Compliance

July 20, 2026

CMMC Phase 2 Is Suspended. Do Not Stand Down.

The DoD paused third-party CMMC assessments on July 13. Self-assessment and DFARS 252.204-7012 still bind. Here is what changed and what did not.

CMMC Phase 2 Is Suspended. Do Not Stand Down.

On July 13, 2026, the Department of Defense suspended Phase 2 of the Cybersecurity Maturity Model Certification program. Third-party assessments by C3PAOs are paused. The November 10, 2026 deadline for ramping them up is postponed indefinitely. A sixty-day top-to-bottom review of the program is underway, and the memo suspends all pending and future CMMC milestones until further notice.

If you are a defense contractor who has been sweating an assessment date, that is a genuine reprieve. If you read it as permission to stop, you have misread it.

What was actually suspended

Only the third-party assessment requirement. That is the whole of it.

DoD CIO Kirsten Davies was direct about the reasoning, saying the program "imposes significant and often prohibitive burdens on the Defense Industrial Base, particularly the small and non-traditional businesses," and that "the current CMMC program is structurally incompatible with our need to rapidly expand the DIB."

That is a statement about cost and access, not about whether the underlying security requirements matter. Nothing in the suspension says the controls were wrong.

What is still fully binding

This is the part that gets lost in the headlines.

Self-assessment continues. Contracting officers can still require CMMC Level 1 (Self) or Level 2 (Self) on contracts, and Phase 1 requirements remain active. During the review window, self-assessment is what gets designated. No waivers are being issued.

DFARS 252.204-7012 has not moved an inch. If you handle Controlled Unclassified Information, you are still required to implement NIST SP 800-171 and still required to report cyber incidents to DoD within 72 hours. This clause predates CMMC, exists independently of it, and carries False Claims Act exposure if you affirm compliance you do not have.

Annual affirmation still applies. Under 32 CFR 170.22, a senior Affirming Official signs off on your compliance every year. That signature is a personal attestation.

Government-led assessments continue. The DoD can still come and look.

Cloud services handling CUI still need FedRAMP Moderate authorization.

So the honest summary is: the auditor is not coming next quarter, and everything the auditor was going to check is still your legal obligation.

What Level 2 actually asks for

For contractors who have not yet done the work, the target has not changed. CMMC Level 2 maps to the 110 security requirements in NIST SP 800-171, organized across 14 domains covering access control, identification and authentication, incident response, system and communications protection and the rest.

Scoring runs against NIST SP 800-171A objectives out of a perfect 110. Unlike Level 1, where the 15 requirements are scored met or not met with no plan of action permitted, Level 2 allows a conditional status: remaining gaps can sit on a Plan of Action and Milestones alongside a System Security Plan.

Those two documents — the SSP and the POA&M — are where most smaller contractors lose the most ground, and they are entirely within your control to fix right now.

Why standing down is the expensive choice

Three reasons.

The pause has an end. The DFARS CMMC clause 252.204-7021 remains prescribed through November 9, 2028. A sixty-day review is a review, not a repeal. The most likely outcome is a modified program, not no program, and the businesses that keep working will be the ones ready when it lands.

Your prime contractor is not waiting. Flow-down requirements do not track DoD memos in real time. Primes have their own obligations, their own risk appetite, and their own lawyers. Plenty will keep asking for evidence regardless of what Phase 2 is doing.

Your SPRS score is visible. Self-assessment scores get submitted to the Supplier Performance Risk System, and they are used. A low score is a competitive disadvantage in a room where somebody else has done the work.

What to do in the next ninety days

The suspension has handed you something valuable: time, without a deadline attached. Use it on the things that are slow.

Scope your CUI honestly. Where does it actually live? Which laptops, which shares, which mailboxes, which subcontractors? Most assessment failures trace back to a scope that was drawn optimistically rather than accurately. This takes weeks and cannot be rushed later.

Write a System Security Plan that describes reality. Not aspiration. An SSP that says you do things you do not do is worse than no SSP, because it converts a security gap into a documentation problem with legal weight.

Score yourself properly against all 110. Against the 800-171A objectives, not a vibe. Then put the gaps on a POA&M with real dates and real owners.

Fix the evidence problem. Most contractors are doing more than they can prove. Screenshots, logs, policy documents, training records, ticket histories. Evidence collection is tedious, which is exactly why doing it without deadline pressure is a gift.

Sort the multi-factor authentication and access control gaps. These are the domains where small contractors most often fall short, and they are also the ones that reduce real-world risk fastest.

The bottom line

The DoD suspended a mechanism, not a standard. Contractors who treat July 13 as the end of the obligation will find themselves explaining, at some point, why they attested to something they had not done.

Contractors who treat it as breathing room will be in a much better position whenever the program returns — and better protected in the meantime, which was always the actual point.

If you want a clear-eyed picture of where you stand against the 110, that is precisely what a Secure Start assessment produces: a score, a gap list, and a plan you can hand to your Affirming Official without crossing your fingers.

Start the conversation

Not Sure Where to Start?

You do not need to know which cybersecurity service to ask for. Tell us what prompted the conversation and we will help you determine the right place to start.

  • A customer sent a security questionnaire
  • A compliance requirement is coming into scope
  • A cyber insurance renewal raised new questions
  • Leadership wants to know where the business stands

Prefer to talk directly?
Info@ProtectTheCube.com · 888-408-CUBE

A security advisor in conversation with a client across a desk
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Simplifying cybersecurity, one Cube at a time.
Copyright © 2026 Cube IT  |  Powered by Supersad Productions