Compliance
CMMC Phase II is suspended. Your signature got heavier.
What the CMMC Phase II suspension actually changes — and the three things it doesn’t.
On 13 July 2026 the Department of War suspended CMMC Phase II. The third-party certification requirement that was going to bite on 10 November is on hold, later implementation milestones are frozen with it, and a reform task force is due to report around mid-September. The Department has not ruled out cancelling the programme outright.
If you run a defense contractor, you have probably already had the conversation where someone asks whether you can stop spending on this.
The honest answer is that the thing you were racing toward moved. Almost nothing else did — and one thing got materially more dangerous.
What actually happened
The suspension was implemented through memorandum 26-P-1023, dated 13 July 2026, signed by the Department’s Chief Information Officer, Kirsten A. Davies, together with an implementing memorandum from the Under Secretary for Acquisition and Sustainment. Its operative language is that all pending and future CMMC implementation milestones across Department solicitations and contracts are “held in abeyance until further notice.”
The reasoning was capacity and cost, and the figures are worth sitting with. The Small Business Administration, welcoming the suspension, put compliance at roughly $593,800 per certification for a small firm requiring third-party assessment, and about $388,600 for a firm eligible to self-assess. Against that: more than 120,000 small businesses in the defense industrial base, and roughly 100 approved assessors to serve them.
The Department’s CIO summarised the arithmetic more bluntly: the math simply doesn’t work for small and medium businesses to get compliant by the transition date.
That is not the language of a programme being quietly killed for being unnecessary. It is the language of one that outran its own delivery capacity.
The three things that did not change
Most of the coverage stops at “Phase II is paused.” That is where the useful part starts.
1. Your safeguarding clauses are untouched. If you handle CUI, DFARS 252.204-7012 still requires you to implement the 110 security controls of NIST SP 800-171, still requires cyber incident reporting, and still requires unaltered flowdown to subcontractors. If you handle FCI, FAR 52.204-21 still sets the basic safeguarding floor. Every other contractual cybersecurity clause remains intact. This is a policy pause, not a regulatory repeal.
2. A CMMC status is still a condition of award. Phase I has been in effect since 10 November 2025 and the suspension did not touch it. During the suspension, contracting officers may still include CMMC Level 1 (Self) or Level 2 (Self) assessment requirements in solicitations and contracts wherever FCI or CUI is anticipated. You still need a current self-assessment score posted in SPRS, plus an annual affirmation of continuous compliance entered by a named senior official.
What changed is not whether a CMMC status gates your award. It is which kind of status can be demanded. The third-party-assessed flavour is suspended. The self-assessed flavour is live, required, and checked.
3. Your prime’s flowdowns are contractual, not regulatory. The memoranda bind Department personnel. They do not rewrite terms you have already signed with a prime. If your subcontract obligates you to a certification posture, that obligation lives in the contract and relief does not automatically flow downhill. Check the paper before you assume it lifted.
The part nobody is putting on a slide
Here is the shift that matters, and it runs opposite to the headlines.
Third-party certification was going to be the mechanism that verified your security posture. With it suspended, the Department will lean on self-assessment and select government-led assessments instead. Which means the artefact carrying the weight is your affirmation — signed by a named individual, entered in SPRS, asserting continuous compliance.
False cybersecurity certifications are the express target of the Department of Justice’s Civil Cyber-Fraud Initiative. That initiative did not pause on 13 July.
So the compliance burden went down and the exposure on your signature went up. An organisation that reads “CMMC is suspended” as licence to let its posture drift, while continuing to affirm continuous compliance annually in SPRS, has not reduced its risk. It has concentrated it onto one named person.
This is also the moment to be certain which obligations are actually yours rather than your provider’s. Security Assessment — the System Security Plan, the POA&M and the affirmation itself — is the row most often assumed to sit with somebody else. Our shared responsibility matrix sets out the usual split across all 14 families.
If you take one thing from this: the pause is on the audit, not on the obligation.
Watch for amendments — and check what level you can even be asked for
Two operational details that have not travelled well in the coverage.
Active solicitations are being amended. Where a requirements package included a CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) requirement, program managers and requiring activities must initiate an amendment removing it and hand the amended requirements document to the contracting officer, who issues the solicitation amendment “as soon as practicable.” If you are mid-bid on something that demanded third-party certification, that requirement is coming out — and the competitive field may widen as a result.
Only two designations remain available. During the suspension, requiring activities may designate CMMC Level 1 (Self) or Level 2 (Self) and nothing else. Level 2 (C3PAO) and Level 3 (DIBCAC) may not be designated at all. If you see either of those in a live requirement, it is out of step with the memorandum.
And no waivers are being granted during the review period — worth knowing if a waiver was part of anyone’s plan.
Already-awarded contracts are being modified too. Contracting officers are directed to issue modifications removing Phase II requirements from existing contracts, before the next option period is exercised or at the next scheduled administrative modification. So if you hold a contract carrying a certification requirement, expect paper.
When it lands, read it rather than file it. It tells you precisely which obligations the Department considers lifted on that specific contract — and note that a modification removing a certification requirement is not one removing your safeguarding requirements. The two will arrive looking similar and mean very different things.
Why unwinding costs more than maintaining
If you have already built a CUI enclave, stood up GCC High, or worked through a gap assessment, the instinct to bank the savings is understandable and wrong on the arithmetic.
A reformed requirement can return within months — the task force is a review, not a repeal, and government-led assessments continue in the interim. Unwinding a CUI enclave and rebuilding it later costs materially more than maintaining one, because you pay the migration twice and lose the operational knowledge in between.
The deficiencies documented in your gap assessment also survive the suspension. They are written down. Remediating them on a defensible timeline is a very different position to be in than shelving the report and being asked later why nothing happened after you knew.
What to do in the next 30 days
-
Comment on the RFI — the window closes 14 August 2026. The Department has asked industry directly about cost drivers, administrative burden, which controls deliver real security uplift, commercial tooling and managed services, and the practical problems with Phase I self-assessment. If any of that has a shape in your business, this is the cheapest opportunity you will get to describe it to the people writing the replacement. Submissions are electronic only.
-
Verify your SPRS status is current. Not your plan to update it — the actual record a contracting officer will pull. This is the requirement that can cost you an award this quarter.
-
Re-read your prime flowdowns, specifically for certification-posture obligations that survive independently of the Department’s schedule.
-
Keep remediating, on a defensible timeline. Slow down if the business case demands it. Document why. Do not stop and do not dismantle.
-
Confirm who your affirming official is, and that they understand what they are signing now that it carries more weight than it did in June.
What to watch for in mid-September
The task force reports within 60 days of 13 July, drawing on the RFI responses. Expect one of three outcomes: a rescoped CMMC with a longer runway and more assessor capacity, a tiered model reducing what smaller contractors must certify, or — the Department has explicitly not ruled it out — cancellation in favour of a different mechanism.
In all three, NIST SP 800-171 and DFARS 252.204-7012 remain the floor. That is why the maintain-don’t-dismantle position holds regardless of how the review lands: every plausible outcome still requires the security controls. Only the verification mechanism is genuinely in question.
Cloud Kings runs managed IT, cyber security, and cloud for businesses nationwide, and builds CMMC Level 2-ready GCC High and Azure Government environments for the defense supply chain.
If the suspension has left you unsure what your actual obligations are this quarter, we offer a free CMMC gap assessment for qualifying contractors. Schedule a call and we will work out where you genuinely stand against the 110 controls — including which of them are yours rather than ours.
This reflects the regulatory position as of 4 August 2026 and will change when the task force reports. Last reviewed 4 August 2026. This is not legal advice.
Frequently asked
- Is CMMC cancelled?
- No. Phase II is suspended and later milestones are frozen pending a review. Phase I remains fully in effect. The Department has said it has not ruled out cancelling the programme, but no such decision has been made.
- Do I still need a CMMC status in SPRS?
- Yes. Phase I self-assessment requirements are unchanged. Contracting officers may still include CMMC Level 1 (Self) and Level 2 (Self) requirements in contracts where FCI or CUI is anticipated, and you still owe an annual affirmation of continuous compliance.
- Do I still need to meet NIST SP 800-171?
- Yes. DFARS 252.204-7012 was not affected by the suspension. The 110 controls, incident reporting, and unaltered flowdown to subcontractors all continue to apply.
- What about FCI rather than CUI?
- FAR 52.204-21's basic safeguarding requirements are unaffected.
- My prime says the requirement is lifted. Is it?
- Check the subcontract. The memoranda bind Department personnel; they do not amend commercial terms you have already agreed. Contractual obligations do not automatically track the Department's schedule.
- Will my active solicitations change?
- Yes, where they carried a Level 2 (C3PAO) or Level 3 (DIBCAC) requirement. Requiring activities must initiate amendments removing it, and contracting officers issue those amendments as soon as practicable.
- Will my already-awarded contracts change?
- Yes. Contracting officers are directed to modify existing contracts to remove Phase II requirements, before the next option exercise or at the next administrative modification. When the modification arrives, read it carefully: removing a certification requirement is not the same as removing a safeguarding one.
- Can I still be asked for a Level 2 (C3PAO) assessment?
- No. During the suspension only CMMC Level 1 (Self) and Level 2 (Self) may be designated. No waivers are being granted during the review period either.
- Should we pause our GCC High migration?
- That is a business decision, but the arithmetic usually says no. Every likely outcome of the review still requires NIST SP 800-171 controls, and unwinding then rebuilding an enclave costs more than maintaining one.
- When will we know more?
- The CMMC Reform Task Force reports within 60 days of 13 July 2026 — around mid-September.
Continue reading
-
The CMMC controls nobody owns
Most contractors don't fail on the controls they got wrong. They fail on the ones both parties assumed the other had. Free matrix template inside.
-
How to choose a CMMC partner
The questions that actually produce different answers from different providers — plus the ones every provider passes, and the red flags worth walking away from.