessment remains independent evidence that an environment met all 110 NIST SP 800-171 requirements.
What happens if an awarded contract already contains a CMMC clause?
The contract clause continues to govern until a modification is issued. Department officials stated at the July 13 briefing that program managers and contracting officers have been directed to amend or modify active solicitations and contracts containing the suspended Phase II requirements, but until that modification arrives, the existing contract terms apply.
Do prime contractor flow-down requirements still apply?
Yes. Flow-down requirements are contract terms between a prime and its suppliers, and they do not change because a Department milestone was suspended. DFARS 252.204-7012 flow-down obligations remain in effect regardless of the CMMC Phase II suspension.
Should we keep going if our CMMC assessment is already underway?
In most cases, yes. The security requirements behind the assessment have not changed, and pausing typically costs more than it saves as the assessment team and institutional knowledge mobilized for the engagement are not easily reassembled later. When the review concludes, organizations that paused will be competing for the same limited assessment capacity as everyone else.
What should we do if no contract or prime currently requires certification?
Waiting on certification may be reasonable, but the interim period still carries a signature: SPRS scores are attested under False Claims Act exposure regardless of the suspension. Organizations in this position should use the pause to validate their score against current evidence and build a prioritized remediation plan, rather than treating the absence of a near-term deadline as a reason to deprioritize the work.
Are C3PAO assessments still available if we want one voluntarily?
Yes. The DoW has not told the Cyber AB or C3PAOs to stop and the CMMC PMO explicitly directed the ecosystem to keep operating. Many primes still require Level 2 certification contractually regardless of the federal mandate pause.
Is there really a shortage of C3PAO assessors?
That’s disputed. While the DoW’s Chief Information Officer said there is a “severe shortage” of third-party assessors, many practitioners dispute that framing. The Cyber AB reports that nearly 2,000 organizations are already certified at Level 2, and government contracts attorneys have noted that assessment volume has outpaced original rulemaking projections. The backlog for CMMC assessments is not long, and prepared organizations should have no issue scheduling an assessment with a C3PAO.
What does CMMC certification actually cost?
The figures vary widely depending on who’s citing them and what’s being measured. DoW’s estimated a Level 2 C3PAO assessment at roughly $105,000. Separately, SBA Administrator Kelly Loeffler has cited compliance costs “exceeding half a million dollars.” Government contracts attorneys point out that the cost of implementing NIST SP 800-171 controls — remediation, tooling, managed security support — is often conflated with the cost of the C3PAO assessment itself, which is a narrower, later-stage expense. An organization’s actual cost depends heavily on how far its environment is from compliance before the assessment clock starts.
Is NIST SP 800-171 Revision 3 coming?
The interim standard is explicitly Revision 2. Whether Revision 3 is introduced during or after the Task Force review is an open question that the July 13 announcement did not address.
Why did some CMMC guidance pages go offline after the announcement?
Several Department CIO CMMC pages and guidance documents were removed from public view around the time of the announcement, which contributed to speculation that the program had been eliminated entirely. The Department has not explained the removals. The written release and an organization’s own contract terms remain the authoritative record, not the availability of a webpage.
Relevant resources
News release: Department of War Suspends CMMC Phase II Requirements
Department of War Chief Information Officer website
The Cyber AB Statement on the Department of War’s Suspension of CMMC Phase II Requirements
MSP Open Response to the Suspension of CMMC Phase II
Key takeaways
The July 13 announcement changes how the Department verifies contractor cybersecurity. It does not change the underlying requirement to protect CUI. PhThe July 13 announcement changes how the Department verifies contractor cybersecurity. It does not change the underlying requirement to protect CUI. Phase I remains in effect, DFARS 252.204-7012 remains in effect, and NIST SP 800-171 Revision 2 remains the enforced standard. The CMMC Reform Task Force will report to the Department CIO by mid-September 2026.
The CyberAB reports that the CMMC ecosystem has already demonstrated success with nearly 2,000 Level 2 certified organizations, and reiterates that independent, third-party validation remains one of the most effective mechanisms for creating trust, consistency, and accountability across the DIB.
A-LIGN supports efforts to improve and streamline the CMMC program with reforms that increase efficiency, scalability, and consistency, while preserving the fundamental value of independent verification.
How A-LIGN can help
A-LIGN supports organizations across every stage of the CMMC process, from initial scoping and readiness assessments to full Level 2 certification. Our federal assessment team can help evaluate how the Phase II suspension affects a scheduled or in-progress engagement, and can advise on maintaining an accurate self-assessment during the interim period.
Organizations with questions about scheduled assessments, contractual obligations, or interim readiness strategy are encouraged to contact A-LIGN directly.




