Contact Us

CMMC Reform Is Underway: What DoD’s Listening Sessions Mean for Small Defense Contractors Right Now

Published August 11, 2026 | TIKC NewsWire

The Pentagon suspended CMMC Phase 2 third-party certifications in June and stood up a reform review team. That team held its first listening session on July 16 — and the questions swirling around what DoD can actually change, how quickly, and what it means for the thousands of small defense contractors currently navigating cybersecurity compliance requirements are only beginning to get answers. Here is the current state of play and what small businesses must understand right now.

Where the CMMC Reform Stands

The Pentagon wants to move quickly with its review of the Cybersecurity Maturity Model Certification program, but plenty of questions swirl around what defense officials can do differently this time to balance compliance concerns for small businesses with the need to enforce cybersecurity requirements. The CMMC review team met for the first time on July 16, DoD CIO Kirsten Davies told reporters that same day. The suspension covers Phase 2 third-party assessments — the requirement for CMMC Level 2 certification through accredited C3PAO assessors. The suspension does not eliminate CMMC or its underlying cybersecurity requirements.

What the reform team is examining falls into several broad areas: the cost and burden of third-party assessments on small businesses, particularly those with limited IT budgets; the adequacy of CMMC Level 1 self-assessment as a compliance pathway; the timeline and sequencing of CMMC requirements across different contract tiers; and whether the C3PAO ecosystem has the capacity to certify the volume of contractors DoD needs without creating a bottleneck that delays contract awards.

What Has Not Changed

The CMMC Phase 2 suspension does not suspend DFARS 252.204-7012 — the foundational cybersecurity clause that has been in DoD contracts since 2017. Every contractor subject to that clause is still required to implement NIST SP 800-171 controls and maintain an accurate SPRS score. The suspension does not change those obligations. What it suspends is the timeline for requiring third-party C3PAO assessments on existing contracts — contractors cannot yet be required to obtain a CMMC Level 2 certification as a contract condition while the review is underway.

Sponsored

GovCon iSource

Find, track, and win federal contracts in one platform

Opportunity matching, bid tracking, and proposal tools built for small businesses.

Start Free Tour →

What Small Defense Contractors Should Do Right Now

Do not stop your NIST 800-171 implementation. Whether CMMC’s third-party assessment requirement is reformed, simplified, or restructured, the underlying cybersecurity controls it is based on — NIST SP 800-171’s 110 practices — are not going away. DoD’s cybersecurity requirements predate CMMC and will survive any CMMC reform. Contractors who use the suspension as a reason to pause implementation are making a strategic error: the SPRS score reflecting your 800-171 implementation is a legal document per the LOGZONE FCA settlement, and inaccurate scores remain an enforcement liability regardless of CMMC’s status.

Update your SPRS score if it does not reflect your actual posture. The SPRS self-assessment score you submitted to the Supplier Performance Risk System is a certification of your cybersecurity posture. If your controls have improved or deteriorated since your last assessment, update the score. A score that materially understates or overstates your actual implementation is a compliance and legal risk.

Watch for Phase 2 restart timing. The reform review is expected to produce recommendations within 60 days of its July 16 start — meaning results could arrive in mid-September. Monitor DoD CIO communications and Federal Register notices for any rule changes that emerge from the review. The restart of Phase 2 requirements, when it comes, may include modified timelines or tiered requirements that differ from the original CMMC rule.

The Bottom Line

CMMC is being reformed, not eliminated. The core cybersecurity requirements underlying it are unchanged. The suspension gives small businesses breathing room on third-party assessment timelines — not permission to pause cybersecurity work. Use this window to get your NIST 800-171 implementation solid, your SPRS score accurate, and your documentation in order. When Phase 2 restarts, contractors who used the pause wisely will be ahead of those who treated it as a reprieve. Brick by brick — cyber compliance is not optional, and the reform will not make it easier, only more structured.

Free Download

The First Federal Contract Roadmap

The complete 90-day guide — registration, certifications, and your first bid — with checklists for every step.

Get the Free Roadmap →

Frequently Asked Questions

What did the CMMC Phase 2 suspension actually suspend?

The suspension paused the requirement for contractors to obtain CMMC Level 2 certification through accredited C3PAO third-party assessors as a contract condition. It did not suspend DFARS 252.204-7012, NIST SP 800-171 implementation requirements, or SPRS self-assessment obligations.

Do I still need to maintain my SPRS score during the suspension?

Yes. The SPRS score is a self-certification of your cybersecurity posture under DFARS 252.204-7012, which remains fully in force. An inaccurate SPRS score is a False Claims Act exposure regardless of CMMC’s Phase 2 status.

When will CMMC Phase 2 restart?

The reform review team began work July 16 and is expected to produce recommendations within approximately 60 days — suggesting mid-September 2026. The restart timeline, and whether Phase 2 will be modified as a result of the review, will be announced through DoD CIO communications and potentially a Federal Register rule change.

GovCon iSource  Track CMMC-required defense contract opportunities matched to your NAICS codes.

Explore iSource →

References

Federal News Network. (2026, July 30). DoD Plans CMMC Listening Sessions As Questions Swirl Around Review. https://federalnewsnetwork.com/defense-main/2026/07/dod-plans-cmmc-listening-sessions-as-questions-swirl-around-review/

PilieroMazza. (2026, July 30). Weekly Update for Government Contractors — July 30, 2026. https://www.pilieromazza.com/weekly-update-for-government-contractors-and-commercial-businesses-july-30-2026/

Melanie Patterson

About the Author

Melanie Patterson

Founder & CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale — brick by brick. Contact

Most Read

Mergers and acquisitions in government contracting trigger novation and recertification requirements that can end a
A proposed FAR rule would standardize how all contractors handle Controlled Unclassified Information — with

Related

Discover more from Team Integrity Knowledge Center

Subscribe now to keep reading and get access to the full archive.

Continue reading