CMMC Phase 2 Is Suspended: What Defense Contractors Should Do Now
On July 13, 2026, the Department of Defense suspended Phase 2 of the CMMC rollout. The memo, signed by DoD Chief Information Officer Kirsten Davies and numbered 26-P-1023, halts the requirement that would have put third-party certification assessments into new solicitations starting November 10, 2026, and it pauses all pending CMMC milestones until further notice. A CMMC Reform Task Force is running a 60-day review of the whole program, with recommendations due in mid-September. Here is what the suspension does not touch: Phase 1 self-assessment requirements remain in force, DFARS 252.204-7012 still contractually requires NIST SP 800-171 implementation, and SPRS scores still carry False Claims Act exposure. The verification schedule moved. The security requirements did not move at all.
What was actually suspended
CMMC's rollout was structured in phases. Phase 1 took effect November 10, 2025: new DoD contracts began requiring Level 1 or Level 2 self-assessment status, posted in the Supplier Performance Risk System with an annual affirmation from a senior company official. Phase 2 was the escalation, scheduled for November 10, 2026, when applicable new solicitations would begin requiring Level 2 certification assessments conducted by a C3PAO, an authorized third-party assessment organization, rather than accepting self-assessment alone.
The July 13 memo suspends that escalation. No new solicitations will carry C3PAO certification requirements while the suspension holds, and the phased milestones that would have followed, including government-led Level 3 assessments, are paused with it. The memo's stated reasoning is blunt for a government document: the current program imposes significant and often prohibitive burdens, compliance costs are severe for smaller companies, and third-party assessment capacity is short. Roughly 80,000 companies would eventually need certification under the program as designed, against an assessor ecosystem that was visibly not scaling to meet them.
What the review is likely to change
The task force's mandate is a top-to-bottom review that prioritizes speed to capability and lowers barriers for small, medium, and non-traditional contractors. That language signals direction without committing to specifics, and reading it alongside the capacity problem suggests a few plausible outcomes. The review could resequence the phases and simply delay the C3PAO requirement. It could narrow the population that needs third-party certification, reserving C3PAO assessments for higher-sensitivity contracts while letting self-assessment cover more of the base. It could restructure the assessment model itself. What it is unlikely to do is weaken the underlying standard, because NIST SP 800-171 is written into DFARS 252.204-7012 independently of CMMC, and nothing in the memo touches that clause.
Contractors should treat mid-September as a checkpoint, not a finish line. A 60-day review produces recommendations, and turning recommendations into rulemaking takes months at minimum. The realistic planning assumption is a period of continued self-assessment enforcement, followed by a revised third-party requirement whose shape becomes clear late in 2026 at the earliest.
When the recommendations land, three details will tell you most of what you need to know: whether the C3PAO requirement survives and for what population of contracts, whether the phase dates reset from the original schedule or restart from the announcement, and whether anything changes about POA&M allowances and conditional status. Read those three first and skip the framing language around them.
What still applies, in full
The suspension changed one future requirement. It changed nothing about the present, and the present already has teeth. DFARS 252.204-7012 has required NIST SP 800-171 implementation since the end of 2017, along with 72-hour incident reporting to DoD and FedRAMP Moderate or equivalent cloud services wherever covered defense information touches them. DFARS 252.204-7019 still requires a current self-assessment score posted in SPRS before award, and 7020 still gives the government the right to show up and assess. Phase 1 of CMMC itself remains fully in force: new contracts continue to require self-assessment status and annual affirmations. Our guide to what CMMC is and how the clauses fit together covers the full structure.
The affirmation is the piece contractors underestimate. A senior official affirming a SPRS score is making a federal representation, and the Department of Justice has already prosecuted the gap between claimed and actual compliance under the False Claims Act, including the $9 million Aerojet Rocketdyne settlement and Penn State's $1.25 million settlement over its attestations. Nothing about the suspension reduces that exposure. If anything, a period of lighter third-party verification raises the weight the government puts on the representations companies make about themselves. An inflated score in SPRS is a standing liability whether or not an assessor ever books a visit. Our SPRS score guide covers how the scoring methodology works and what an honest score looks like.
If you already hold a certification, or were mid-assessment
The memo suspends future solicitation requirements; it does not revoke anything already earned. Companies that completed a C3PAO certification assessment hold a status in SPRS with a three-year term, and that status remains the strongest evidence of readiness a contractor can show a prime, whatever the clauses require this quarter. Companies that were mid-engagement with a C3PAO when the memo landed face a narrower question of contract and scheduling: whether to complete the assessment now, while assessor calendars are open, or pause and hold their place. There is a reasonable argument for completing it. Assessment capacity was the program's tightest constraint before the suspension, the review is explicitly aimed at getting verification moving again in some form, and a certification in hand converts the next rule change from a scramble into a non-event. The cost of the assessment is the same either way; the queue when the requirement returns will not be. Confirm terms with your C3PAO directly, since engagements differ, and keep the paper trail of whatever you decide.
The wrong move is to stop
The tempting read of the suspension is that the deadline pressure is off and the remediation budget can slide a year. That read fails on three facts. First, the requirements are contractual today under 7012, suspension or none. Second, primes are not waiting: contractors report that flow-down requirements, teaming decisions, and supplier scorecards increasingly ask for CMMC readiness evidence ahead of any clause, because a prime's own eligibility depends on its supply chain and primes plan past single memos. Third, the work itself takes 6 to 12 months for most small and mid-sized contractors from a standing start, which means a company that pauses now and restarts when the revised rule lands will be assessed against whatever timeline the rule sets, minus the year it gave back.
There is also a competitive read. Assessment capacity was the program's binding constraint, and it will be the binding constraint again the day a third-party requirement returns in any form. Companies that hold their readiness posture keep their place in that queue. Companies that let controls decay will rediscover that rebuilding operating evidence, logs, reviews, and tickets that assessors sample, takes quarters, because evidence of operation cannot be backdated.
What to do with the pause
Used well, the suspension is schedule relief on the most expensive part of the timeline, the external assessment, without any change to the destination. The sensible sequence looks like this: keep your SPRS score current and honest, and correct it if the last posted number would not survive a DIBCAC look. Close the gaps your last assessment surfaced, in the order that moves your score most. If you have not had an independent look at your environment against all 110 requirements of NIST SP 800-171, get one, because self-graded scores run high with remarkable consistency. The requirements themselves are unchanged, so work completed now counts fully under whatever the task force produces; our Level 2 requirements guide walks the control families in detail.
BD Emerson runs CMMC gap assessments, remediation, SSP development, and mock assessments for defense contractors. We are not a C3PAO and do not certify anyone; a separate authorized assessor performs the certification assessment whenever that requirement returns. That separation is deliberate, and during a suspension it is specifically useful: a readiness firm with no certification revenue at stake has no reason to tell you anything other than where you actually stand. The program is being rewritten. Your contracts are not. Plan against the clauses you have signed, and let the memo change the calendar instead of the work.
