Skip to main content

On July 13, 2026, the Department of War (DoW) suspended the CMMC Phase II requirements that were scheduled to take effect November 10, 2026, and opened a 60-day review of the entire CMMC program. Here is what that actually means for your obligations as a defense contractor, and, more importantly, what it does not change.

What does the CMMC pause do

According to DoW CIO Kirsten A. Davies, the Department is “suspending the CMMC Phase II requirements and initiating a 60-day study of the future of this program.”

This pause suspends the transition to CMMC Phase II. Phase II requires a passed third-party C3PAO certification assessment for Level 2 before contract award. The DoW has also established a CMMC Reform Task Force to review the program and deliver recommendations to the CIO within 60 days.

What the CMMC pause does NOT do

This is where contractors could find friction. The suspension is narrow. It does not:

  • Remove your obligation to implement NIST SP 800-171 Rev 2. All 110 security requirements still apply.
  • Change DFARS 252.204-7012. The release is explicit: the action “does not eliminate the requirement for companies to protect federal data,” and every contractor and subcontractor remains contractually obligated to safeguard covered defense information under -7012.
  • Waive the FedRAMP Moderate baseline for cloud. If you use a cloud service to store, process, or transmit CUI, the CSP must still meet the FedRAMP Moderate (or equivalent) requirement under 252.204-7012. This requirement lives in the DFARS clause, not in CMMC’s assessment mechanism, so the pause doesn’t touch it.
  • Alter contract requirements for upcoming solicitations. The DoW directive explicitly states that contracting officers can only include Phase I requirements, meaning Level 1 (Self) or Level 2 (Self), in active or new procurements during this 60-day window. If you are bidding on work right now, you are still expected to meet and affirm these Phase I baselines to qualify for award.
  • Undo CMMC Level 1 for FCI. The annual Level 1 self-assessment and affirmation for Federal Contract Information remain fully in force.
  • Remove the Level 2 self-assessment. All Phase I requirements “remain firmly in place.” That includes your Level 2 self-assessment against 800-171 Rev 2, with your score and affirmation posted to SPRS.

Finally, and most critically: during this interim period, the DoW will enforce 800-171 Rev 2 compliance “through self-assessments and select government-led assessments.” A pause on third-party certification is not a pause on accountability. The government still reserves the right to assess you directly.

What we don’t know yet about the CMMC pause

We don’t know what the final decision and what CMMC will look like after the 60-day review. The DoW has said it wants agility and security without the administrative burden that has been pushing small and mid-size firms out of the Defense Industrial Base. That could produce a sensible cyber-hygiene program with appropriate governance, or something else entirely.

Our recommendation hasn’t changed

Organizations are still bound by DFARS 252.204-7012. The interim posture self-assessment, along with the possibility of a government-led assessment, still places the burden of proving your organization’s baseline squarely back on you.

Our guidance remains the same as before July 13: complete your required Level 2 self-assessment and post your score to SPRS. If you handle CUI and you don’t have a current score in SPRS, you are already behind on an obligation that predates CMMC. Use this window to close your gaps, not to stand down.

Follow this live

This is an evolving 60-day review, and the official record is the place to watch. Track it directly at the source:

If you have additional questions for our CMMC experts, contact us today.