CMMC Phase 2 Is Suspended: What the July 2026 Pause Means for Defense Contractors
On July 13, 2026, the Department of War suspended CMMC Phase II, effective immediately, pending a review. The certification gate that was driving every countdown is paused. The security obligations underneath it are not. Here is what actually changed, what did not, and what to do while the review runs.
In This Article
If you built a plan around November 10, 2026, this is the update that changes the framing. The date has not been enforced into a certification requirement, because the requirement itself is on hold. But a pause is not a repeal, and reading it as “CMMC is cancelled” is the fastest way to walk into 2027 unprepared.
What Happened on July 13, 2026
In a memorandum dated July 13, 2026, the Department of War suspended CMMC Phase II requirements, effective immediately, pending a review. Reporting from counsel and assessment firms indicates that the third party certification gate for Level 2 has been paused in new solicitations, while the underlying contractual security obligations were not repealed. The Small Business Administration publicly backed the decision the same day.
That is the whole of what is confirmed. The memorandum paused the certification requirement and set a review in motion. It did not roll back DFARS, it did not withdraw NIST SP 800-171, and it did not end self assessment.
What the Suspension Does Not Change
This is the part that gets lost in the headline. The certification gate is one layer. The obligations beneath it are a separate mechanism, and they are still in force:
- DFARS 252.204-7012 still requires adequate security for covered defense information and implementation of NIST SP 800-171. It was not touched by the pause.
- DFARS 252.204-7019 and 7020 still require a current NIST SP 800-171 self assessment posted in SPRS, with the senior official affirmation. That is a different clause from the CMMC certification gate.
- Your SPRS score is still what primes and contracting officers check before they shortlist bidders. A stale or missing score is still a silent disqualifier.
The affirmation obligation is worth dwelling on, because it carries personal exposure that a pause does not remove. We covered that in our post on the CMMC self assessment: the C3PAO may be gone from new solicitations, but the signature is not, and the affirmation now carries False Claims Act exposure for whoever signs it.
Why the SBA Backed the Pause
A cybersecurity agency welcoming a pause in a cybersecurity program only reads as strange until you look at the arithmetic. Roughly 100,000 companies in the defense industrial base needed third party assessments, and there were roughly 100 approved assessors to perform them. That queue was never survivable for a small supplier, and the practical effect was pushing small businesses out of defense work rather than securing them in it.
The pause is a chance to fix that mismatch. It is not a signal that the security bar is going away. Small contractors still need help meeting NIST SP 800-171, and that is exactly what our sponsor Cyber Grants Alliance wrote about in CMMC Is Paused, Small Contractors Still Need Help.
What to Do While the Review Runs
The moves that mattered before the pause are the same moves that matter now, minus the calendar panic. In priority order:
- Do not disband the program. Teams that stood down when the news broke will restart from behind. The obligations did not pause with the certification gate.
- Refresh your SPRS self assessment and affirmation. It costs nothing, takes days, and it is still the number that screens you in or out of a bid.
- Get your scope right. The asset boundary you define serves your SPRS score, your SSP, your DFARS 7012 posture and any future assessment, in that order. Start with our guide to scoping CUI assets versus security protection assets.
- Keep closing the high weight gaps. Access control, multifactor authentication, audit logging and incident response are the controls that matter under any regime, pause or no pause.
None of this is wasted work if Phase II resumes, and none of it is wasted work if it does not, because it is the same work DFARS 7012 already requires. That is the definition of a decision that survives the uncertainty.
Why We Are Not Predicting a Date
You will see plenty of confident timelines about when Phase II comes back and what it looks like. We are not going to add to them. What happens next is not settled, and anyone telling you a firm date is speculating. What we can tell you is what is durable: the security obligations, the SPRS score, and a clean scope. Build on those, and the resumption date stops being the thing your program depends on.
Not Sure Where the Pause Leaves You?
Book a free 30-minute call with Rick and get an honest read on what still applies to your contracts and what to do next, with no sales pitch. We never touch your CUI.
Book a Free Call with RickFrequently Asked Questions
Is CMMC still required after the July 2026 suspension?
The July 13, 2026 memorandum suspended CMMC Phase II requirements, but it did not repeal the underlying obligations. DFARS 252.204-7012 still requires adequate security for covered defense information and implementation of NIST SP 800-171, and DFARS 252.204-7019 and 7020 self assessment and SPRS reporting obligations sit in separate clauses that remain in effect.
What did the July 13, 2026 memorandum actually do?
It suspended CMMC Phase II requirements effective immediately, pending a review. In practice the third party certification gate that Phase 2 introduced has been paused in new solicitations. The Small Business Administration publicly backed the decision the same day.
Does the pause remove the November 10, 2026 date?
The third party certification requirement that was tied to the Phase 2 rollout is paused. What happens next, and whether a firm date returns, is not settled. Anyone giving you a hard date right now is speculating, and we are not going to.
Should we stop our CMMC program?
No. The security obligations under DFARS 252.204-7012 and NIST SP 800-171 remain, SPRS scoring and the annual affirmation remain, and scoping and remediation retain their value in every scenario.
Why did the SBA support pausing a cybersecurity program?
Because the assessment arithmetic was pushing small suppliers out of defense work. Roughly 100,000 companies in the defense industrial base needed third party assessments against roughly 100 approved assessors, a queue that was never survivable for small contractors.
Sources
- CMMC Reform Memorandum, July 13, 2026 (dowcio.war.gov)
- Latham & Watkins, "What Defense Contractors Should Know About DoD Suspension of CMMC Phase 2" (lw.com)
- DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019 and 252.204-7020, NIST SP 800-171 DoD Assessment Requirements
- NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
- Cyber Grants Alliance, "CMMC Is Paused. Small Contractors Still Need Help." (cybergrantsalliance.org)
