Industry Insights
CMMC Phase 2 Is Suspended: Here's What It Actually Means for Defense Contractors.
July 14, 2026 · Brock Griffin
On Monday, July 13, 2026, the Department of Defense abruptly suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program. That is the phase that would have required most defense contractors to pass a third-party assessment before winning new contracts. If you have spent the last two years preparing for CMMC, your first question is probably: does this mean I can stop? The short answer is no. Here is what actually happened, and why the smart move is to keep going.
What the Pentagon actually announced
DoD Chief Information Officer Kirsten Davies and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey announced an immediate suspension of CMMC Phase 2, which was scheduled to take effect on November 10, 2026. Phase 2 would have required contractors handling Controlled Unclassified Information (CUI) to pass an assessment from a Certified Third-Party Assessor Organization (C3PAO) in order to receive contract awards.
The Department went further, suspending all pending and future CMMC milestones, including Phase 3 and full implementation, until further notice, and standing up a 60-day "CMMC Reform Task Force" to review the entire program. Officials have not ruled out reinstating a revised CMMC, replacing it, or ending it altogether at the end of that review.
Why they hit pause
It comes down to cost and capacity. Citing Small Business Administration data, Davies said future CMMC phases could cost small and mid-sized businesses more than $7 billion a year, a burden the Department concluded was pushing small and non-traditional companies out of the defense industrial base. A March 2026 Government Accountability Office report had warned of exactly that: that the standards might prove too difficult and costly for some small businesses to meet, forcing them out of the DIB. Add a severe shortage of C3PAO assessors, and as Davies put it bluntly, "the math just simply doesn't math for small to medium-sized businesses to even get compliant by the transition date."
What did NOT change, and this is the part that matters
A suspension is not a repeal. The certification requirement is paused. The underlying security obligations are not.
- Phase 1 stays in effect. The CMMC self-assessment requirements that took effect last November remain in force for applicable contracts.
- The standard still applies. During the pause, the Department will continue to enforce cybersecurity through the NIST SP 800-171 Revision 2 standard, using self-assessments and select government-led assessments.
- Your contract clauses didn't disappear. DFARS 252.204-7012 and your obligation to protect CUI are still written into your contracts.
- This could come back. The task force is due to report within 60 days. Whatever replaces this pause, it is not going to be "no cybersecurity requirements at all."
Why you should keep doing the work
It is tempting to treat this as a reprieve and redirect the budget. Here is why that is a mistake:
- The threat didn't pause. Nation-state and criminal actors target the defense supply chain regardless of the compliance calendar. NIST 800-171 exists because those threats are real.
- You're still legally on the hook. Self-attesting to a security posture you don't actually have carries real exposure under the False Claims Act, the same risk that has already produced multimillion-dollar settlements.
- Primes still flow it down. Your customers up the supply chain still expect NIST 800-171 compliance, task force or not.
- Restarting costs more than continuing. Teams that stop and rebuild momentum later pay for it twice. The ones that stay the course will be first in line, and lowest cost, when the requirement returns.
What to do now
Keep your program moving on the things that don't depend on a C3PAO:
- Keep your System Security Plan (SSP) and Plan of Action & Milestones (POA&M) current.
- Maintain an honest NIST 800-171 self-assessment and keep your SPRS score accurate.
- Keep closing control gaps: identity, endpoints, logging, backup, and the rest.
- Don't cancel your assessment roadmap. Re-time it, and watch what the task force recommends.
Not sure where this leaves your business?
The rules just got more confusing, not less. Gryphon Tech Advisors helps organizations in the Defense Industrial Base navigate exactly this, cutting through the noise to keep your CMMC and NIST 800-171 program moving without spending money on the wrong things at the wrong time. If you're not sure what this pause means for your contracts, talk with an advisor, and we'll give you a straight answer.
Sources
- U.S. Department of War: official release on suspending CMMC Phase II requirements
- Federal News Network: Pentagon suspends CMMC phase two requirements, launches review
- DefenseScoop: DOD halts cybersecurity requirements for CMMC Phase 2
- Washington Technology: DOD suspends CMMC Phase 2, launches 60-day reform review
- National Defense Magazine: Pentagon Suspends Phase 2 of CMMC Program