CMMC Phase II Is Suspended: What the Pentagon Pause Means for Small Defense Contractors

On July 13, 2026, the Department of War suspended the CMMC Phase II requirement that would have forced third-party cybersecurity audits starting this November. It is a pause, not a repeal, and a 60 day review is now underway. Here is what changed, what has not, and what to do before the next contract modification lands.

Category: GovCon News · 9 min read · Published 2026-07-13

Key takeaways

  • The Department of War suspended CMMC Phase II on July 13, 2026, effective immediately and until further notice, along with all pending and future CMMC implementation milestones.
  • This is a pause, not a repeal. Phase I self-assessment requirements remain fully in force.
  • DFARS 252.204-7012, the 110 NIST SP 800-171 controls, rapid cyber incident reporting, and annual SPRS affirmations all remain mandatory.
  • A CMMC Reform Task Force under the DoD CIO has 60 days to recommend a replacement framework, and a related Request for Information closes at 12 p.m. Eastern on August 14, 2026.
  • SBA figures cited alongside the announcement put individual certification costs at approaching 600,000 dollars per company, across more than 100,000 small businesses.
  • Contracting officers were directed to amend active solicitations to remove Phase II requirements and to modify existing contracts before the next option exercise.

On July 13, 2026, the Department of War announced the immediate suspension of CMMC Phase II, the requirement that would have forced tens of thousands of defense contractors to pass a third-party cybersecurity assessment starting November 10, 2026. If your company has spent the past year racing toward that deadline, the race just changed shape. It did not end.

The announcement came in a memo signed by DoD Chief Information Officer Kirsten Davies, alongside a companion memo from Under Secretary of War for Acquisition and Sustainment Michael Duffey. Both memos suspend the transition to Phase II, along with all pending and future CMMC implementation milestones, effective immediately and until further notice. At the same time, the Department opened a formal Request for Information asking industry to help redesign the program.

What Actually Got Suspended

CMMC, the Cybersecurity Maturity Model Certification program, protects Controlled Unclassified Information and Federal Contract Information handled by defense contractors. It rolled out in phases. Phase I took effect November 10, 2025, and requires contractors handling FCI or CUI to complete a self-assessment against the relevant NIST SP 800-171 controls and post the score to the Supplier Performance Risk System. Phase II was scheduled for November 10, 2026, and would have replaced self-assessment with a mandatory third-party audit, a Level 2 certification performed by a Certified Third-Party Assessment Organization, for any contract requiring protection of CUI.

That is the piece the Department paused. Phase I self-assessment requirements remain fully in force. The Department can still choose to include a C3PAO requirement in a given solicitation at its discretion, but it is no longer required to phase that in across the board starting in November. Contracting officers have been directed to amend active solicitations to remove Phase II requirements as soon as possible, and to modify existing contracts to remove them before the next option exercise or scheduled administrative modification.

Why the Pentagon Pulled Back

The memo from CIO Davies is blunt about the reasoning. It states that the current CMMC program, while intended to enhance security, imposes prohibitive burdens on the Defense Industrial Base, particularly on small and non-traditional businesses. Davies wrote that the combination of high compliance costs, a shortage of accredited C3PAO assessment capacity, and complex regulatory timelines was actively forcing innovative new entrants and small businesses to opt out of DoD contracts, freezing suppliers out of the market the Department needs to expand.

The Small Business Administration backed the move publicly. SBA Administrator Kelly Loeffler said the agency had heard directly from small businesses that CMMC compliance had become an untenable barrier, and SBA figures cited alongside the announcement put individual certification costs at approaching 600,000 dollars per company, with the broader compliance burden reaching more than 100,000 small businesses across the defense supply chain. The suspension is framed as an extension of Secretary of War Pete Hegseth's Acquisition Transformation Strategy, which prioritizes speed to capability and lower barriers to entry for small and non-traditional contractors over what the Department now describes as a bureaucratic compliance checklist.

What Has Not Changed

This is a pause, not a repeal, and the distinction matters for anyone deciding what to do next. Every substantive cybersecurity obligation that exists outside the CMMC certification process is untouched. Contractors must still safeguard CUI and FCI under DFARS clause 252.204-7012, still must implement the 110 security controls in NIST SP 800-171, still must report cyber incidents rapidly, and still must complete self-assessments and submit annual affirmations of continuous compliance to SPRS. The Department of Justice's Civil Cyber-Fraud Initiative, which pursues False Claims Act cases against contractors who misrepresent their compliance status, is also unaffected. If your company certified a compliance posture it did not actually have, this pause does not change your exposure.

It is also worth naming what this is not. It is not a cancellation of CMMC 2.0 or the underlying requirement that CUI-handling contractors eventually reach Level 2. The Department has not ruled out ending the program entirely once its review concludes, but it has also not committed to that outcome. Law firms tracking the rollout describe it accurately as paused, not canceled, and caution that CMMC 2.0 is still very much on the table depending on what the review recommends.

The 60 Day Review and the RFI

The suspension memo establishes a CMMC Reform Task Force under the DoD CIO, tasked with a top to bottom review of the program over the next 60 days. The task force is directed to recommend a framework that prioritizes speed to capability, lowers barriers for small, medium, and non-traditional businesses, and replaces the current third-party assessment model with what the Department calls scalable, realistic security measures.

Alongside the task force, the Department published a formal Request for Information titled Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base. It poses seven questions to industry covering the specific cost drivers and administrative burdens tied to CMMC and NIST SP 800-171 compliance, which security controls contractors believe actually reduce risk versus which ones create cost without meaningful security benefit, how commercial cybersecurity platforms and services might be recognized within a federal framework, how Phase I self-assessments could be streamlined, and what policy changes would most reduce barriers to entry. Responses must be submitted by email and are due by 12 p.m. Eastern time on Friday, August 14, 2026.

This RFI is a genuine opportunity, not a formality. The Department is actively looking for data on which controls are worth keeping and which ones should go, and small businesses that have lived through CMMC preparation have exactly the cost and burden data the task force says it wants.

What This Means If You Were Racing Toward November

If your company had a C3PAO assessment scheduled or was mid-remediation against the 110 NIST 800-171 controls, do not treat this as a green light to stop. Every control you were implementing to reach Level 2 compliance is the same set of controls required for your Phase I self-assessment and your SPRS score, and those obligations have not moved. What has changed is the hard deadline forcing a third-party audit specifically. Given that the Department has not ruled out reinstating a C3PAO requirement in some form after its review, and given that prime contractors may still choose to require certification from their subcontractors regardless of what DoD mandates directly, walking away from work already in progress risks having to restart it later under a compressed timeline again.

If you are a subcontractor whose prime had set an internal CMMC deadline ahead of the government's November date, check with that prime directly. Some primes built their own supply chain requirements independent of the federal timeline, and those may or may not change based on this pause.

A Complication Worth Watching

The CMMC pause is not the only cybersecurity rule in motion this summer. On June 23, 2026, the FAR Council published a proposed rule as part of the broader Revolutionary FAR Overhaul that would extend similar CUI safeguarding and incident reporting requirements to CUI handled under any federal contract, not just DoD contracts, with comments due July 23, 2026. If that rule advances largely as drafted, a scaled back CMMC program may not reduce your total compliance burden as much as it first appears, since a government-wide FAR requirement could impose comparable obligations regardless of what happens to CMMC specifically.

What to Do Right Now

Keep implementing the NIST SP 800-171 controls you have already started remediating, and keep your SPRS score current. Self-assessment and annual affirmation are still mandatory, and a strong score remains a competitive differentiator even without a C3PAO requirement forcing the issue.

Check your active DoD contracts and pending solicitations for CMMC Phase II or Level 2 C3PAO language, and expect modifications removing that language to arrive before your next option exercise. If a modification has not arrived and your contract still references a hard C3PAO deadline, raise it with your contracting officer rather than assuming it will be handled automatically.

If you are a subcontractor, confirm directly with your prime contractor whether their internal certification deadline is tied to the federal timeline or set independently, since this pause does not automatically change a prime's own supply chain requirements.

Consider responding to the RFI before the August 14, 2026 deadline. If your company has real data on what CMMC compliance actually cost in dollars, staff time, or lost opportunities, that is precisely the evidence the task force is soliciting, and small business input has already been credited with shaping this decision.

Do not let your compliance posture lapse. DFARS 252.204-7012, incident reporting obligations, and False Claims Act exposure for misrepresented compliance are all still fully enforceable, pause or no pause.

How ProposalApp Helps You Track This

CMMC requirements show up buried in solicitation language, contract clauses, and modifications, which makes them easy to miss when a program is in flux like this one. When you upload a solicitation or an active contract into ProposalApp, the Proposal Assistant reads the document and flags references to CMMC, DFARS 252.204-7021, or Controlled Unclassified Information, so you can see whether a specific opportunity still carries Phase II language that has not yet been updated, or whether a modification has quietly removed it.

ProposalApp's capability profile tools also help you document your current NIST SP 800-171 posture and SPRS score as part of your standard proposal content, so your cybersecurity compliance narrative stays current and consistent across every bid, whether or not a C3PAO requirement applies. Use the Find Opportunities page to search "CMMC," "DFARS 252.204-7021," or "C3PAO" across your active pipeline to see exactly which pursuits reference the paused requirement today.

Sources

- [Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements | U.S. Department of War](https://www.war.gov/News/Releases/Release/Article/4542329/forging-the-arsenal-of-freedom-department-of-war-suspends-cmmc-phase-ii-require/)
- [Pentagon suspends CMMC phase two requirements, launches review of program | Federal News Network](https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/)
- [DOD Pauses CMMC 2.0 Implementation: A Big Deal with Little Immediate Impact | Wiley](https://www.wiley.law/alert-DOD-Pauses-CMMC-2-0-Implementation-A-Big-Deal-with-Little-Immediate-Impact)
- [SBA Commends U.S. Department of War's Suspension of CMMC Phase II for Small Defense Contractors | U.S. Small Business Administration](https://www.sba.gov/article/2026/07/13/sba-commends-us-department-wars-suspension-cmmc-phase-ii-small-defense-contractors)
- [DoW Hits Pause on CMMC: What Contractors Need to Know Now | Sheppard](https://www.sheppard.com/insights/blogs/dow-hits-pause-on-cmmc-what-contractors-need-to-know-now)

Frequently asked questions

Is CMMC canceled?

No. CMMC Phase II is suspended, not repealed. The Department has not ruled out ending the program once its review concludes, but it has also not committed to that outcome. The underlying requirement that contractors handling CUI eventually reach Level 2 has not been withdrawn.

What exactly was suspended on July 13, 2026?

The transition to Phase II, scheduled for November 10, 2026, which would have replaced self-assessment with a mandatory third-party Level 2 certification performed by a Certified Third-Party Assessment Organization for any contract requiring protection of CUI. All pending and future CMMC implementation milestones were suspended alongside it.

Do I still need to comply with NIST SP 800-171?

Yes. Every cybersecurity obligation outside the CMMC certification process is untouched. Contractors must still safeguard CUI and FCI under DFARS 252.204-7012, implement the 110 security controls in NIST SP 800-171, report cyber incidents rapidly, and submit self-assessments and annual affirmations of continuous compliance to SPRS.

Why did the Pentagon suspend CMMC Phase II?

The memo from DoD CIO Kirsten Davies states the program imposed prohibitive burdens on the Defense Industrial Base, particularly small and non-traditional businesses. It cites high compliance costs, a shortage of accredited C3PAO assessment capacity, and complex regulatory timelines that were forcing innovative new entrants and small businesses to opt out of DoD contracts.

When is the CMMC reform RFI response due?

Responses to the RFI, titled Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base, must be submitted by email by 12 p.m. Eastern time on Friday, August 14, 2026. It poses seven questions covering cost drivers, which controls actually reduce risk, and how commercial cybersecurity platforms might be recognized in a federal framework.

Does the suspension reduce False Claims Act exposure?

No. The Department of Justice's Civil Cyber-Fraud Initiative, which pursues False Claims Act cases against contractors who misrepresent their compliance status, is unaffected. A company that certified a compliance posture it did not actually have has the same exposure it had before the pause.

🤖 /llms.txt