Skip to main content
KaselTech Founding Client RatesPreferred project pricing. Monthly rates guaranteed for 6 months.Explore rates
KaselTech
Back to Blog
Compliance

CMMC Phase 2 Is Suspended. Your Obligations Are Not.

By KaselTech Team · July 31, 2026 · 8 min read

In this guide
  1. What Was Actually Suspended
  2. What You Still Owe, Today
  3. Why It Happened: The Math Did Not Math
  4. The Part Nobody Is Enjoying: Your Legal Exposure Just Went Up
  5. If You Have a C3PAO Assessment Booked
  6. You Have Until August 14 to Say Something
  7. What We Would Do With the Next Sixty Days

On July 13, 2026, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification program. Phase 2 was the part with teeth: starting November 10, 2026, most contractors handling Controlled Unclassified Information would have needed a passing assessment from a Certified Third-Party Assessor Organization, a C3PAO, before they could be awarded work. That requirement is now on hold, along with all pending and future CMMC implementation milestones, and the entire program is under a 60-day top-to-bottom review.

If you run a small defense contractor, the reaction in the room was probably relief. That is fair. It is also the wrong place to stop, because the memo did not lower the bar. It removed the person who was going to check your work, and left the bar exactly where it was.

Here is what actually changed, what did not, and what we would do with the next sixty days.

What Was Actually Suspended

Two memos came out on July 13, signed under DoW Chief Information Officer Kirsten Davies. The first, "Removing Barriers to Defense Industrial Base Expansion," suspended Phase 2 and stood up a CMMC Reform Task Force. The second told contracting officers what to do about it. A follow-up the next day directed that active solicitations carrying Level 2 C3PAO or Level 3 assessment requirements be amended to strip them out "as soon as practicable," and that existing contracts be modified before the next option period or at the next scheduled administrative modification.

So: the third-party certification gate is suspended. Phase 1 is not. Nothing else is.

What You Still Owe, Today

Every one of these survived the memo untouched:

DFARS 252.204-7012. Safeguard covered defense information, and report a cyber incident to DoD within 72 hours. This clause has been in your contracts for years and it is still there.

FAR 52.204-21. Basic safeguarding of Federal Contract Information. Applies to nearly everyone.

NIST SP 800-171 Revision 2, all 110 controls. The suspension changed who verifies your implementation. It did not change what you are required to implement. DoW was explicit that it will continue enforcing compliance through self-assessment and select government-led assessments during the review.

Your SPRS score. You still post and maintain a self-assessment score in the Supplier Performance Risk System.

Your annual affirmation. A senior official at your company still signs an annual statement to the federal government that you are compliant.

Phase 1 CMMC. Level 1 and Level 2 self-assessments and attestations remain in solicitations and contracts where the government expects you to handle FCI or CUI. Program managers also retain discretion to require assessments.

Read that list again. If you were going to be ready for a C3PAO in November, you were going to be doing all of this anyway. The suspension removes an appointment. It does not remove the homework.

Why It Happened: The Math Did Not Math

The department did not hide the reason. There are roughly 100 authorized C3PAOs and well over 100,000 companies in the defense industrial base. Wait times for an assessment slot were projected to pass eighteen months. Small Business Administration data put the compliance cost to small and mid-sized firms above $7 billion a year, and a GAO report warned the standard was too hard and too expensive for smaller firms to reach in time.

Davies put it plainly: "The math just simply doesn't math for small to medium-sized businesses to even get compliant by the transition date." The stated goal of the pause is keeping companies in the defense industrial base that would otherwise have been pushed out of it. Under Secretary Michael Duffey was equally direct that this is not a security rollback: "We are not reducing cybersecurity through this measure. We are reducing the red tape."

That framing matters, because it tells you what the department thinks it bought. Not lower requirements. Fewer gatekeepers.

If You Have a C3PAO Assessment Booked

Do not cancel it reflexively. Think about three things.

Your existing contract clauses remain binding until a contracting officer actually issues the modification. Nobody has published a timeline for those mods. Until the paper changes, the requirement in your contract is the requirement.

A completed third-party assessment is the best evidence you will ever have that your certifications were made in good faith. In a False Claims Act posture, that is worth real money.

And the program may come back. Officials have not ruled out cancelling CMMC outright, but the far more likely outcome of a reform review is a modified framework rather than nothing at all. Preserving your ability to resume costs you very little compared to restarting cold.

If the assessment is a genuine cash-flow problem this quarter, defer it. If it is affordable and you are close, finishing it buys you a differentiator at a moment when most of your competitors just took their foot off the gas.

You Have Until August 14 to Say Something

The Reform Task Force issued a Request for Information. Responses are due by 12:00 p.m. Eastern on August 14, 2026, by email. DoW asked for input on seven areas, including which controls drive the most cost, which deliver the least security for the burden they impose, what commercial security solutions the department could accept in place of bespoke ones, and what would streamline self-assessment for small and non-traditional businesses.

The task force report is due within sixty days of July 13, which puts it around mid-September. Whatever replaces Phase 2 will be shaped by what gets submitted over the next two weeks. If you are a small contractor who has spent the last two years and a real amount of money on this, you have standing to be heard and a narrow window to use it. Most firms will not bother. That is exactly why yours should.

What We Would Do With the Next Sixty Days

Do not stand down. The single worst outcome here is a company that shelves its compliance work in August and gets caught flat when a modified framework lands with a short runway. You have been handed schedule relief, not a cancellation.

Make your SPRS score true. Reassess honestly against all 110 controls. If the real number is lower than what is posted, fix the posting. This is the highest-return hour you will spend this year.

Finish the System Security Plan and the POA&M. These are required now, they were required before, and they are the backbone of any framework that comes next.

Close the cheap gaps. Multi-factor authentication, logging and retention, encryption of CUI at rest and in transit, media handling, and access reviews. Most of it is configuration in a tenant you are already paying for, not new spend.

Write the RFI response. Two pages of specifics from an actual small business beats a hundred pages of association boilerplate.

Put a calendar reminder on mid-September. When the task force reports, re-plan against whatever it says. Do not wait for a solicitation to tell you.

The companies that will come out of this ahead are the ones that treat the suspension as breathing room to get genuinely secure, instead of permission to stop. The requirements did not go away. The deadline did.

KaselTech is a San Antonio firm that does NIST SP 800-171 gap assessments, SPRS scoring, System Security Plans and POA&Ms, and the Microsoft 365 and Entra configuration work underneath them, for defense contractors who do not have a compliance department. Get a straight answer on where you actually stand before you decide what to do with the next sixty days.

Need Help With This?

Our team specializes in helping businesses nationwide with compliance solutions.

Get in Touch