COMMENTARY: On July 13, 2026, the Department of War
suspended CMMC Phase 2 — the requirement that would have forced third-party certification on defense contractors handling Controlled Unclassified Information (CUI), effective Nov. 10, 2026. Phase 1 obligations remain fully in force. No new date has been set for Phase 2.
This is what changed, what didn't, and what it means for contractors currently mid-compliance.
The facts
What was suspended: The mandatory third-party assessment requirement under CMMC Phase 2. Contractors would have needed certification from a Certified Third-Party Assessment Organization (C3PAO) to remain eligible for contracts involving CUI.
What was not suspended: Phase 1 self-assessment requirements. Contractors must still assess their own systems against NIST SP 800-171 Revision 2 and submit scores through the Supplier Performance Risk System (SPRS). DFARS clause 252.204-7012 — the underlying contractual obligation to safeguard covered defense information — remains unchanged and unaffected.
Who announced it: DoD Chief Information Officer Kirsten Davies, in
a memo issued July 13. Her stated rationale: "We are not reducing cybersecurity through this measure. We are reducing the red tape."
The review mechanism: A newly formed CMMC Reform Task Force has 60 days to deliver recommendations. Key dates:
- Aug. 14, 2026 — Deadline for industry responses to DoD's Request for Information on compliance challenges
- Mid-September 2026 (estimated) — Task Force reports findings to CIO Davies
- Nov. 10, 2026 — No longer the operative deadline for Phase 2 implementation
Why the suspension happened
Three factors drove the decision, based on DoD's own public statements and industry reporting:
Cost burden. Industry estimates placed full CMMC Level 2 compliance costs for a small contractor as high as $593,800, once remediation, documentation, and third-party assessment fees were combined. For firms operating on defense-sector margins, that figure was reportedly sufficient to push some out of the Defense Industrial Base entirely.
Assessor capacity. The number of accredited C3PAOs was not sufficient to process the volume of contractors requiring certification ahead of
the Nov. 10 deadline. A hard compliance date paired with insufficient assessment capacity created a structural bottleneck DoD could not resolve through the existing timeline.
Policy alignment. Defense Secretary Pete Hegseth's Acquisition Transformation Strategy prioritizes speed to capability and lower barriers to entry for small and non-traditional contractors. A multi-year, high-cost certification cycle was reportedly assessed as incompatible with that directive.
What this does not mean
The suspension applies specifically to the third-party verification mechanism. It does not suspend, waive, or reduce any contractor's underlying cybersecurity obligation.
Contractors handling CUI remain contractually bound under DFARS 252.204-7012 to safeguard that information, and remain required to maintain a current, accurate NIST SP 800-171 self-assessment score in SPRS. The Defense Contract Management Agency's DIBCAC unit continues to conduct spot-check assessments against self-reported scores, independent of the Phase 2 pause.
Treating this suspension as a general compliance holiday is a misreading of the announcement, and one that carries real exposure for contractors who act on it.
Practical guidance for the interim period
Maintain remediation momentum. Controls implemented for Phase 2 readiness are the same controls that satisfy Phase 1 self-assessment and reduce actual breach risk. Suspending a certification requirement does not reduce the value of the underlying work.
Keep SPRS scores current and accurate. This obligation was not affected by the July 13 announcement. Inaccurate self-reported scores remain subject to DIBCAC review and potential False Claims Act exposure.
Monitor the Reform Task Force timeline. The RFI response window (closing Aug. 14) and the anticipated mid-September report are the two dates most likely to signal what a revised framework will require,
Monitor the Reform Task Force timeline. and on what schedule.
Preserve assessment documentation. Retention requirements tied to prior self-assessments and any completed C3PAO readiness work remain relevant regardless of the Phase 2 pause, and will likely be relevant again once a revised framework is issued.
Bottom line
The certification requirement has been paused. The underlying obligation to protect controlled unclassified information has not. Contractors who treat this as a pause in their own compliance work — rather than a pause in third-party verification — are the ones most likely to be caught unprepared when the Reform Task Force's recommendations take effect.
This summary is based on public statements from DoD officials and contemporaneous industry reporting on the July 13, 2026, announcement. It is provided for informational purposes and does not constitute legal advice. Contractors should consult compliance counsel regarding obligations under their specific contracts.