The Department has suspended the upcoming CMMC Phase 2 transition and started a 60-day review of the certification program. That is a meaningful change, especially for small defense contractors preparing for a third-party CMMC assessment.
It is not the same as canceling CMMC. It also does not remove the cybersecurity clauses already included in a solicitation, prime contract, or subcontract.
The July 13, 2026 memorandum is unusually direct on this point:
- The November 2026 transition to CMMC Phase 2 is suspended.
- Pending and future CMMC implementation milestones are held in abeyance until further notice.
- Procurement documents should include only the need for CMMC Level 1 or Level 2 self-assessments during the suspension.
- Other contractual cybersecurity clauses remain intact.
- The Department will continue enforcing NIST SP 800-171 Revision 2 through defense industrial base self-assessments and selected government-led assessments.
- DFARS 252.204-7012 remains in effect.
For a small defense contractor, the practical message is simple: the third-party certification timeline changed, but the work of protecting federal contract information and controlled unclassified information did not disappear.
| Paused or uncertain | Still applies when required by the solicitation or contract |
|---|---|
| The November 2026 Phase 2 transition | CMMC Level 1 or Level 2 self-assessments during the interim period |
| Broader rollout of C3PAO certification assessments | DFARS 252.204-7012 safeguarding and incident reporting |
| Future CMMC implementation milestones pending reform guidance | Current NIST SP 800-171 DoD Assessments and SPRS scores under DFARS 7019/7020 |
| The former certification schedule | Protection of FCI and CUI, documentation, evidence, and applicable flow-downs |
What did DoD actually suspend?
The Department suspended the planned move into CMMC Phase 2, which was expected to expand the use of CMMC certification requirements in solicitations and contracts beginning in November 2026.
Under the phased rollout, Phase 2 would have increased the number of contracts requiring:
- CMMC Level 2 certification assessments performed by a Certified Third-Party Assessment Organization, or C3PAO;
- government-led assessments for certain higher-risk programs; and
- an active certification status as a condition of contract award or option exercise when specified.
The memorandum places that expansion on hold while a CMMC Review and Reform Task Force conducts a top-to-bottom, 60-day review. The task force is expected to recommend a revised approach that reduces barriers for small, medium, and nontraditional contractors while maintaining cybersecurity and operational resilience.
This creates uncertainty about the future certification model. Third-party assessment timing, contract categories, implementation phases, and other details could change after the review.
What the announcement does not do is declare that CMMC has been repealed or that defense contractors may stop protecting government information.
What remains under CMMC Phase 1?
The memorandum says program managers and requiring activities should continue including the need for CMMC Level 1 or Level 2 self-assessments in procurement requests and requirements documents.
Which level applies depends on the contract and the information involved:
- CMMC Level 1 generally applies when a contractor handles Federal Contract Information, or FCI, but not CUI. It focuses on basic safeguarding requirements.
- CMMC Level 2 applies when a contractor processes, stores, or transmits CUI and the solicitation or contract requires a Level 2 self-assessment rather than a certification assessment.
A self-assessment is not permission to estimate, round up, or mark a requirement complete because a tool was purchased. The contractor still needs to determine whether each applicable requirement is implemented and supported by evidence.
Depending on the requirement, useful evidence may include:
- a current system security plan;
- policies and operating procedures;
- system configurations and security-policy exports;
- user and administrator access records;
- training records;
- vulnerability, patching, logging, and incident-response records;
- network and data-flow diagrams;
- asset inventories; and
- records showing that controls operate as described.
CMMC self-assessment and affirmation requirements should also be reviewed separately from the older NIST SP 800-171 DoD Assessment Methodology used for DFARS and SPRS. They overlap, but they are not interchangeable labels for one filing. Contractors should verify exactly which submission, affirmation, assessment level, and renewal cycle their solicitation or contract requires.
DFARS 252.204-7012 still applies when it is in your contract
The July memorandum specifically states that the cybersecurity requirements in DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting, remain in effect.
For covered contractor information systems, this clause can require a contractor to:
- Provide adequate security for systems that process, store, or transmit covered defense information.
- Implement the applicable NIST SP 800-171 security requirements.
- Ensure an external cloud service provider handling covered defense information meets the contract’s applicable cloud-security requirements, including FedRAMP Moderate-equivalent requirements where the clause calls for them.
- Rapidly report covered cyber incidents to DoD. Under the clause, “rapidly report” means within 72 hours of discovery.
- Preserve affected system images and relevant monitoring or packet-capture data for at least 90 days after submitting the incident report.
- Flow the clause down to applicable subcontractors when subcontract performance involves covered defense information or operationally critical support.
These are contractual duties. A policy announcement about the CMMC rollout does not automatically remove a clause from an existing contract.
Contractors should review the actual language in each contract and subcontract instead of relying on a headline, social-media post, or sales email. If the clause is present, assume it still matters unless the contracting officer provides an authorized modification or other written direction.
Your SPRS and NIST SP 800-171 assessment obligations may also remain
Two related DFARS provisions continue to matter for many contractors:
DFARS 252.204-7019
This solicitation provision requires an offeror that must implement NIST SP 800-171 to have a current NIST SP 800-171 DoD Assessment for each relevant covered contractor information system.
The official provision says the assessment generally must be no more than three years old unless the solicitation specifies a shorter period. The summary-level score must be posted in the Supplier Performance Risk System, or SPRS, for the systems relevant to the offer.
DFARS 252.204-7020
This contract clause defines Basic, Medium, and High NIST SP 800-171 DoD Assessments. It also requires contractors to provide the access needed for the government to conduct a Medium or High Assessment when necessary.
It includes SPRS reporting mechanics and an applicable subcontract flow-down requirement.
The key distinction is that suspending Phase 2 third-party CMMC certification does not, by itself, erase the separate DFARS assessment framework. A contractor may still need a current, supportable SPRS score to compete for or perform covered work.
An SPRS score should reflect the system described in the associated system security plan and the controls actually implemented. If the supporting documentation does not match the score, the contractor has both a compliance problem and a business risk. Unsupported representations can lead to questions during a government assessment, contract review, investigation, or cyber incident.
Does the suspension mean contractors can stop preparing for CMMC?
No. It means contractors should adjust the plan, not abandon it.
The final shape and timing of CMMC Phase 2 may change. That may affect when a contractor hires a C3PAO or schedules a formal certification assessment. It does not justify dismantling security controls, stopping evidence collection, or ignoring unresolved NIST SP 800-171 gaps.
There are several reasons to keep moving:
- Phase 1 self-assessments remain part of the Department’s interim approach.
- Existing DFARS clauses remain enforceable when included in the contract.
- The government may still conduct selected assessments.
- Prime contractors may impose cybersecurity or assessment requirements on suppliers, subject to the subcontract and procurement terms.
- CUI still needs protection whether or not a C3PAO is scheduled.
- Rebuilding documentation and evidence after a long pause is usually more expensive than maintaining it.
- The reform process may change the certification model without reducing the underlying need for measurable cybersecurity.
The safer response is to separate deadline-driven certification work from ongoing contractual security work. The first may be rescheduled. The second continues.
A practical example
Suppose a 25-person machine shop expected to need a C3PAO assessment in 2027. The Phase 2 suspension may change when that assessment is required. But if the shop currently performs a contract containing DFARS 252.204-7012 and receives covered defense information, it still needs to protect that information, maintain the applicable NIST SP 800-171 safeguards, preserve a supportable assessment record, and be ready to report a covered cyber incident. The assessment calendar moved; the contract did not vanish.
What small defense contractors should do now
1. Review the clauses in each contract
Create a contract-by-contract list of the cybersecurity provisions that apply. Look for DFARS 252.204-7012, 252.204-7019, 252.204-7020, CMMC clauses, incident-reporting requirements, cloud restrictions, and subcontract flow-down language.
Do not assume every contract has identical requirements.
2. Confirm whether you handle FCI, CUI, or both
Your obligations and technical scope depend heavily on the information you receive, create, process, store, or transmit.
If the organization does not know where CUI enters the business, who can access it, or which systems contain it, that is the first problem to solve. A narrow, well-defined boundary can be easier to secure and document than the entire company network.
Our guide to CMMC enclave scope and boundary decisions explains why this distinction matters.
3. Validate the SPRS score against real evidence
Compare the submitted score to the current system security plan, implemented safeguards, technical configurations, and operating records.
Do not focus only on reaching a higher number. Focus on producing a score that can be explained and defended. If gaps exist, document them accurately and determine whether a plan of action is permitted for the requirement and business situation involved.
4. Keep the SSP and evidence current
A system security plan should describe the real environment, not the environment the company hopes to deploy later.
Update it when systems, cloud services, users, boundaries, responsibilities, or control implementations change. Maintain evidence as part of normal operations instead of trying to recreate months of records immediately before an assessment.
5. Test the 72-hour incident-reporting process
Identify who decides whether an event is reportable, who has access to the reporting system, who gathers the required facts, and who preserves affected images and logs.
A 72-hour deadline is difficult to meet if the response process starts with finding the contract or locating the person who owns the reporting credential.
6. Review subcontractor flow-downs
Prime contractors should identify which suppliers receive covered defense information or provide operationally critical support. Subcontractors should verify what the prime has flowed down and whether additional requirements were added to the subcontract.
Do not rely on verbal statements about what is or is not required.
7. Delay irreversible assessment spending—not necessary security work
If a C3PAO assessment was scheduled specifically around the former Phase 2 timeline, review the timing, cancellation terms, and business need before committing additional funds.
At the same time, continue the work that supports contract performance: scoping, access control, MFA, secure configuration, logging, patching, incident response, documentation, and evidence collection.
What this means for a CMMC enclave decision
The suspension does not automatically make a CMMC enclave unnecessary.
An enclave is a scoping and risk-management decision. It can help a small contractor isolate CUI from the broader business environment, reduce the number of systems and people in scope, and make security responsibilities easier to document.
Whether an enclave makes financial sense depends on:
- where CUI is stored and processed;
- how many users need access;
- whether the existing environment can satisfy applicable requirements;
- cloud and licensing requirements;
- the cost of remediating the full business network; and
- the contracts the company intends to pursue.
Use our plain-English guide, Do I Need a CMMC Enclave?, before assuming that either a full-environment approach or an enclave is automatically the right answer.
Frequently asked questions
Was CMMC canceled?
No. The July 13 memorandum suspended the upcoming Phase 2 transition and future implementation milestones while the Department conducts a 60-day review. It continued the use of CMMC Level 1 and Level 2 self-assessments during the suspension.
Do we still have to follow NIST SP 800-171?
If an applicable contract clause requires it, yes. The memorandum says the Department will continue enforcing baseline compliance with NIST SP 800-171 Revision 2 during the suspension. Your contract and authorized contracting-officer direction control the specific obligation.
Do we still need an SPRS score?
If DFARS 252.204-7019 applies to the solicitation, a current NIST SP 800-171 DoD Assessment summary score in SPRS may remain a condition of award. Review the solicitation, relevant systems, assessment date, and any shorter validity period specified.
Are C3PAO assessments still required?
The broader Phase 2 rollout of third-party certification requirements has been suspended. Contractors should review the exact solicitation, contract, subcontract, and any written contracting-officer guidance before canceling or continuing a scheduled assessment.
Can a prime contractor still ask a subcontractor for cybersecurity evidence?
A prime may include cybersecurity, flow-down, or supplier-risk requirements in a subcontract. Whether a specific demand is binding depends on the subcontract and applicable flow-downs. Ask for the requirement in writing and review it against the contract.
Should we pause our CMMC project?
Pause only work that depends entirely on the superseded certification schedule. Continue protecting CUI, correcting material gaps, maintaining documentation, validating the SPRS score, and preparing for incident reporting.
The best next step: establish a defensible baseline
The most useful question is no longer, “How fast can we get a certificate?” It is:
Can we show which requirements apply, what systems are in scope, what is implemented, what is missing, and what evidence supports our statements?
Office Heroes’ Compliance Readiness Baseline helps small defense contractors answer those questions without pretending the Phase 2 timeline is settled. We review the environment, contract drivers, CUI boundary, NIST SP 800-171 posture, SPRS support, and practical next steps.
If a contained environment may reduce scope and cost, you can also review the Office Heroes CMMC Enclave.
Schedule a Compliance Readiness Baseline
Sources
- Department of War, July 13, 2026 announcement — Forging the Arsenal of Freedom: Department of War Suspends CMMC Phase II Requirements
- Department of War, July 13, 2026 memorandum, Removing Barriers to Defense Industrial Base Expansion: Immediate Suspension and Strategic Review of Cybersecurity Maturity Model Certification Requirements.
- DFARS 252.204-7012 — Safeguarding Covered Defense Information and Cyber Incident Reporting
- DFARS 252.204-7019 — Notice of NIST SP 800-171 DoD Assessment Requirements
- DFARS 252.204-7020 — NIST SP 800-171 DoD Assessment Requirements
This article provides general information, not legal advice. Contractors should review their solicitations, contracts, subcontracts, and authorized contracting-officer guidance with qualified advisors.
Peter Zendzian is the Founder & Chief Cybersecurity Strategist at Office Heroes, a cybersecurity-focused Managed IT Service Provider helping CPA firms, law firms, credit unions, defense contractors, and small regulated businesses stay secure, compliant, and audit-ready.
Peter served more than 20 years in the U.S. Navy, retiring as a Chief Petty Officer after leading secure communications, cybersecurity operations, and technology teams across joint military environments. His background in classified systems, compliance, risk management, and operational security directly shapes Office Heroes’ modern, practical approach to protecting small businesses.
He is the co-author of two bestselling cybersecurity books:
Your Business Must Have a Cybersecurity Risk Assessment
Cybersecurity Essentials for Small Businesses
Peter is a trusted advisor to business owners and a subject matter expert in:
FTC Safeguards Rule compliance
GLBA compliance
NIST SP 800-171
CMMC Level 2 readiness
Microsoft 365 and Azure security
Endpoint protection, EDR, and vulnerability management
Data protection, disaster recovery, and cloud resilience
Secure remote access and Azure Virtual Desktop
Small business workflow automation
Certifications & Recognition
Retired U.S. Navy Chief Petty Officer (E-7)
DoD Cyber & Communications Leadership Training
20+ years managing classified systems and secure communications
Co-author of two bestselling cybersecurity books
Expert in FTC Safeguards, GLBA, NIST SP 800-171, and CMMC Level 2
Microsoft 365 and Azure security practitioner
Specialist in data protection, disaster recovery, and ransomware defense
Peter’s mission is simple: to make world-class cybersecurity, compliance, and IT support accessible to small businesses that don’t have internal IT or security teams — giving them the protection, clarity, and confidence they deserve.
- Peter Zendzian


