Skip to main content
Switching IT providers this month?Free onboarding and transition. No long-term contract.See the offer
KaselTech
Back to Blog
ComplianceJuly 31, 2026 · 8 min read

CMMC Phase 2 Is Suspended. Your Obligations Are Not.

Table of Contents

On July 13, 2026, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification program. Phase 2 was the part with teeth: starting November 10, 2026, most contractors handling Controlled Unclassified Information would have needed a passing assessment from a Certified Third-Party Assessor Organization, a C3PAO, before they could be awarded work. That requirement is now on hold, along with all pending and future CMMC implementation milestones, and the entire program is under a 60-day top-to-bottom review.

If you run a small defense contractor, the reaction in the room was probably relief. That is fair. It is also the wrong place to stop, because the memo did not lower the bar. It removed the person who was going to check your work, and left the bar exactly where it was.

Here is what actually changed, what did not, and what we would do with the next sixty days.

Need Help With This?

Our team specializes in helping businesses nationwide with compliance solutions.

Get in Touch