CMMC Phase II Suspended: What Changed, What Didn’t, and What to Watch — August Schell
CMMC Program Status · Maintained by August Schell

CMMC Phase II suspended: what changed, what didn’t, and what to watch

Bottom line up front

On July 13, 2026 the Department of War announced the immediate suspension of CMMC Phase II — the third-party certification tier originally scheduled to take effect November 10, 2026. The suspension pauses the verification mechanism, not the security obligation. DoW requiring activities may now designate only Level 1 (Self) or Level 2 (Self) assessments, Phase I self-assessment requirements remain in place, DFARS 252.204-7012 remains fully enforceable, and the Department will enforce NIST SP 800-171 Rev. 2 through self-assessments and select government-led assessments while a 60-day CMMC Reform Task Force review is completed.

Current as of July 16, 2026.  August Schell Enterprises · Authorized C3PAO · Registered Practitioner Organization  ·  This brief reflects a developing policy action and is updated as the Department releases further guidance.
Next deadline
FAR CUI Rule — public comment period closes
July 23, 2026 · Unaffected by the suspension. Applies immediately on finalization, with no phased on-ramp.
Days
Hrs
Min
Sec

Where things stand today

CMMC Phase II — third-party C3PAO certification
Suspended effective immediately per USD(A&S) Memorandum 26-P-1023, implementing the DoW CIO’s suspension. Pending and future implementation milestones are paused across DoW solicitations and contracts.
Suspended
CMMC assessment levels DoW may require
For the duration of the review, Program Managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) and Level 3 (DIBCAC) designations are not permitted, and no waivers will be granted. Existing C3PAO and DIBCAC requirements are being removed from active solicitations, and from existing contracts at the next option exercise or scheduled administrative modification.
Self-assessment only
CMMC Phase I — self-assessment, Levels 1 & 2
A current NIST SP 800-171 self-assessment posted in SPRS, with annual senior-official affirmation, remains a condition of eligibility.
Still required
DFARS 252.204-7012
In full force. Safeguarding covered defense information and the 72-hour incident reporting obligation are unchanged.
In full force
NIST SP 800-171 Rev. 2
The enforced technical baseline during the interim — verified through self-assessments and select government-led DIBCAC assessments.
Enforced
32 CFR Part 170 & the DFARS acquisition rule
The CIO memo pauses implementation; it does not repeal the regulation. Permanent change would require further rulemaking.
Codified law
The CMMC ecosystem — assessments, training, exams
Per the Cyber AB (July 15): only Phase II implementation was suspended. C3PAO Level 2 certification assessments, CAICO training, professional exams, Registered Practitioner services, and DIBCAC assessments all remain operational and available. You can still get certified — though no DoW contract can require it during the suspension.
Fully operational

What changed, effective immediately

  • DoW requiring activities may designate only self-assessments. For the duration of the review, Program Managers and requiring activities may designate only CMMC Level 1 (Self) or Level 2 (Self). Level 2 (C3PAO) and Level 3 (DIBCAC) designations are not permitted, and no waivers will be granted.
  • Phase II requirements are suspended. Third-party CMMC Level 2 certification by a C3PAO is no longer a scheduled condition of award under the November 10, 2026 milestone. Directed by USD(A&S) Memorandum 26-P-1023, July 13, 2026.
  • Existing C3PAO and DIBCAC requirements are being removed. They come out of active solicitations now, and out of contracts already awarded at the next option exercise or scheduled administrative modification — not immediately. Until your contract is modified, the clause on it is still the clause on it. Confirm the status of your specific awards in writing rather than assume a requirement has been read out.
  • A CMMC Reform Task Force has been established to conduct a top-to-bottom review, delivering recommendations to the DoW CIO within 60 days — placing its report in the mid-September 2026 timeframe.
  • A public RFI is open for industry feedback on compliance challenges, posted on SAM.gov, with responses due August 14, 2026. This is industry’s direct channel to influence what replaces or restores Phase II.
  • The rationale, now quantified. SBA analysis published the same day estimates roughly $593,800 per certification for small firms requiring third-party assessment, against roughly $388,600 for a self-assessment — and found Phase II would have required more than 120,000 DIB small businesses to comply through a system supported by only about 100 approved assessors.

What did not change

  • Phase I self-assessment requirements remain firmly in place — a current SPRS score with annual senior-official affirmation is still a condition of eligibility on applicable solicitations.
  • DFARS 252.204-7012 remains in full force. This action does not eliminate the requirement to protect covered defense information. The 72-hour incident reporting obligation is unchanged.
  • NIST SP 800-171 Rev. 2 remains the enforced technical baseline, verified through self-assessments and select government-led assessments conducted by DIBCAC.
  • The underlying rules remain codified law. 32 CFR Part 170 and the DFARS acquisition rule remain in effect. The CIO memo pauses implementation; it does not repeal the regulation.
  • The entire CMMC ecosystem remains operational — including certification itself. The Cyber AB confirmed on July 15 that only Phase II implementation was suspended, and that all program elements remain available: C3PAO Level 2 certification assessments, CAICO training, professional exams, Registered Practitioner services, and DIBCAC’s assessment of C3PAOs. You can still get certified — though no DoW contract can require it during the suspension. If you pursue certification now, you are doing it for the primes and for your FCA posture, not to satisfy a DoW clause.
  • The FAR CUI Rule is unaffected. FAR Case 2017-016 is a separate, government-wide rulemaking. Its comment period closes July 23, 2026, and as drafted it applies immediately upon finalization with no phased on-ramp.

What remains unknown

  • Government-led assessments. The Department has not defined what these will look like, which contractors will be prioritized, or how they will be scheduled and scoped.
  • Existing certifications and in-progress assessments. The announcement is silent on the status and contractual value of certifications already earned and assessments currently underway.
  • The future of Phase II. Whether third-party certification returns in modified form, on a revised timeline, or is replaced by a different verification model will not be known until after the Task Force reports.
  • Duration of the review. The 60-day deadline applies to recommendations, not to a final decision. Any resulting program change would itself require rulemaking time.

Perspective: we have seen this before

This is the second major review of the CMMC program, and the first one did not end it. In 2021 the Department suspended and reviewed CMMC 1.0 over the same two complaints driving today’s action: cost and assessor capacity. The result was CMMC 2.0 — a streamlined program, not a cancelled one.

The requirement to protect federal CUI data has survived every restructuring, because it is the point of the program, not a feature of it.

Two things are different this time, and both favor continuity. First, in 2021 there was no codified rule. Today 32 CFR Part 170 and the DFARS acquisition rule are law, which means this review starts from a standing legal foundation rather than a policy proposal. Because the regulatory machinery remains standing, re-implementation of a modified program could move quickly once the Task Force reports. Organizations that fully dismantle their programs in July could be caught flat-footed in the fourth quarter.

Beneath the rules sits a statutory layer as well. Section 1648 of the FY2020 NDAA (Pub. L. 116-92), “Framework to enhance cybersecurity of the United States defense industrial base,” directs the Department to develop and maintain a comprehensive framework — including unified standards, third-party certifications, and mechanisms for assessing contractor cybersecurity. Absent congressional relief, the Department is not free to simply have no framework; the question this review answers is what form it takes.

Second, the Task Force’s mandate is not whether to verify compliance, but how — at lower cost and with greater assessor capacity. Even if third-party certification were permanently eliminated, the government retains its own assessment capability through DIBCAC, so verification exposure does not disappear. DIBCAC’s finite capacity across an industrial base of this scale is exactly why a scalable model is expected to emerge from this review rather than none at all.

The accreditation body said the same thing this week. In a July 15 statement, Cyber AB Chief Executive Officer Matthew Travis pointed to the program’s measurable footprint — over 1,000 Certified Assessors, 110 authorized C3PAOs, and nearly 2,000 contractors already certified at Level 2 — and called third-party verification of cybersecurity conformity “absolutely critical.” He was direct about what a certificate is worth right now:

“NIST SP 800-171 and DFARS 7012 requirements remain in place and unchanged for most all contractors. A Level 2 certification by a C3PAO remains a compelling calling card for subcontracting viability to primes and the best insurance policy against False Claims Act risk.”
— Matthew Travis, CEO, The Cyber AB · July 15, 2026

The Cyber AB will address the Phase II pause, the Reform Task Force, and the state of the program at its CMMC Town Hall on Tuesday, July 28 at 6:00 pm EDT. We will be there, and we will publish what we learn here.

What organizations should do now

  • Do not dismantle your compliance program. The technical standard is unchanged, self-attestation now carries direct government audit exposure, and organizations with documented, maintained NIST SP 800-171 programs are best positioned regardless of what verification model emerges.
  • Validate your SPRS score against evidence. Inaccurate affirmations carry False Claims Act risk. With the third-party checkpoint suspended, a score that would not survive a government-led assessment is more exposed than it was before, not less. A non-certification mock assessment delivers the same line-by-line diagnostic an assessor would apply, without the certification cost — and does not establish a consulting relationship under Cyber AB conflict-of-interest rules.
  • Confirm your assessment designation. Ask your contracting officer, in writing, which CMMC level and assessment type your contract now carries. Requiring activities may designate only Level 1 (Self) or Level 2 (Self) during the review, and existing C3PAO and DIBCAC requirements come off at the next option exercise or administrative modification — which means the answer today may not be the answer on your contract today.
  • Confirm existing contract and prime requirements in writing. Where DFARS 252.204-7021 already sits in an awarded contract, it remains a live obligation until modified. Primes impose supplier cybersecurity terms independent of the DFARS, and their obligations to you did not change with this announcement.
  • Strengthen the environment behind your attestation. A purpose-built CUI environment — self-managed or delivered as a managed enclave with expert staff — provides the documented control implementation that supports a defensible SPRS score.
  • Submit FAR CUI Rule comments before July 23, 2026, and respond to the CMMC RFI before August 14, 2026. Actual cost data from your own program carries more weight than general commentary.

Key dates

July 13, 2026
Phase II suspension effective
July 28, 2026
Cyber AB CMMC Town Hall, 6:00 pm EDT
August 14, 2026
CMMC RFI responses due on SAM.gov
Mid-September 2026
Task Force report due to the DoW CIO

How does this apply to your contracts?

We’re engaging directly with the Cyber AB at the executive level and will update this brief as the RFI and the 60-day Task Force review develop. For an assessment of how this action applies to your specific contract portfolio, certification timeline, or compliance roadmap, talk to our team.

Full brief · PDF

The complete sourced brief

Three pages, fully cited to the CIO memo, the SBA analysis, and the FY2020 NDAA. Updated as guidance develops.

Get the brief → Request a readiness check

Talk to a person

Business POC
Alonzo “Cory” Booker
Director, Managed Services
alonzo.booker@augustschell.com
Customer POC
Jane Zipoli
Senior CMMC Account Manager
jane.zipoli@augustschell.com
Technical POC
Timothy Judy
Chief Information Security Officer
timothy.judy@augustschell.com
Sources. U.S. Department of War, “Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements,” Immediate Release, July 13, 2026. USD(A&S) Memorandum 26-P-1023, “Implementing Department of War Chief Information Officer’s Suspension of the Advancement to Cybersecurity Maturity Model Certification Phase 2 Requirements,” with Attachment 1, July 13, 2026. U.S. Small Business Administration, News Release 26-73, “SBA Commends U.S. Department of War’s Suspension of CMMC Phase II for Small Defense Contractors,” July 13, 2026. The Cyber AB, “Statement on the Department of War’s Suspension of CMMC Phase II Requirements,” National Harbor, MD, July 15, 2026. DoW CIO, Brilliant Basics. Memorandum 26-P-1023 (PDF) signed by Michael P. Duffey, Under Secretary of War for Acquisition and Sustainment.