Editor's note: This post builds on our July coverage of the CMMC Phase 2 suspension. The accuracy of the reform timeline and cost figures should be verified against dodcio.defense.gov/CMMC before publication.
The RFI window closed on August 14. The Department of Defense's reform task force is now in its 60-day review period. And for every federal contractor — large or small — the question isn't whether CMMC is coming back. It's what it will look like when it does.
Where things stand
On July 13, the DoD suspended CMMC Phase 2 rulemaking. That was the headline. But the suspension wasn't a pause on all CMMC activity. Phase 1 self-assessments remain in force. Contractors who need to maintain their current certification levels still need to stay current. The suspension only stopped the rulemaking process for Phase 2.
The reform task force — created in response to pushback from industry, Congress, and the Small Business Administration — is now developing recommendations. They have 60 days from the start of their review to produce a report. The RFI that closed August 14 was their primary mechanism for gathering input from contractors, assessors, and industry groups.
The structural problem nobody solved
CMMC's biggest operational challenge was never about the security standards. It was about capacity. As of the suspension, there were roughly 100 certified assessors (C3PAOs) available to conduct audits. The pool of companies needing certification was estimated at over 100,000.
That's not a bottleneck. That's a blockade.
The SBA, in its comments on the rule, flagged a cost burden of $7 billion or more per year for small and midsize businesses. When the cost of compliance for a small contractor starts approaching the value of the contracts they're bidding on, the system breaks. The reform task force was created to fix that break.
What's on the table
The key question the task force is wrestling with: Can self-attestation replace third-party certification for some tiers of contractors?
The risk, from DoD's perspective, is that self-attestation without verification creates a paper-compliance problem — companies check boxes without actually implementing the controls. The benefit is that it dramatically expands assessment capacity overnight. Every company can self-attest. Very few can get a C3PAO audit in a reasonable timeframe.
The outcome is genuinely uncertain. The industry lobby is pushing hard for self-attestation with random audits (the IRS model). DoD's security hawks want to preserve third-party assessment but find a way to scale it. The reform report will tell us which direction the department is leaning.
What contractors should do right now
Two things are true at the same time: the current rulemaking is paused, and Phase 1 requirements are still in effect. The safest path is to treat the suspension as a window, not a vacation.
- Keep your current assessments current. Nothing in the suspension changes your existing obligations.
- Prepare for either outcome. If the reform produces a simpler, cheaper path, you want to be ready to take it. If it preserves the current structure, you don't want to have lost ground during the pause.
- Watch the 60-day clock. The reform report is the next major milestone. Plan to review it within 48 hours of release and adjust your compliance posture accordingly.
Here's what you can do this week
Check your current CMMC assessment status. If you're due for renewal within the next six months, start the process now — the assessor shortage hasn't improved. Waiting for the reform report is tempting, but the timeline is tight enough that delay could mean losing your certification window.
Direct, practitioner-level, no hedging — TCB GovCon voice. All time-sensitive claims flagged for verification.