On July 13, 2026, the Department of Defense suspended Phase 2 of the Cybersecurity Maturity Model Certification (CMMC) program and opened a 60-day review. Within hours I heard the same reaction across the defense industrial base: good, now we can slow down.
That reading is wrong, and it will cost the contractors who believe it. The Department paused one mechanism. It did not lift a single security obligation. If your contracts require you to protect controlled unclassified information, your legal duties today look exactly as they did on July 12.
Here is what actually changed, what did not, and why the contractors who keep moving will hold the advantage when the assessors return.
What did DoD actually suspend?
DoD suspended Phase 2 of the CMMC rollout, the stage that would have required many contractors handling CUI to pass a third-party assessment as a condition of award. That requirement was scheduled to take effect on November 10, 2026. A new CMMC Reform Task Force, reporting to the DoD Chief Information Officer, now runs a review of the program, with contractor input collected through a request for information due August 14, 2026.
Two distinctions matter here. First, the suspension targets Phase 2 of the rollout, not CMMC Level 2 itself. Level 2 remains the security tier that applies to most contractors who handle CUI. Second, Phase 1 self-assessment requirements stay fully in place. The Department kept the self-attestation layer running and removed only the outside audit.
Is CMMC cancelled?
No. The Department paused a verification step. It did not repeal a rule. The CMMC Program rule at 32 CFR Part 170 and the DFARS acquisition clauses remain on the books, and unwinding either one would take formal rulemaking measured in months. Officials have not ruled out larger changes, but nothing in the July memo removes an existing requirement.
Treat CMMC as the checking mechanism, not the standard. The standard came first, and it still governs your program.
What has not changed for defense contractors
This is the part the headlines miss. Several obligations survived the suspension untouched.
- DFARS 252.204-7012 still applies. This clause has required contractors and subcontractors that handle covered defense information to implement the 110 controls of NIST SP 800-171 since 2017, and to report cyber incidents within 72 hours.
- Your NIST SP 800-171 self-assessment still counts. You calculate a score against the 110 requirements and keep it current.
- Your SPRS score is still live. Every prime and contracting officer you work with can see it, and it factors into your eligibility for award.
Enforcement did not pause either. The Defense Industrial Base Cybersecurity Assessment Center (DIBCAC) continues to run reviews, and the Department of Justice continues to pursue False Claims Act cases tied to inaccurate cybersecurity attestations. With no third-party assessor checking your work first, an overstated SPRS score now carries more personal exposure, not less.
Contractors that serve both defense and civilian agencies get no reprieve at all. The duty to protect sensitive federal information reaches beyond CMMC, so a pause on one program does not clear the wider requirement.
Why pausing your compliance program is a commercial mistake
I spent two decades selling enterprise technology, and I learned early that timing beats intensity. The contractors who treat this pause as schedule relief rather than permission to stop will convert it into a market position.
Look at the math behind the assessment bottleneck. More than 100,000 companies in the defense industrial base need an assessment, and roughly 100 authorized third-party assessor organizations exist to perform them. A 60-day review does not close a gap that wide. When the requirement returns, and the underlying rule suggests it will in some form, the queue will favor the companies that stayed ready.
There is a business development angle that compliance teams sometimes overlook. Primes vet their subcontractors on cyber posture before they award work. A current, defensible SPRS score is a sales asset. It signals that you can hold CUI without becoming the weak link in a bid. Let that score go stale during the pause, and you hand a competitor a reason to take the flow-down.
I write about this intersection of cybersecurity compliance and commercial strategy because the two decisions are rarely separate. If this is the conversation you are having inside your own organization, connect with me on LinkedIn.
What defense contractors should do now
The right response to a pause is steady progress, not a full stop. A practical posture for the review period looks like this.
- Keep your evidence current. Configuration records, scan results, and POA&M updates you collect now will count under any assessment model the task force designs.
- Refresh your SPRS score. A stale score is a contract risk today, suspension or not.
- Close your open POA&M items on the original timeline. Remediation you schedule now lands well before assessors return.
- Confirm your CUI boundary. Know which systems touch covered defense information, and keep that scope documented.
- Watch for a class deviation or a DFARS amendment. A memo changes discretion. Only a rule change moves the law, so track the formal record rather than the headlines.
This is the operational discipline I described in CMMC in the Plant, Not the PowerPoint, where compliance lives on the shop floor instead of in a slide deck. The pause does not change that. It rewards the companies that already built the habit.
Frequently asked questions
Is CMMC going away?
No. The Department suspended Phase 2 of the rollout and launched a review. The CMMC Program rule and the DFARS clauses remain in effect, and removing them would require formal rulemaking.
Do I still need to meet NIST SP 800-171 during the pause?
Yes. If your contract includes DFARS 252.204-7012 and you handle covered defense information, you still implement all 110 controls of NIST SP 800-171 and maintain your System Security Plan.
Do I still have to post an SPRS score?
Yes. Self-assessment and SPRS score posting remain mandatory. Your score stays visible to primes and contracting officers throughout the review.
When will CMMC Phase 2 resume?
No firm date exists. The task force review runs on a 60-day clock, and the Department has not committed to a restart date. Plan for the requirement to return rather than disappear.
Can enforcement still happen while Phase 2 is paused?
Yes. DIBCAC reviews and False Claims Act enforcement continue. An inaccurate self-attested score carries real legal exposure with no third-party assessor in the loop.
The bottom line
The CMMC Phase 2 pause is a shift in schedule, not a change in what the government expects you to protect. The rule stands, the DFARS clauses stand, and your self-assessment still speaks for you every time a prime checks your posture. Contractors who read the memo as a stop sign will lose ground to the ones who read it correctly, as time to get further ahead.
Use the window. Keep your controls live, keep your score honest, and keep your program moving. When the assessors come back, and the structure of the program suggests they will, readiness will separate the companies that win defense work from the ones still explaining why they waited.
Navneet Lounsberry writes on cybersecurity compliance and commercial strategy, most recently with Idenhaus Consulting. She spent more than twenty years in enterprise technology sales and business development with IBM, SAP, and others.
Copyright © 2026, Full Throttle Media, Inc. FTM #fullthrottlemedia #inthespread #sethhorne

