CMMC Phase II Is Suspended. Readiness Isn’t.

14th July 2026 | CMMC CMMC Phase II Is Suspended. Readiness Isn’t.

On July 13, 2026, the Department of War suspended Phase II of the Cybersecurity Maturity Model Certification (CMMC) program. 

The third-party assessments that were set to start appearing in defense contracts from November 10 are on hold. So are the later milestones lined up behind them.

A newly formed CMMC Reform Task Force now has 60 days to review the whole program, gather industry feedback through a public request for information (RFI), and report back with recommendations. 

Why has CMMC Phase II been suspended?

Department leadership pointed squarely at cost

By their own figures, compliance was running as high as $600,000 per company and pushing more than 100,000 small businesses toward the exit from the defense supply chain. 

The Department also cited the need to cut red tape, pointing to Secretary of War Pete Hegseth’s directive to reduce compliance barriers for small and medium-sized businesses.

Asked what comes next, officials would not rule out scrapping CMMC altogether once the review is done.

If you’ve spent the past year racing toward a Certified Third-Party Assessor Organization (C3PAO) audit, this reads like a reprieve. It’s narrower than it looks.

The one thing that’s changed

The Department is halting third-party assessments. Program managers have been told to strip Phase II language out of active solicitations and modify existing defense contracts that already carry it. If your bid or your contract named a C3PAO certification, expect that requirement to come out.

Nothing else moved. CMMC Phase I requirements remain firmly in place. Everything the audit was built to verify still stands.

What’s still in force

Phase I stays exactly where it was. Level 1 and Level 2 self-assessments are still required, and you still post your score to the Supplier Performance Risk System (SPRS).

DFARS 252.204-7012 is still in your contracts, so you’re still obligated to implement the security requirements in NIST SP 800-171, protect controlled unclassified information, and report incidents to DIBNet within 72 hours.

Through the review period, the Department will keep enforcing the 800-171 standard using those self-assessments and select government-led checks.

The annual affirmation is still a legal certification. A senior official still signs it, under penalty of law, affirming that what you claim is genuinely in place. And the Department of Justice is still running its Civil Cyber-Fraud Initiative, using the False Claims Act to pursue contractors who misrepresent their security.

That last point gets sharper under the suspension. Third-party audits were going to catch an inflated score before it did any harm. Take the auditor out of the process and your self-assessment becomes the main thing standing between you and a false-claims case.

An inaccurate SPRS number now sits quietly on file until a breach or a whistleblower brings it into the light.

The cases are already on the books. One contractor paid $4.6 million after reporting a positive SPRS score when the true figure was negative 142. Penalties run to triple the government’s damages plus a charge on every false claim, and whistleblowers keep a share of whatever gets recovered.

What defense manufacturers need to do

Keep going. Anyone treating this as permission to stand down has misread it.

  1. Finish implementing NIST 800-171, and score yourself honestly in SPRS with evidence you can produce on demand
  2. Keep your POA&Ms current and real
  3. Before your affirming official signs the next annual affirmation, make sure the posture on paper matches the posture in the building
  4. Stay on the 72-hour incident clock
  5. If you’re a prime, keep checking your subcontractors. Their weak points become your liability
  6. Keep an eye out for what comes next

Real resilience is about being prepared for the unexpected, and this announcement proves that.

A new recommendation is coming in 60 days, and every signal from the Department this week points to 800-171 staying at the center of it.

Our read: the standard outlasts the wrapper around it. Build to the standard, not to the acronym.

Firms with mature controls will absorb whatever replaces Phase II inside a quarter. The ones that treat the pause as a reason to stop will find themselves starting from behind, with less runway than they had last week.

Audits change, resilience remains

CMMC put a deadline on something that was always worth doing. The deadline is gone for now. The reason behind it is not. 

Adversaries are still targeting the defense supply chain, and a breach still costs contracts, customers, and sometimes the whole business.

Regulations move and deadlines slip. Being ready for the ones you didn’t schedule is the whole point, and it’s what we’ve told clients for years.

A program built specifically for a November date and the audit requirement is being re-planned this week, but if you built to protect the business instead, this change should barely register.

The need for a defensible program remains, and it’s more consequential now that your self-assessment is the only thing between you and a false-claims case.

That work is still worth doing well, and it’s the work we do: build a program that holds up, or validate the one you’ve already built, and stand behind the score you file. A date on a calendar was never what made it worth the investment.

If you want a straight read on whether your program and your score would survive scrutiny, talk it through with us.

Latest Cyber and AI Insights

Improve your readiness, combat disruption

Get the latest cyber and AI insights to help your organization stay compliant, resilient and ready for ever-evolving threats and challenges.

Because while risk is constant, ready is a choice.

The Four-Week Shutdown: What Happens When a Manufacturer Loses Every System

The Four-Week Shutdown: What Happens When a Manufacturer Loses Every System

It's 2 a.m. Ransomware reaches the controllers that run your production line. By first shift, nothing turns on:...

Read more
CMMC Phase II Is Suspended. Readiness Isn’t.

CMMC Phase II Is Suspended. Readiness Isn’t.

On July 13, 2026, the Department of War suspended Phase II of the Cybersecurity Maturity Model Certification...

Read more
How Much Does CMMC Level 2 Actually Cost for a 300-Person Manufacturer?

How Much Does CMMC Level 2 Actually Cost for a 300-Person Manufacturer?

The DoD's own rulemaking estimates that getting through a Level 2 certification assessment costs a mid-sized...

Read more