On July 13, 2026, the Department of War (the renamed Department of Defense, still widely referred to as the DoD) announced the immediate suspension of CMMC Phase 2. The announcement came from Davies, the DoW Chief Information Officer, and Duffey, the Under Secretary of War for Acquisition and Sustainment. It is the most consequential shift in the program since the final rule, and it is already being read in two very different ways.
One reading, loud on social media within hours, is that CMMC is dead. It is not. That reading confuses the certification mechanism with the security requirement, and the two are not the same thing. The DoW paused the part of the program that verifies compliance through a third party. It did not, and legally could not with a memo, repeal the obligation to actually secure covered defense information. That obligation predates CMMC and survives it.
What Actually Changed
The suspension has a specific, bounded scope. Read the list literally, because the space between what was suspended and what was not is where contractors will get into trouble.
- The C3PAO third-party certification mandate is suspended, effective immediately. The requirement to obtain a Level 2 certification from an accredited third-party assessment organization before award is paused. The C3PAO assessment process still exists, but it is no longer a gate the DoW is enforcing while the review runs.
- Pending and future CMMC implementation milestones are suspended. The certification requirements that had been scheduled to appear in solicitations and contracts are on hold. Milestones already written into the phased rollout are frozen pending the review.
- A 60-day CMMC Reform Task Force has been stood up. Its job is to review the program and deliver a report to the DoW CIO with recommendations. Counting from the July 13 announcement, that report is due on or about September 13, 2026.
- An RFI is out, with responses due August 14, 2026. It solicits feedback on assessment cost drivers, third-party assessment capacity, and the line worth reading twice: whether commercial cybersecurity tools and managed services could replace standalone assessments as evidence of compliance. It also asks about the burden of the Phase 1 self-assessment itself, a signal that Phase 1, not just Phase 2, is on the table.
In Davies' own framing, the announcement suspends the certification mechanism, not the cybersecurity obligation. That distinction is the entire story, and it drives everything below.
What Did Not Change. Read This Twice
This is the section that matters most, because it is the one the headlines skip. Nothing in the July 13 announcement altered a single cybersecurity requirement. Every obligation below is exactly as binding today as it was on July 12.
- Phase 1 self-assessment requirements remain in force. If you are in scope for a Level 2 self-assessment, you still owe it. The suspension touched third-party certification, not self-assessment.
- DFARS 252.204-7012 is untouched. Every contractor that receives, stores, processes, or transmits covered defense information is still contractually obligated to implement all 110 controls of NIST SP 800-171. This clause is the legal foundation, and it predates CMMC by years. Our DFARS 7012 compliance guide walks through what the clause actually requires.
- SPRS scores are still required. You must still calculate a score against the 110 requirements and post a current one in the Supplier Performance Risk System. See our SPRS scoring guide for how the 1, 3, and 5-point weighting produces that number.
- The underlying security standard has not moved. NIST SP 800-171 is the same document it was last week. The controls did not get easier, fewer, or optional.
Why It Happened
The suspension did not come out of nowhere. It came out of arithmetic that had become impossible to ignore.
The capacity math. There are fewer than 100 authorized C3PAOs and roughly 600 to 800 credentialed assessors, against a population of more than 80,000 contractors the DoW projects will need a Level 2 assessment. Davies put it bluntly: "the math just simply doesn't math." We ran exactly these numbers on July 6 in our Phase 2 capacity analysis: a handful of assessment firms, a sub-1,000 assessor pool, and a demand curve two orders of magnitude larger. Those are the same figures Davies cited as the reason for the pause. The queue we described as the binding constraint is the constraint the DoW just acted on.
The small-business exodus. SBA data indicated that CMMC compliance costs were pushing companies out of the defense industrial base rather than into it, the opposite of the program's intent. A certification requirement that thins the supplier base it is meant to protect is a policy problem, not just a scheduling one.
Alignment with acquisition reform. The pause fits Secretary Hegseth's Acquisition Transformation Strategy, which prioritizes speed and lowers barriers for small, mid-size, and non-traditional businesses. Duffey framed the task force's job the same way, saying its goal is to "maintain a strict security baseline while removing paralyzing costs and keeping innovators and competition growing in the defense supply chain." Read that carefully: strict security baseline stays, paralyzing costs go. The suspension is less a retreat from cybersecurity than an attempt to find a compliance path that does not choke the industrial base at the assessment bottleneck.
What Contractors Should Do Now
Here is the part that separates the contractors who come out of this ahead from the ones who lose a year. The instruction is simple: do not stop.
Keep doing the self-assessment. It is still a contract condition. The certification pause did not touch DFARS 7012 or your SPRS obligation. If you stand down your compliance program on the strength of a headline, you are walking away from a requirement that is still in your contract. Keep your SPRS self-assessment current and defensible, and make sure the score you post is one you could actually stand behind.
Expect your primes to keep flowing down requirements. The DoW paused its own certification enforcement. It did not tell primes to stop managing their supply-chain risk, and they will not. Compliance language keeps flowing down the tiers regardless of the certification pause. Our subcontractor flow-down guide explains why the contract chain, not the DoW memo, sets your actual obligation.
If you already invested, you are ahead, and Davies said so. The DoW CIO stated explicitly that contractors who have already done the work are better positioned no matter what the task force recommends. Any plausible outcome, whether a streamlined certification, recognition of commercial tools, or a tiered model, still rests on having implemented NIST 800-171. A clean, documented control environment and a live SPRS score are assets under every scenario. Keep your POA&M credible and your evidence organized.
Use the August 14 RFI window. The RFI is not just a bureaucratic formality. It is an open door for small DIB contractors to shape what replaces the current structure. If assessment cost or capacity has hurt your business, this is the moment to say so on the record, while the task force is still writing its recommendations. New to the program? Start with our CMMC overview to ground your response.
What to Watch
The rest of the 60-day review window will decide what CMMC becomes. Four things are worth tracking closely.
- The task force report, due on or about September 13, 2026. The 60-day review is the document that turns "suspended" into a direction. It consolidates the RFI responses and listening-session feedback into recommendations for DoW leadership, and it will signal whether third-party certification returns, and in what form.
- Recognition of commercial tools and managed services. The RFI's most consequential question is whether commercial cybersecurity platforms and managed services can count as compliance evidence in place of standalone assessments. If the answer is yes, the entire compliance model shifts.
- A streamlined or tiered certification model. Watch for a lighter-weight or risk-tiered structure replacing the current single C3PAO path, a likely middle ground between full third-party certification and pure self-attestation.
- The NIST 800-171 Rev 3 timeline. Any change to the certification structure could ripple into the Rev 3 adoption schedule. Whether the revised standard's rollout speeds up, slows down, or holds steady is worth monitoring alongside the task force's work.
The through-line across all four: the security standard is the stable center of a moving program. The verification wrapper around it is being redesigned. Build to the standard, and you are covered whichever wrapper wins.
We are tracking the 60-day review as it unfolds.
The task force report, the RFI outcome, and any move toward recognizing commercial tools will reshape what compliance looks like. Leave your work email and we will send the analysis the day each development lands. No fear-mongering, just what changed and what to do about it.