CMMC Phase 2 Is Paused: What DoD Contractors Should Do Now

On July 13, 2026, the Department of War suspended the transition to Phase 2 of the Cybersecurity Maturity Model Certification program. Within a week, a lot of small defense contractors heard a much simpler version of that sentence: CMMC is dead.

It is not. And acting as though it is will cost you contracts, and possibly a False Claims Act settlement.

What actually happened is narrower and stranger than the headlines. Two memoranda — not a rule, not a Federal Register notice, not a class deviation — stopped the escalation to third-party certification while leaving the entire CMMC regulatory structure standing. The rule is still on the books. The clause is still in your contract. The self-assessment you owe is still due. Here is what changed, what did not, and what a small contractor should actually be doing this quarter.

What the July 13 memos actually say

Two documents were released the same day. The first is a memorandum from Kirsten A. Davies, the Department of War Chief Information Officer, titled “Removing Barriers to Defense Industrial Base Expansion.” The second is an implementing memorandum from the Office of the Under Secretary of War for Acquisition and Sustainment.

The CIO memo states that “the upcoming November 2026 deadline to transition to Phase 2 of CMMC implementation is suspended” and that all pending and future CMMC implementation milestones are “held in abeyance until further notice.” It then does something people keep missing. It directs that program managers “shall only include the need for CMMC Level 1 or Level 2 Self Assessments in procurement request and requirement documents,” and states plainly that “all other contractual cybersecurity clauses in contracts remain intact.”

Read that twice. The memo does not suspend CMMC. It freezes the program at Phase 1 and affirmatively orders contracting activities to keep requiring self-assessments.

The implementing memo turns that into contracting instructions. Program managers “may not designate CMMC Level 2 (C3PAO) or Level 3 (DIBCAC) assessments” during the suspension. Where an active solicitation already carries one, contracting officers are directed to amend it “as soon as practicable.” Where an existing contract carries one, they are directed to remove it by modification “prior to the exercise of the next option period or during the next scheduled administrative modification.” And no waivers will be granted while the review runs.

The legal detail that matters most: this was done by memo

Nothing was published in the Federal Register. No class deviation was issued for the suspension. The CMMC program rule at 32 CFR Part 170 and the acquisition rule that produced DFARS 252.204-7021 are both still in force, unamended, today.

That produces a genuine oddity. The regulation still says Phase 2 begins one year after Phase 1, and Phase 1 began November 10, 2025 — so the text on the books still points at November 10, 2026. The memos say do not do it. For a contracting officer, the directive controls. For you, the rule is what a court would read.

The practical consequence is simple: a policy created by memorandum can be reversed by memorandum. There is no notice-and-comment process to run, no proposed rule to watch, no comment period to participate in. If leadership changes its mind, the reversal can arrive as fast as the suspension did. Build your plans accordingly.

What you still owe today

Assume nothing about your obligations until you have read your actual contract. That caveat is doing real work right now, because the Revolutionary FAR Overhaul reorganized DoD’s cybersecurity clauses into a deviated DFARS Part 240 for new solicitations in early 2026. Depending on when your solicitation issued, you may be looking at the familiar 252.204-series numbers or at renumbered 240-series equivalents.

What has not moved:

  • DFARS 252.204-7012 is fully in force. The CIO memo goes out of its way to say so. That means the 110 requirements of NIST SP 800-171 Revision 2, adequate security on covered contractor information systems, media preservation, malicious software submission, flowdown to subcontractors handling covered defense information, and 72-hour cyber incident reporting to DIBNet.
  • DFARS 252.204-7021 is in force. If it is in your contract, you must maintain the required CMMC status for the life of the contract, process covered information only on systems holding that status, affirm continued compliance annually in SPRS through a named Affirming Official, and verify subcontractor status before award.
  • Level 1 and Level 2 self-assessments are not merely permitted. They are directed into new procurements.
  • Government-led assessments continue. The memos preserve “select Government-led assessments.” DIBCAC did not stand down.

If you want the underlying control set in plain language, our guide to NIST 800-171 for small contractors walks through it, and the DFARS cybersecurity clauses covers how 7012 operates.

The counterintuitive part: your legal risk probably went up

Removing the third-party audit does not remove the requirement. It removes the check on your own answer.

Under Phase 1, the government’s knowledge of your security posture comes almost entirely from a number you calculated and posted yourself. That number is a representation to the government. It supports award decisions. It is reaffirmed annually by a named official at your company.

In June 2026, the Justice Department settled with LOGZONE, Inc., an Alabama defense contractor, for $507,144. The allegation covered conduct from May 2021 through March 2025 on two Navy contracts. The detail worth memorizing is that a DCMA assessment scored the company at −170 on a scale DOJ itself described as running from −203 to 110. The settlement resolved allegations only; there was no determination of liability.

The mechanism is what should concern you. Once the government performs its own assessment, it holds an authoritative numeric counter-figure to whatever you posted. That is a far easier case to build than a traditional argument about whether controls were adequate. Every major government contracts practice that wrote about the suspension made the same point independently: with the third-party check gone, self-assessment accuracy becomes the whole ballgame.

Your prime does not answer to this memo

Flowdown requirements from a prime contractor are private contract terms. The Department of War cannot suspend them, and did not try.

Several large primes told their supply chains within days of the announcement that nothing changed on their end. One wrote to suppliers that the pause was “an opportunity to strengthen your program – not a reason to delay it.” If you are a subcontractor, the operative document is your subcontract, not the CIO memo. Ask, in writing, before you cancel anything.

What the Reform Task Force is and is not

The CIO memo directed the immediate creation of a CMMC Reform Task Force to run a 60-day top-to-bottom review, with a mandate to recommend a framework that “prioritizes speed to capability, lowers barriers for small, medium, and non-traditional businesses, and replaces prohibitive, third-party compliance models with scalable, realistic security measures.”

Sixty days from July 13 lands around September 11, 2026. As of this writing the task force has not reported, no membership roster has been published, and no interim findings exist. A related request for information closed in mid-August.

Note carefully what that mandate is. It is a charter describing what someone was asked to look into. It is not a decision. Anyone telling you what CMMC will be replaced with is guessing.

Where the levels stand right now

Level 1 (Self) covers Federal Contract Information against the 15 basic safeguarding requirements, assessed annually, pass/fail, with annual affirmation. Level 2 (Self) covers Controlled Unclassified Information against all 110 requirements of NIST SP 800-171 Rev 2, assessed every three years, with annual affirmation. Both remain available and directed.

Level 2 (C3PAO) and Level 3 (DIBCAC) may not be designated in new requirements and must be stripped from active solicitations and existing contracts. Certifications already issued were not revoked. Voluntary third-party assessments remain available — the accreditation body and the assessor organizations were not stood down.

A nine-item checklist for this quarter

  1. Read your contracts. Identify which cybersecurity clauses you actually carry, by number. Clause numbering varies by solicitation date because of the FAR overhaul deviations.
  2. Check whether the CO has issued the modification. If you hold a contract or are pursuing a solicitation carrying Level 2 (C3PAO) or Level 3, the contracting officer is directed to strike it. If nothing has happened, ask.
  3. Keep SPRS current. Your assessment must be no more than three years old, and a solicitation can demand something fresher.
  4. File the annual affirmation. It is a certification to the government signed by a named official. In a five-person shop that is the owner.
  5. Make sure your score is defensible. Keep the system security plan, the plan of action, and the evidence artifacts aligned with what you posted.
  6. Keep 7012 running, including the ability to report an incident within 72 hours. Reporting requires a DoD-approved medium assurance certificate — obtain it before you need it, not during an incident.
  7. Confirm with your prime in writing before changing anything driven by a flowdown.
  8. Finish remediation already underway. The interim standard is the same 110 controls, just self-attested.
  9. Watch for a Federal Register notice. That is the tell that separates durable reform from a reversible memo.

Key takeaways

  • The transition to CMMC Phase 2 was suspended on July 13, 2026 by memorandum — not by rule. 32 CFR Part 170 and DFARS 252.204-7021 remain in force.
  • Phase 1 is running. Level 1 (Self) and Level 2 (Self) are affirmatively directed into new procurements.
  • What stopped is the escalation to C3PAO certification and DIBCAC assessment as a condition of award.
  • DFARS 252.204-7012 and the 110 NIST SP 800-171 Rev 2 requirements are untouched.
  • Prime contractor flowdown obligations did not pause and many primes have not relaxed them.
  • With the third-party check removed, the accuracy of your self-assessment carries more legal weight, not less.
  • The Reform Task Force has not reported. Nothing about a replacement framework has been decided.

Frequently asked questions

Can I cancel my scheduled C3PAO assessment? You can, but think first. Certifications already issued remain valid, voluntary assessments are still available, no waivers are being granted during the review, and the suspension is explicitly temporary with no end date. If a prime is driving the requirement, their flowdown did not pause. Confirm with the buying activity and your prime before cancelling.

Do I still have to post a score in SPRS? Yes. The self-assessment and affirmation obligations were expressly preserved. An assessment older than three years is stale, and letting it lapse while performing on a contract that requires it is exactly the fact pattern that produces enforcement problems.

Is CMMC coming back? Unknown. The suspension has no end date and no replacement framework exists. The signal to watch is whether any reform arrives through the Federal Register rather than another memorandum — a rule is durable, a memo is not.

If you are working through what your contract actually requires and want a second set of eyes, Veteran Forge Strategies works with small federal contractors on exactly this kind of compliance assessment.

Similar Posts