Breaking Analysis

Department of War Suspends CMMC Phase 2: What Changed, What Didn't, and What Contractors Should Do

Published: 2026-07-13 · Last updated: 2026-08-04

What Changed What Did Not Change Why It Happened What to Do Now What to Watch

On July 13, 2026, the Department of War (the renamed Department of Defense, still widely referred to as the DoD) announced the immediate suspension of CMMC Phase 2. The announcement came from Davies, the DoW Chief Information Officer, and Duffey, the Under Secretary of War for Acquisition and Sustainment. It is the most consequential shift in the program since the final rule, and it is already being read in two very different ways.

One reading, loud on social media within hours, is that CMMC is dead. It is not. That reading confuses the certification mechanism with the security requirement, and the two are not the same thing. The DoW paused the part of the program that verifies compliance through a third party. It did not, and legally could not with a memo, repeal the obligation to actually secure covered defense information. That obligation predates CMMC and survives it.

The one-sentence version
The certification mechanism is under review. The security requirements are not. Contractors who treat this as permission to stop are making a mistake; contractors who already invested are ahead regardless of what the task force recommends.

What Actually Changed

The suspension has a specific, bounded scope. Read the list literally, because the space between what was suspended and what was not is where contractors will get into trouble.

  • The C3PAO third-party certification mandate is suspended, effective immediately. The requirement to obtain a Level 2 certification from an accredited third-party assessment organization before award is paused. The C3PAO assessment process still exists, but it is no longer a gate the DoW is enforcing while the review runs.
  • Pending and future CMMC implementation milestones are suspended. The certification requirements that had been scheduled to appear in solicitations and contracts are on hold. Milestones already written into the phased rollout are frozen pending the review.
  • A 60-day CMMC Reform Task Force has been stood up. Its job is to review the program and deliver a report to the DoW CIO with recommendations. Counting from the July 13 announcement, that report is due on or about September 13, 2026.
  • An RFI is out, with responses due August 14, 2026. It solicits feedback on assessment cost drivers, third-party assessment capacity, and the line worth reading twice: whether commercial cybersecurity tools and managed services could replace standalone assessments as evidence of compliance. It also asks about the burden of the Phase 1 self-assessment itself, a signal that Phase 1, not just Phase 2, is on the table.

In Davies' own framing, the announcement suspends the certification mechanism, not the cybersecurity obligation. That distinction is the entire story, and it drives everything below.

What Did Not Change. Read This Twice

This is the section that matters most, because it is the one the headlines skip. Nothing in the July 13 announcement altered a single cybersecurity requirement. Every obligation below is exactly as binding today as it was on July 12.

  • Phase 1 self-assessment requirements remain in force. If you are in scope for a Level 2 self-assessment, you still owe it. The suspension touched third-party certification, not self-assessment.
  • DFARS 252.204-7012 is untouched. Every contractor that receives, stores, processes, or transmits covered defense information is still contractually obligated to implement all 110 controls of NIST SP 800-171. This clause is the legal foundation, and it predates CMMC by years. Our DFARS 7012 compliance guide walks through what the clause actually requires.
  • SPRS scores are still required. You must still calculate a score against the 110 requirements and post a current one in the Supplier Performance Risk System. See our SPRS scoring guide for how the 1, 3, and 5-point weighting produces that number.
  • The underlying security standard has not moved. NIST SP 800-171 is the same document it was last week. The controls did not get easier, fewer, or optional.
The trap to avoid
A contractor who reads "Phase 2 suspended" as "compliance suspended" is misreading a certification pause as a legal waiver. DFARS 7012 is in your contract right now. Failing to meet it, or misrepresenting that you meet it in SPRS, carries the same False Claims Act exposure it always did. The suspension changed the verification step, not the duty.

Why It Happened

The suspension did not come out of nowhere. It came out of arithmetic that had become impossible to ignore.

The capacity math. There are fewer than 100 authorized C3PAOs and roughly 600 to 800 credentialed assessors, against a population of more than 80,000 contractors the DoW projects will need a Level 2 assessment. Davies put it bluntly: "the math just simply doesn't math." We ran exactly these numbers on July 6 in our Phase 2 capacity analysis: a handful of assessment firms, a sub-1,000 assessor pool, and a demand curve two orders of magnitude larger. Those are the same figures Davies cited as the reason for the pause. The queue we described as the binding constraint is the constraint the DoW just acted on.

The small-business exodus. SBA data indicated that CMMC compliance costs were pushing companies out of the defense industrial base rather than into it, the opposite of the program's intent. A certification requirement that thins the supplier base it is meant to protect is a policy problem, not just a scheduling one.

Alignment with acquisition reform. The pause fits Secretary Hegseth's Acquisition Transformation Strategy, which prioritizes speed and lowers barriers for small, mid-size, and non-traditional businesses. Duffey framed the task force's job the same way, saying its goal is to "maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain." Read that carefully: strict security baseline stays, paralyzing costs go. The suspension is less a retreat from cybersecurity than an attempt to find a compliance path that does not choke the industrial base at the assessment bottleneck.

What Contractors Should Do Now

Here is the part that separates the contractors who come out of this ahead from the ones who lose a year. The instruction is simple: do not stop.

Keep doing the self-assessment. It is still a contract condition. The certification pause did not touch DFARS 7012 or your SPRS obligation. If you stand down your compliance program on the strength of a headline, you are walking away from a requirement that is still in your contract. Keep your SPRS self-assessment current and defensible, and make sure the score you post is one you could actually stand behind.

Expect your primes to keep flowing down requirements. The DoW paused its own certification enforcement. It did not tell primes to stop managing their supply-chain risk, and they will not. Compliance language keeps flowing down the tiers regardless of the certification pause. Our subcontractor flow-down guide explains why the contract chain, not the DoW memo, sets your actual obligation.

If you already invested, you are ahead, and Davies said so. The DoW CIO stated explicitly that contractors who have already done the work are better positioned no matter what the task force recommends. Any plausible outcome, whether a streamlined certification, recognition of commercial tools, or a tiered model, still rests on having implemented NIST 800-171. A clean, documented control environment and a live SPRS score are assets under every scenario. Keep your POA&M credible and your evidence organized.

Use the August 14 RFI window. The RFI is not just a bureaucratic formality. It is an open door for small DIB contractors to shape what replaces the current structure. If assessment cost or capacity has hurt your business, this is the moment to say so on the record, while the task force is still writing its recommendations. New to the program? Start with our CMMC overview to ground your response.

Where 1TEN fits
The security work is the durable asset here, and it is exactly the work that does not go away no matter how the task force rules. 1TEN maps your environment to all 110 NIST 800-171 requirements, produces an SSP that matches reality, keeps a defensible POA&M, and shows your live SPRS score. Whatever the reformed program looks like, you are already meeting the standard underneath it.

What to Watch

The rest of the 60-day review window will decide what CMMC becomes. Four things are worth tracking closely.

  • The task force report, due on or about September 13, 2026. The 60-day review is the document that turns "suspended" into a direction. It consolidates the RFI responses and listening-session feedback into recommendations for DoW leadership, and it will signal whether third-party certification returns, and in what form.
  • Recognition of commercial tools and managed services. The RFI's most consequential question is whether commercial cybersecurity platforms and managed services can count as compliance evidence in place of standalone assessments. If the answer is yes, the entire compliance model shifts.
  • A streamlined or tiered certification model. Watch for a lighter-weight or risk-tiered structure replacing the current single C3PAO path, a likely middle ground between full third-party certification and pure self-attestation.
  • The NIST 800-171 Rev 3 timeline. Any change to the certification structure could ripple into the Rev 3 adoption schedule. Whether the revised standard's rollout speeds up, slows down, or holds steady is worth monitoring alongside the task force's work.

The through-line across all four: the security standard is the stable center of a moving program. The verification wrapper around it is being redesigned. Build to the standard, and you are covered whichever wrapper wins.

Update: the July 30 SBA roundtable
On July 30, 2026 the SBA Office of Advocacy hosted an off-the-record roundtable on the DoW's RFI, with more than 600 registrants and roughly 509 participants at its peak. The DoW confirmed the program is paused in Phase 1 self-attestation, that Phase 2 remains on hold, and that it had already received more than 125 RFI responses feeding the September report. The recurring small-business themes were the ones the RFI targets: assessment costs in the $35,000 to $50,000-plus range, FIPS-validation and FedRAMP/GCC High expense, inconsistent CUI marking that forces over-scoping, and requests for phased or maturity-based implementation. Two points cut against the "CMMC is dead" reading: participants warned the word "suspension" could discourage contractors who have prepared for years, and noted that prime-contractor flow-down has not stopped despite the pause. SBA Advocacy is filing its own comment letter and urged contractors to submit to both SBA and the DoW before the August 14 deadline.

Frequently Asked Questions

Is CMMC cancelled?

No. On July 13, 2026 the DoW suspended the Phase 2 third-party certification mandate and launched a 60-day review. It did not repeal any cybersecurity requirement. The obligation to protect covered defense information under DFARS 252.204-7012 and NIST SP 800-171 predates CMMC and remains in force. What is paused is the mechanism for verifying compliance through a C3PAO, not the compliance itself.

Do I still have to do a self-assessment?

Yes. Phase 1 self-assessment requirements remain in force. If your contract contains DFARS 252.204-7012, you are still required to implement all 110 NIST SP 800-171 controls, maintain a System Security Plan and POA&M, and post a current score in SPRS. None of that changed on July 13.

Does the suspension change DFARS 252.204-7012?

No. DFARS 252.204-7012 is untouched. Every contractor that handles covered defense information is still contractually obligated to implement NIST SP 800-171 and report a SPRS score. The DoW CIO framed the announcement as suspending the certification mechanism, not the cybersecurity obligation.

What is the 60-day task force and the August 14 RFI?

The DoW stood up a 60-day CMMC Reform Task Force to review the program. It issued an RFI with responses due August 14, 2026, soliciting feedback on assessment cost drivers, third-party assessment capacity, and whether commercial cybersecurity tools and managed services could substitute for standalone C3PAO assessments. The window is an opportunity for small DIB contractors to shape what comes next.

Should I stop my compliance work?

No. The self-assessment is still a contract condition, and primes are continuing to flow down compliance requirements regardless of the DoW's certification pause. The DoW CIO stated that contractors who already invested are better positioned no matter what the task force recommends. Treating the suspension as permission to stop is a mistake.

Built for the DIB.

1TEN tracks your control posture across all 110 NIST SP 800-171 requirements and generates C3PAO-ready documentation automatically.

Request a Demo