CMMC Phase 2 Is Suspended. What Contractors Still Owe
DoD suspended CMMC Phase 2 on July 13, 2026. The C3PAO deadline is gone, but DFARS clauses and your SPRS affirmation still bind. Here is what changed.
On July 13, 2026, the Department of Defense suspended CMMC Phase 2.
If you have been working toward a third-party certification on a November 2026 clock, that clock is gone. If you read the announcement and concluded your cybersecurity obligations went with it, that reading will cost you.
Here is what actually changed, what did not, and what to do with the time.
Is CMMC still required?
Third-party certification is paused; the underlying requirements are not. Two memoranda issued July 13, 2026 under publication case 26-P-1023, one policy memo from the DoD CIO and one implementation memo from the undersecretary of defense for acquisition and sustainment, suspended CMMC Phase 2 and froze Phases 3 and 4 along with all future implementation milestones. During the suspension, program managers may designate only CMMC Level 1 (Self) or Level 2 (Self). They may not designate Level 2 (C3PAO) or Level 3 (DIBCAC), and active solicitations and contracts carrying those requirements are being amended to remove them. Phase 1 remains in effect. DFARS 252.204-7012, -7019, -7020(c), and -7021 all remain in force, as does your annual SPRS affirmation. The 48 CFR acquisition rule was never rescinded, which makes this a policy pause rather than a repeal.
What was actually suspended
The narrow answer: the assessment mechanism, not the standard.
Phase 2 was the point where CMMC Level 2 certification by a certified third-party assessment organization (C3PAO) would have become a condition of award for contracts involving Controlled Unclassified Information. That is what stopped. For existing contracts that already include a C3PAO or DIBCAC requirement, contracting officers will remove it by modification before the next option period or at the next scheduled administrative modification.
DoD also established a CMMC Reform Task Force to run a 60-day review and issued a public request for information, which closed on August 14, 2026.
What none of that touched: the 110 controls in NIST SP 800-171 Revision 2, the requirement to self-assess against them, the requirement to post your score to the Supplier Performance Risk System, or the requirement that a senior official affirm that score every year.
What you still owe, today
This is the part worth being precise about, because the obligations that survived are the ones with the sharpest teeth.
DFARS 252.204-7012. Safeguard covered defense information and report cyber incidents to DoD within 72 hours. In effect since 2017. Untouched.
DFARS 252.204-7019 and 252.204-7020(c). Maintain a current NIST SP 800-171 self-assessment and post the summary score to SPRS. Untouched.
Annual affirmation. A named senior official at your company affirms the accuracy of that score. Untouched.
NIST SP 800-171 Revision 2. The 110 controls remain the measuring stick. Untouched.
Read those together and the shape of the current moment gets clear. The government removed the audit that would have verified your score. It did not remove the score, the affirmation, or the consequences of getting either wrong.
The liability that did not pause
Your SPRS score is a formal representation to the federal government, signed by a person whose name is attached to it. The Department of Justice treats inaccurate cybersecurity representations as False Claims Act exposure through its Civil Cyber-Fraud Initiative, and it has been settling these cases.
The clearest example: a defense contractor submitted an SPRS self-assessment score of 104 out of 110 in January 2021. A third-party gap analysis in July 2022 put the real score at negative 142. The case came from a whistleblower, an employee who resigned after finding the gaps, and it settled for $4.6 million.
No breach occurred. The liability came entirely from the gap between what the company said and what was true.
That risk is unchanged by the Phase 2 suspension. Arguably it is worse now: the C3PAO assessment, whatever else it was, would have forced a lot of optimistic scores into contact with reality on a known schedule. Without it, an inflated score can sit in SPRS for years, accruing affirmations, until a whistleblower or an incident surfaces it.
What the levels were going to require
Worth keeping in view, because the framework itself did not change and the phase-in can restart.
Level 1 (17 controls, self-assessment). For contractors handling only Federal Contract Information. Basic hygiene: access control, antivirus, physical security. Annual self-assessment, score to SPRS.
Level 2 (110 controls). Where most primes and subcontractors handling CUI land. Full NIST 800-171 implementation. Under the paused Phase 2, most of this work would have required C3PAO certification; during the suspension, only the self-assessment path is available.
Level 3 (110+ controls). The most sensitive programs, adding controls from NIST SP 800-172, assessed by DIBCAC. Also paused.
If you were scoped for Level 2, you are still scoped for those 110 controls under DFARS. Only the verification method changed.
What to do with the runway
The suspension bought you time. Here is how to spend it so you are not repeating this exercise under pressure later.
1. Make your SPRS score true
Start here, ahead of everything else. Pull your current score, then check it against your environment as it exists today rather than as it existed when someone last scored it. A gap assessment against NIST 800-171 gives you a defensible score and a Plan of Action and Milestones behind it. If your real score is lower than what is posted, correct it. An accurate low score with a dated POA&M is a far better position than an inflated one your affirming official cannot substantiate.
2. Keep remediating
The controls have not moved. Access control, logging and monitoring, encryption of CUI at rest, incident response: the same gaps that would have failed a C3PAO assessment are the same gaps that make your SPRS score wrong today. Prioritize by the CMMC scoring weights, which still reflect what DoD considers most consequential.
3. Validate that the controls work
Implemented and effective are different claims. Compliance and security overlap without being the same thing, and a penetration test tells you whether your controls hold against someone actually trying. That evidence supports your score today and shortens any future assessment.
4. Keep the evidence package current
Policies, procedures, system security plans, configuration baselines, training records. Evidence decays: a system security plan that describes an environment you migrated off eighteen months ago is worse than none, because it documents a claim you cannot support. Keep it current while there is no deadline pressure.
5. Decide who owns this
Most of the contractors who ended up with a wrong SPRS score did not have anyone whose actual job was to keep it right. If you have no dedicated security leader, a virtual CISO can own the scoring, the POA&M, and the affirmation package without a full-time hire.
How we help defense contractors
We work with organizations across government contracting, healthcare, financial services, education, and utilities, and the CMMC and NIST 800-171 work draws on the same testing and assessment practice as the rest of it. That breadth is useful here: the controls DFARS asks about are the controls we test in other regulated environments every week.
Our approach on this work is straightforward. Establish what your score really is, build a remediation plan you can actually execute, and leave you with an evidence package your affirming official can sign without hedging.
Where this lands
The deadline moved. The obligations did not, and the one with genuine financial consequences, the accuracy of what you affirm in SPRS, never depended on CMMC at all.
Contractors who treat the suspension as permission to stop will find out whether they were right when the Reform Task Force reports. Contractors who use it to true up their score and close real gaps will be fine either way.
Contact us for a NIST 800-171 readiness assessment. We will tell you what your score actually is and what it takes to defend it.