Contact Us

Breaking: Pentagon Suspends CMMC Phase 2 — What Defense Contractors Must Still Do

On July 13, 2026, the Pentagon announced the immediate suspension of Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program — the third-party certification requirements that were scheduled to take effect November 10, 2026. Phases 3 and 4 are suspended as well, and a newly formed CMMC Reform Task Force will conduct a 60-day review. For the more than 100,000 companies in the defense industrial base, this changes the compliance calendar dramatically. But it does not change the underlying obligation to protect federal data.

What Happened and Why

The department’s stated reason for pulling back is arithmetic. Officials cited data suggesting future CMMC phases could cost small and mid-sized businesses more than $7 billion annually in compliance, against an assessment ecosystem of only around 100 approved assessor organizations serving more than 100,000 companies that would need certification — math that the Pentagon’s chief information officer summarized bluntly as not working for small business. During the review period, the department will rely on self-assessments and select government-led assessments.

GovCon iSource — Your pipeline runs while you run your business.

What Is Still Fully in Force

Phase 1 self-assessments remain in place. Contracts can continue to include CMMC self-assessment requirements, and applicable solicitations still demand a current score in the Supplier Performance Risk System (SPRS).

DFARS 252.204-7012 still applies. Every defense contractor and subcontractor handling covered defense information remains contractually obligated to implement NIST SP 800-171 controls and report cyber incidents. The 110 controls, the System Security Plan, and the Plan of Action and Milestones are all still your responsibility.

False Claims Act exposure may now be the sharper risk. With self-assessment as the primary verification mechanism, the accuracy of your self-reported SPRS score matters more, not less. The DOJ’s Civil Cyber-Fraud Initiative has an established record of pursuing contractors over misrepresented cybersecurity compliance. An inflated score attached to monthly invoices multiplies liability with every billing cycle.

Government-led assessments remain possible. The department explicitly reserved the right to conduct its own assessments during the suspension — and unlike a scheduled C3PAO engagement, those arrive on the government’s timeline, not yours.

Your Five-Step Action Plan

1. Do not dismantle anything. If you have been building toward Level 2 compliance, that investment bought you a defensible security posture and an SPRS score you can stand behind.

2. Verify your SPRS score is honest and evidence-backed. Re-run your NIST 800-171 self-assessment, document the evidence for every control you claim, and keep your POA&M realistic. In the new environment, your self-assessment is the compliance artifact the government relies on — and prosecutes against.

3. Respond to the RFI. The department posted a request for information seeking industry feedback on cost drivers, administrative burdens, and which controls actually reduce risk. This is the small business community’s direct channel to shape what replaces Phase 2.

4. Watch your primes. Prime contractors can still gate subcontract awards on cybersecurity posture regardless of what the Pentagon requires. If defense work sits anywhere in your pipeline, expect flow-down requirements to persist.

The Bottom Line

For small defense contractors, this suspension is genuine relief — the third-party certification bottleneck threatened to lock capable firms out of the market through no fault of their own, and the government acknowledged as much. But the smartest read of July 13 is not “compliance is over.” It is “the audit changed hands.” The standard survives, the contract clauses survive, and the enforcement mechanism shifted from a scheduled commercial assessment to self-certification backed by federal fraud liability. Stay sharp, stay honest in SPRS, and use the next 60 days to get your evidence in order. Brick by brick.

Not sure where you fit? Start with a call. Book Free Call.

Frequently Asked Questions

Is CMMC still required in 2026?

Yes — CMMC Phase 1 remains fully in effect. Contractors must still self-assess against CMMC Levels 1 and 2 and maintain a current score in SPRS where solicitations require it. Only the Phase 2 third-party certification requirement (and later phases) are suspended during the 60-day reform review.

Does DFARS 252.204-7012 still apply after the suspension?

Yes, completely. The DFARS 7012 clause and its NIST SP 800-171 requirements are contract obligations independent of CMMC. Contractors handling covered defense information must still implement the 110 controls, maintain a System Security Plan, and report cyber incidents.

When will CMMC third-party assessments come back?

No date has been set. The CMMC Reform Task Force is conducting a 60-day review and gathering industry input through an RFI. Maintaining your compliance posture through the pause is the smart position regardless of the outcome.

GovCon iSource — Your pipeline runs while you run your business.

References

DefenseScoop. (2026, July 13). DOD halts cybersecurity requirements for CMMC Phase 2. https://defensescoop.com/2026/07/13/dod-halts-cmmc-cybersecurity-requirements-phase-2/

Federal News Network. (2026, July 13). Pentagon suspends CMMC phase two requirements, launches review of program. https://federalnewsnetwork.com/cybersecurity/2026/07/pentagon-suspends-cmmc-phase-two-requirements-launches-review-of-program/

Melanie Patterson

About the Author

Melanie Patterson

Founder & CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale — brick by brick. Contact

Most Read

Federal law protects contractor employees who report waste, fraud, or law violations — and punishes
The Anti-Kickback Act and the FAR gratuities rules criminalize improper payments up and down the

Related

Discover more from Team Integrity Knowledge Center

Subscribe now to keep reading and get access to the full archive.

Continue reading