CMMC Phase 2 Suspension: What Actually Changed
On July 13, 2026, the Department of Defense suspended the Phase 2 requirements of the Cybersecurity Maturity Model Certification program, pulling back the mandatory third-party assessment that was set to take effect that November. For contractors who spent the past two years preparing for a C3PAO assessment, the announcement reads like a reprieve. It is not one. The self-assessment obligations, the SPRS reporting, and the underlying cybersecurity requirements that carry the real legal exposure remain exactly where they were on July 12. Contractors who treat this as a pause on compliance, rather than a pause on one specific enforcement mechanism, will be the ones scrambling when the review period ends.
What the CMMC Phase 2 Suspension Actually Changes
CMMC rolled out in four phases. Phase 1, which began November 10, 2025, required Level 1 and Level 2 self-assessments in applicable solicitations, with contracting officers holding discretion to add a third-party requirement. Phase 2 would have made that discretion mandatory: starting November 10, 2026, every solicitation involving Controlled Unclassified Information would have required a Level 2 assessment performed by a CMMC Third-Party Assessment Organization. That is the piece DoD suspended.
Phase 1 Stays. Phase 2 Doesn't. For Now.
Self-assessment requirements under DFARS 252.204-7021 continue without interruption. Contractors handling Federal Contract Information still need Level 1 self-assessments. Contractors handling CUI still need Level 2 self-assessments, posted to the Supplier Performance Risk System, with annual affirmation of continuous compliance. What disappears, at least for now, is the requirement that a subset of those Level 2 contractors also pass an independent audit from a C3PAO before award.
What the Suspension Does Not Touch
The obligations that actually generate legal exposure sit outside the CMMC rule entirely. DFARS 252.204-7012 requires safeguarding of covered defense information and rapid reporting of cyber incidents, and that clause is untouched. The 110 security requirements in NIST SP 800-171 Revision 2 remain the technical baseline contractors must implement regardless of which assessment mechanism verifies them. And the Department of Justice's Civil Cyber-Fraud Initiative, which pursues False Claims Act cases against contractors who misrepresent their cybersecurity posture, was not part of this announcement and was not affected by it.
Why DoD Pulled Back
The suspension did not come out of nowhere. DoD's Chief Information Officer cited Small Business Administration data showing that CMMC compliance costs had reached as much as $600,000 for individual companies, with more than 100,000 small businesses facing some version of that burden. There was also a capacity problem waiting on the other side of November 2026: roughly 100 authorized C3PAOs against a population of contractors that dwarfs what those firms could realistically assess in time.
DoD's CIO and the Undersecretary for Acquisition and Sustainment each issued memoranda establishing a CMMC Reform Task Force, which has 60 days to review the program against Secretary Pete Hegseth's Acquisition Transformation Strategy. That strategy directs the Department to prioritize speed to capability and lower barriers for small and non-traditional businesses, goals that a mandatory third-party audit requirement was working against. Alongside the task force review, DoD opened a public Request for Information asking industry seven direct questions, among them which security controls deliver real risk reduction and which ones just generate paperwork. Responses are due by noon Eastern on August 14, 2026.
Real-World Implications for Contractors
Two things are happening on parallel tracks right now, and business development leaders need to track both. First, DoD has directed requiring activities to amend active solicitations to strip Phase 2 language "as soon as possible," and contracting officers have been told to modify existing contracts before the next option period or scheduled administrative modification. If your active or pending contract carries a C3PAO requirement, expect that language to change, and watch for the modification rather than assuming it already happened.
Second, and this is the part that gets missed: a suspension is not a repeal. The Reform Task Force could recommend anything from a scaled-back third-party requirement to reinstating Phase 2 on a delayed timeline. Contractors who let their self-assessment lapse, stop tracking SPRS scores, or quietly deprioritize POA&M closure because "CMMC is on hold" are making a bet that the underlying framework disappears. Nothing in the July 13 announcement supports that bet. The safeguarding clause, the incident reporting timeline, and the False Claims Act exposure all still apply to a contractor who claims compliance and cannot back it up.
There is a second layer of complication most contractors have not connected yet. The FAR Council's separate proposed rule expanding CUI safeguarding requirements to all federal contracts, not just DoD's, moved forward on its own track in June 2026, with comments closing July 23. If that rule survives in anything close to its current form, a scaled-back CMMC program would not relieve contractors of CUI obligations. It would just move the enforcement mechanism.
Tactical Recommendations
- Keep every self-assessment current and confirm your SPRS score reflects your actual environment, not a snapshot from before the suspension. (Section 3.1)
- Continue closing open POA&M items on the same timeline you would have used under Phase 2. A future reinstatement will not extend deadlines for contractors who paused. (Section 4)
- Monitor active contracts for the contract modification that removes Phase 2 language, rather than assuming your contracting officer has already acted. (Section 4)
- Submit or review industry input to the RFI before the August 14 deadline if your organization has data on assessment costs or control effectiveness worth putting in front of the task force. (Section 3)
- Watch the FAR Council's CUI rule alongside the CMMC review. A narrower CMMC scope paired with a broader FAR CUI requirement changes where the compliance burden lands, not whether it exists.
Contractors who use this window to tighten their documentation, close their POA&Ms, and confirm their SPRS posture will be ready for whatever the task force recommends in September. Contractors who stand down will be relearning the same 110 controls under a compressed timeline, with less runway than they have today. Atlantic Digital's CMMC Strategy Experts track the Reform Task Force output and the FAR CUI rule in parallel, so clients know which requirements are actually moving and which ones only look like they are. For organizations that want a single point of accountability for self-assessment accuracy, POA&M tracking, and SPRS reporting through this review period, Atlantic Digital's vCISO Services provide that oversight without requiring an internal hire.
Contact us today to learn more.
Frequently Asked Questions
Does the CMMC Phase 2 suspension mean the program is going away? No. DoD suspended the requirement for third-party C3PAO assessments under Phase 2. Phase 1 self-assessment requirements, SPRS reporting, and annual affirmations remain fully in effect, and the CMMC Reform Task Force could recommend reinstating some version of Phase 2 after its 60-day review.
Do I still need to post a self-assessment score in SPRS? Yes. Contractors handling CUI must still complete a Level 2 self-assessment and post the score to the Supplier Performance Risk System, with an annual affirmation of continuous compliance. Nothing in the July 13 suspension changes that requirement.
What happens to a CMMC Level 2 (C3PAO) requirement already written into my active contract? DoD has directed requiring activities to amend affected solicitations and modify existing contracts to remove the Phase 2 requirement, prioritizing changes before the next option period or scheduled administrative modification. Confirm the modification with your contracting officer rather than assuming it has already been issued.
When will DoD decide what comes next for CMMC? The CMMC Reform Task Force has 60 days from its formation to complete its review, informed by RFI responses due by noon Eastern on August 14, 2026. A published outcome is expected in the following weeks, though DoD has not committed to a specific reinstatement or reform timeline.