Published August 28, 2026 | TIKC NewsWire
On July 13, 2026, the Department of Defense made an announcement that sent shockwaves through the Defense Industrial Base: the immediate suspension of CMMC Phase II requirements, which had been scheduled to take effect November 10, 2026. The Department’s Chief Information Officer cited a critical assessment bottleneck — more than 100,000 companies needing assessment against roughly 100 authorized C3PAOs — as structurally incompatible with the need to rapidly expand the DIB. The SBA put a number on the burden: total compliance costs can reach approximately $593,800 per CMMC certification for small firms requiring third-party assessment, and about $388,600 for firms eligible for self-assessment. If implemented on its planned launch date, CMMC Phase II would have required more than 120,000 DIB small businesses to seek compliance through a cost-prohibitive system. The suspension was immediate, sweeping, and — for the 100,000+ companies that had been preparing — confusing. Here is what it actually means and what you must do right now.
What the Suspension Actually Suspends
CMMC Level 2 C3PAO and Level 3 DIBCAC third-party assessment requirements are suspended, and active solicitations and contracts must be amended to remove those designations during the suspension period. Phase III (November 2027), Phase IV (full implementation 2028), and all future implementation milestones are frozen until further notice. The CMMC program rule itself has not been repealed, and the DFARS has not been amended — this is a policy pause, not a regulatory change. The Cyber Accreditation Body was not notified before the announcement. The reform process is underway.
What the Suspension Does NOT Suspend
This is the part that matters most — and the part most contractors have gotten wrong. Phase I self-assessments remain mandatory and fully enforceable. Defense contractors must continue implementing NIST SP 800-171 Revision 2 and maintaining accurate scores in the Supplier Performance Risk System (SPRS) or risk losing contract eligibility. The full list of obligations that remain in force:
Core cybersecurity obligations remain enforceable: DFARS 252.204-7012, NIST SP 800-171 Rev. 2 compliance, cloud security requirements, and cyber incident reporting duties are all still in effect. Your SPRS score is a legal certification. Your prime contracts still bind you to cybersecurity obligations regardless of what the Pentagon announced. Any gap assessment documentation in your files did not evaporate — and if it showed non-compliance, your FCA exposure did not evaporate either.
Sponsored
GovCon iSource
Find, track, and win federal contracts in one platform
Opportunity matching, bid tracking, and proposal tools built for small businesses.
The Reform Task Force and Mid-September Report
A CMMC Reform Task Force has been created to review the program and will report back in mid-September. The Task Force is operating under a 60-day mandate from the July 13 announcement — placing its final report to the DoD CIO around mid-September 2026. That report could recommend anything from a narrowly restructured Phase II to a wholesale redesign of the certification framework. DoD officials declined to rule out ending the program entirely, and the Cyber AB was not told before the announcement.
The RFI comment period closed August 14 — companies that submitted comments have directly shaped the reform recommendations. If you submitted, watch the September report closely; your input is in the record. If you did not, the report is your next opportunity to engage through your industry association or prime contractor relationships before the Task Force’s recommendations translate into regulatory action.
What You Must Do Right Now — The Action Plan
Do not stop your NIST SP 800-171 implementation. The suspension of Phase II third-party assessments does not relieve you of the obligation to protect Controlled Unclassified Information. DFARS 252.204-7012 is unchanged. Every contract you have that covers CUI still requires the underlying cybersecurity controls regardless of CMMC certification status.
Audit your SPRS score for accuracy — immediately. Your SPRS score is a legal certification. An inaccurate score exposes your organization to False Claims Act liability — particularly in the current enforcement environment where the DOJ Fraud Division has explicitly identified defective certifications as an enforcement priority. If your SPRS score does not reflect your actual NIST SP 800-171 implementation status, correct it now. A score that overstates your compliance is FCA exposure. A score that understates it costs you contracts.
Do not cancel your System Security Plan or POAM. Your SSP and Plan of Action and Milestones are compliance infrastructure that prime contractors, contracting officers, and eventually assessors will review. A POAM that documents known gaps and your remediation timeline is evidence of a good-faith compliance program — far better than no documentation at all.
Watch the mid-September Task Force report. The recommendations in that report will telegraph the direction of the reformed program — whether it moves toward simplified self-assessment, scaled requirements by contract size, or a fundamentally restructured certification framework. Companies preparing for CMMC should watch that process closely. The businesses that understand the new framework first will be positioned to comply first — and to compete for contracts that require CMMC compliance before their competitors are ready.
If you are a C3PAO or CMMC consultant — differentiate now. The suspension has disrupted the C3PAO market, but it has not eliminated demand for cybersecurity implementation support. Small businesses that were paying for C3PAO assessments are still required to implement NIST SP 800-171. The market has shifted from certification to implementation support — and firms with CMMC expertise who pivot their service offering accordingly will capture the demand that remains.
The Bottom Line
CMMC Phase II is suspended. CMMC Phase I — the self-assessment requirement, DFARS 252.204-7012, NIST SP 800-171, and SPRS scoring — is not. The 100,000+ defense contractors who needed to comply with Phase II have not been given a compliance holiday; they have been given a reprieve from third-party certification while the underlying cybersecurity obligation remains fully in force. Do not use the suspension as an excuse to stop implementation. Audit your SPRS score. Maintain your SSP and POAM. Watch mid-September. And position for the reformed program — whatever it looks like — before your competitors do. Brick by brick — the requirement to protect defense information has not changed. Only the certification mechanism is under review.
Free Download
The First Federal Contract Roadmap
The complete 90-day guide — registration, certifications, and your first bid — with checklists for every step.
Frequently Asked Questions
What exactly did DoD suspend on July 13?
DoD suspended CMMC Level 2 third-party assessment (C3PAO) and Level 3 DIBCAC assessment requirements, along with all Phase III, IV, and future implementation milestones. The CMMC program rule itself was not repealed and the DFARS was not amended — it is a policy pause pending the CMMC Reform Task Force report due in mid-September 2026.
Do I still need to maintain my SPRS score?
Yes — absolutely. SPRS scoring is a Phase I self-assessment requirement that was not suspended. Your SPRS score is a legal certification of your NIST SP 800-171 compliance posture. An inaccurate score creates False Claims Act exposure regardless of Phase II suspension status. Audit your score immediately for accuracy.
Should I cancel my C3PAO assessment?
The third-party assessment requirement has been suspended, so there is no current legal mandate to obtain a C3PAO assessment. However, continuing your NIST SP 800-171 implementation and SSP/POAM maintenance is still required. Whether to proceed with voluntary C3PAO assessment depends on your specific prime contractor requirements, contract terms, and competitive positioning — consult with GovCon counsel before canceling scheduled assessments.
GovCon iSource Find defense cybersecurity and IT opportunities matched to your NAICS codes.
References
A-LIGN. (2026, July). What the CMMC Phase II Suspension Means for Defense Contractors. https://www.a-lign.com/articles/cmmc-phase-ii-suspension
SBA. (2026, July 13). SBA Commends U.S. Department of War’s Suspension of CMMC Phase II for Small Defense Contractors. https://www.sba.gov/article/2026/07/13/sba-commends-us-department-wars-suspension-cmmc-phase-ii-small-defense-contractors
Troutman Pepper Locke. (2026, July 16). Years in the Making, Suspended in a Day: DoD/W Halts CMMC Phase II but Keeps Baseline Cybersecurity Obligations. https://www.troutman.com/insights/years-in-the-making-suspended-in-a-day-dod-w-halts-cmmc-phase-ii-but-keeps-baseline-cybersecurity-obligations/
Washington Technology. (2026, July 13). DOD suspends CMMC Phase 2, launches 60-day ‘reform’ review. https://www.washingtontechnology.com/contracts/2026/07/dod-suspends-cmmc-phase-2-launches-60-day-reform-review/414739/
About the Author
Melanie Patterson
Founder & CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale — brick by brick. Contact