On July 13, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program. Phase 2 was set to take effect November 10, 2026. It would have required contractors handling Controlled Unclassified Information (CUI) to get certified by an authorized third-party assessment organization (C3PAO). That deadline is off the table.
But here's the part that matters for your daily compliance work: nothing about Phase 1 changed. If you're subject to Level 1 or Level 2 self-assessment requirements, you still need to meet them. You still need to submit your score to the Supplier Performance Risk System (SPRS). You still need to comply with NIST SP 800-171 Rev 2 under the DFARS clause at 252.204-7012. The annual affirmation requirement is also still in place.
The suspension covers the verification mechanism — the third-party audit — not the underlying security obligation.
The Department created a CMMC Reform Task Force to conduct a 60-day review. The task force reports to the Department of War Chief Information Officer (CIO). Officials are gathering public comments through a Request for Information (RFI) due August 14, 2026 — that's today. The task force will deliver recommendations around mid-September.
Why the pause? Cost concerns played a big role. Small Business Administration data suggests future CMMC phases could cost small to midsize businesses more than $7 billion annually. There's also a severe assessor shortage. More than 100,000 companies need assessments. Fewer than 100 C3PAOs are authorized to conduct them.
What about certificates already issued? The governmentcontractslaw.com analysis notes that already-issued Level 2 certificates still carry weight. They demonstrate a contractor's commitment to cybersecurity. But the reform task force could change how those certificates are recognized going forward.
Contractor beware. Government contracts law firm McCarter & English flags a key risk: your prime contract may still require CMMC compliance regardless of what the Pentagon memo says. Federal contracts have their own flow-down clauses. Read your contract. If it references CMMC, the obligation may still bind you.
The bottom line: keep your compliance program running. The security bar hasn't moved — only the audit deadline did. Use the pause to close open Plan of Action and Milestones (POA&M) items and strengthen your NIST 800-171 controls. The reform task force could bring back third-party assessment in a different form, and you want to be ready when it does.
Accuracy Review — Post 1
- Confirm Phase 1 start date (November 10, 2025) and Phase 2 suspension date (July 13, 2026) against dodcio.defense.gov/cmmc/About
- Verify "100+ companies needing assessments vs. ~100 C3PAOs" figure against governmentcontractslaw.com and/or SBA data
- Confirm RFI due date is August 14, 2026 via SAM.gov workspace listing
- Verify "already-issued Level 2 certificates still carry weight" statement — this is analysis from govcon law blogs, not DoD CIO policy
- Confirm the Department of War naming — the dodcio.defense.gov domain now uses "Department of War" branding