On July 13, 2026, the Department of War — the Pentagon — announced an immediate suspension of the transition to Phase II of the Cybersecurity Maturity Model Certification (CMMC), along with a 60-day, top-to-bottom review of the program.

If you sell to the defense market, you have probably already seen the headlines, and maybe a few confident predictions about what it means. Here is the calm version: less changed than the headlines suggest, and the parts that changed are the parts that were still in the future. The obligations you already carry are still on the books.

Here is what was actually suspended, what still applies, and what to do about it.

What was suspended

Phase II was the stage that would have made a third-party assessment your gate to the contract. Starting November 10, 2026, applicable contracts involving Controlled Unclassified Information (CUI) would have required certification at CMMC Level 2 by a C3PAO — a Certified Third-Party Assessment Organization — as a condition of award. No certificate, no contract.

That is the piece that is now paused. The Department of War is running a 60-day review of the whole program, with industry responses to a Request for Information due August 14, 2026. The stated reason is cost and capacity: the department and the Small Business Administration heard, repeatedly, that the framework as designed put a heavy, expensive burden on exactly the small businesses the defense industrial base depends on — more than 120,000 of them potentially in scope, served by roughly 100 approved assessors. The math did not work, so the mandatory-certification gate is on hold while they rethink it.

What did not change

This is the part that gets lost in the noise, and it is the part that matters most:

  • Phase I is still in effect. The self-assessment requirements that took effect in late 2025 — where you assess your own environment against the standard and report it — remain in force. They were not suspended.
  • NIST SP 800-171 still applies. If your contracts carry DFARS clause 252.204-7012, the requirement to implement the 800-171 security controls has been law for years. That did not move.
  • Your SPRS score is still a legal representation. The score you submit to the government about your own security posture is something you are attesting to. It was true before July 13, and it needs to be true now.
  • The duty to protect CUI never went anywhere. The government paused one mechanism for verifying that you protect controlled information. It did not pause the obligation to actually protect it — or the consequences (including False Claims Act exposure) if you say you do and you don't.

In plain terms: the government suspended the audit at the door. It did not suspend the requirements inside the building.

Should you stop your readiness work?

No — and if anything the suspension is a reason to get the quiet, unglamorous work done while the pressure is off.

A few reasons this is the wrong moment to coast:

  1. Certification is being reworked, not retired. A 60-day review is a redesign, not a repeal. The most likely outcome is a version of third-party assessment that is less costly and better staffed — which means the gate comes back, and the organizations that kept working are the ones that walk through it easily.
  2. The obligations that remain are the hard part anyway. Implementing 800-171, writing a defensible System Security Plan (SSP), building real evidence, and keeping your SPRS score honest is the bulk of the work. A certificate is just someone confirming you did it. Do the work now and the eventual assessment — self or third-party — is a formality instead of a fire drill.
  3. Primes are not waiting for the DoW. Flow-down happens by contract. A prime that handles CUI can — and many will — keep requiring their subcontractors to meet 800-171 and show evidence, mandate or no mandate, because the prime is still on the hook for the data.
  4. Security drift doesn't observe policy timelines. The gap between "assessed" and "actual" opens the day after any point-in-time review. Suspension or not, an environment that drifts out of compliance is an environment that is less secure — and, if you've attested otherwise, out over its skis legally.

What to do now, by situation

If you only handle Federal Contract Information (FCI) — roughly Level 1 territory. Keep your basic safeguarding practices in place and your self-assessment current. Nothing about the July 13 announcement lowers that bar. This is a good window to make sure your Level 1 hygiene is genuinely done, not just claimed.

If you handle CUI — Level 2 territory. This is where the suspension changes your timeline but not your destination. Keep implementing 800-171. Keep your SSP and Plan of Action & Milestones (POA&M) real and current. Keep your SPRS score honest. Treat the review period as breathing room to close gaps deliberately rather than a reprieve from having them.

If you're a prime. Decide — on purpose — what you will require of your subcontractors during the review period, and tell them clearly. The data-protection obligation still rolls downhill to you; ambiguity now becomes risk later.

If you were mid-assessment or about to book one. Don't throw away the progress. A readiness posture you can prove is an asset regardless of which verification mechanism the department lands on.

What's still uncertain

We won't pretend to know the outcome. The open questions are real: what the redesigned assessment model looks like, whether the Level 2 threshold or scoping changes, how quickly a revised rule appears after the 60-day review, and what happens to contracts that already contain CMMC language. We're watching the RFI responses and the review, and we'll update this page as the picture firms up.

What isn't uncertain is the through-line: protect the data, document it, and keep it true. That was the point before CMMC, it's the point during the pause, and it will be the point when the next version arrives.


If you want a straight answer about where you actually stand against these requirements — and what it would take to close the gap — that's exactly the conversation our CMMC & compliance readiness work is built for. We've sat on the assessor's side of the table, so we can tell you what holds up and what doesn't.

Last reviewed: July 19, 2026.

Sources: Department of War release, July 13, 2026; Federal News Network; U.S. Small Business Administration; Breaking Defense.