CMMC Level 2* Suspension: that is the headline many defense contractors have seen this summer, but CMMC is not dead. On July 13, 2026, the Department of War suspended Phase 2 of the Cybersecurity Maturity Model Certification program, which had been scheduled to take effect on November 10, 2026. That is a real change and it matters. But it changed far less than most contractors think.
Here is the distinction that everything else depends on. The Department suspended a verification mechanism. It did not suspend the security requirement. If you handle Controlled Unclassified Information for a defense customer, what you legally owe today is almost exactly what you owed on July 12.
This post explains what was suspended, what is still fully enforced, what happens next, and how to decide what to pause and what to keep funding. Plain language, no hedging.
What Was Suspended, and What Was Not
Two memoranda came out of the Department on July 13, 2026. One, from the Department CIO, ordered the suspension and stood up a CMMC Reform Task Force. The second gave contracting officers instructions on how to handle solicitations and contracts already in flight.
Suspended
Level 2 third-party certification. The requirement to obtain a CMMC Level 2* certification from an accredited C3PAO as a condition of contract award is paused.
Level 3 assessments. DIBCAC-led Level 3 assessment requirements are paused as well.
Phases 3 and 4. The suspension is broader than the headlines suggested. All pending and future CMMC implementation milestones are frozen until further notice, not just the November date.
Active solicitations. Contracting officers were directed to amend solicitations carrying Level 2 C3PAO or Level 3 requirements to remove those designations as soon as possible.
Existing contracts. Modifications removing suspended requirements are to be issued before the next option period or the next scheduled administrative modification.
Still Fully in Force
This is the part the headlines buried.
CMMC Phase 1. Level 1 and Level 2 self-assessments are untouched. New solicitations can still designate Level 1 (Self) or Level 2 (Self).
NIST SP 800-171 Revision 2. All 110 controls still apply. Note that Level 2 maps to Revision 2, not Revision 3, under the controlling rule.
DFARS 252.204-7012. The safeguarding and cyber incident reporting clause is intact, including the 72-hour incident reporting obligation.
SPRS scores and annual affirmations. You still post your score. A senior official still signs the affirmation. Both remain conditions of award eligibility.
DFARS 252.204-7025 and 252.204-7021. The solicitation provision that puts you on notice of the required CMMC level, and the contract clause that governs compliance during performance, both still exist. Read your solicitation rather than assuming.
False Claims Act exposure. The Department of Justice Civil Cyber-Fraud Initiative did not pause. More on this below, because it is the real risk right now.
32 CFR Part 170. The CMMC program rule was not repealed. This was a policy memo, not a rulemaking, and a memo can be reversed as quickly as it was issued.
Why the Rule Still Binds You Even Though the Memo Says Otherwise
There is a technical point here that trips up a lot of compliance leads, and it is worth being precise about.
A memo changes what contracting officers are directed to do going forward. It does not change the law, and it does not retroactively rewrite a clause that is already in your awarded contract. A clause written into an existing contract governs until a contracting officer formally modifies it. If you have a CMMC requirement sitting in an awarded contract today, the right move is to call your contracting officer and ask, not to assume it evaporated on July 13.
The same logic applies to your prime. Prime contractors can flow down whatever cybersecurity requirements they choose, and most are holding their flow-down obligations steady because their own contract risk did not change in July. If you are working under multiple primes, the strictest requirement governs your posture. You cannot build a compliance program around your most lenient customer.
And if silence from your prime feels like permission to stop, it is not. Under review is functionally the same as silence.
The Enforcement Risk Went Up, Not Down
This is the part almost nobody leads with, and it is the most important thing in this post.
Remove the third-party assessor from the process and you have not removed the accountability. You have moved it. When a C3PAO validates your environment, an independent party shares the judgment call. Without that assessment, the only signature certifying your security posture is your own, and that signature carries legal weight.
The consequences are not hypothetical. In June 2026, the Department of Justice settled a False Claims Act case with a defense contractor for just over $507,000. The company had reported a perfect NIST SP 800-171 self-assessment score of 110 in SPRS. A later assessment by DIBCAC, the government's own assessment arm, scored the same environment at negative 170. The company did not admit guilt. The settlement still cost more than the Department's own modeled figure for a full three-year Level 2 assessment cycle.
Read that gap again. A self-reported 110 against a government-assessed negative 170. That is the exposure created when a score reflects intention rather than reality.
So if your SPRS score is optimistic, the suspension did not protect you. It removed the mechanism that would have surfaced the discrepancy in a controlled setting, and left the affirmation signature exactly where it was. Treating the pause as a reason to slow down cybersecurity investment walks you toward liability, not away from it.
What to Pause and What to Keep Funding
Most contractors are asking the wrong question. The question is not whether to continue your CMMC program. It is which parts of it were certification spend and which parts were security spend.
For a lot of organizations those two things were one project with one budget line and one name. That is the failure mode to avoid. If you halt the CMMC program and inadvertently halt your NIST 800-171 remediation because the program and the remediation were the same line item, you have created a compliance gap and an enforcement exposure at the same time.
If you cannot currently separate certification-specific spend from control-implementation spend, that inability is itself a finding worth writing down.
Reasonable to pause
Keep funding: no exceptions
Scheduling and paying for a C3PAO assessment where the contract requirement is suspended and no customer is demanding it
Implementation and remediation of the 110 NIST SP 800-171 controls
Consulting engagements scoped specifically to certification readiness rather than control implementation
SPRS score accuracy, and correcting any score that overstates your posture
Capital spend justified solely by the November 10, 2026 date
Annual affirmations and the evidence that supports them
Assessment-cycle travel, scheduling, and assessor coordination overhead
Incident detection and the 72-hour reporting capability under DFARS 252.204-7012
Certification-specific project management overhead
System Security Plan and POA&M currency: your gap assessment did not stop being a written record of your shortfalls
N/A
Your compliance team. Skilled people are the hardest thing to rebuild when the requirement returns.
The Trap for Mixed Civilian and Defense Portfolios
Here is a development most CMMC coverage skipped entirely, and it matters enormously if you sell to civilian agencies as well as defense.
On June 23, 2026, the FAR Council published a proposed rule that would extend safeguarding and incident reporting requirements to all Controlled Unclassified Information handled under all federal contracts, not just Department of War contracts. If it is implemented as drafted, NIST SP 800-171-derived requirements would apply across the entire federal contracting ecosystem. That proposal also references the newer Revision 3 baseline, which the Department has not adopted for CMMC and would need separate rulemaking to adopt.
The implication is uncomfortable and worth stating plainly. If you hold both defense and civilian federal work, any narrowing of CMMC scope on the defense side may deliver no meaningful relief at all, because a comparable obligation could arrive government-wide through a completely different regulatory door.
A contractor who stands down their 800-171 program because of the CMMC pause, and then meets the FAR CUI rule eighteen months later with nothing built, has not saved money. They have deferred the same spend into a shorter window.
Two regulatory threads, tracked together. That is the correct posture.
What Happens Next
The CMMC Reform Task Force was given a 60-day mandate from July 13, which puts its report to the Department CIO in the middle of September 2026. The public Request for Information, titled Reforming CMMC and Reducing Compliance Burden for the Defense Industrial Base, closed on August 14, 2026.
The Under Secretary of War for Acquisition and Sustainment framed the intent directly at the time of the announcement: the Department is not relaxing the NIST standards, it is removing the bureaucracy of the third-party assessment. Officials have also declined to rule out narrowing, restructuring, or ending the program once the review concludes.
For planning purposes, keep three things in view. Watch for a class deviation, a DFARS rule change, or an amendment to 32 CFR Part 170, those are the mechanisms that would constitute genuine legal change. Expect that any new framework will require formal rulemaking before it is enforceable in a contract, and rulemaking takes months regardless of what the task force recommends. And treat mid-September as a report date, not a decision date. Formal determinations could plausibly slip to late 2026 or into 2027.
What this means for CMMC updates in 2026
Build your compliance program around the controls, not the calendar. Every organization that anchored its plan to the November 10, 2026 date has now had to rebuild that plan. Organizations that anchored to NIST SP 800-171 implementation have had to change nothing.
This is the practical test of whether your program was designed to survive a policy update.
The No-Regrets Position
There is one posture that is correct under every plausible outcome of the reform review, whether Phase 2 returns intact, returns narrowed, is replaced by an enhanced self-attestation model, or is scrapped entirely.
Make your SPRS score true. Verify that it reflects your actual environment. If it is inflated, correct it now, before an investigation or a whistleblower surfaces the gap. The affirmation signature is a personal exposure for the official who signs it.
Keep implementing the 110 controls. They are required today and they are the floor under every version of this program that could emerge.
Keep your documentation current. SSP, POA&M, and the evidence behind both. Documentation is what turns a claim into a defensible position.
Separate your budget lines. Certification spend and control spend are different decisions. Make them separately.
Read your actual contracts. Not the news. Your obligations live in your clauses and your prime flow-downs, and those govern until formally modified.
Track the FAR CUI rule alongside CMMC. Especially if you serve civilian agencies.
None of that is wasted effort under any scenario. All of it improves your actual defensive posture rather than only your audit posture, which, judging by the RFI's own questions about which controls deliver meaningful risk reduction, is the direction the Department is heading anyway.
How KSG Approaches This
Kaizen Solutions Group has secured federal and state government systems since 2016. We are an SBA 8(a) certified small disadvantaged business, ISO 27001:2022, ISO 9001:2015 and ISO 20000-1:2018 certified, and we hold GSA HACS designations across all five categories: Risk and Vulnerability Assessment, High Value Asset assessment, Penetration Testing, Incident Response, and Cyber Hunt.
Our position on the current moment is the one this post argues: compliance that only produces paperwork is not worth funding. Compliance that hardens your environment is worth funding regardless of what the reform task force decides.
Our CMMC Level 2* readiness practice is built around control implementation, not certificate chasing. That distinction is exactly why the July suspension did not disrupt how we scope engagements. The work we do, CUI boundary scoping, gap assessment against all 110 NIST SP 800-171 controls, System Security Plan and POA&M development, and remediation, is required today and will remain required under any reformed framework.
Where we typically start
Gap assessment against all 110 NIST 800-171 controls: including an honest reconciliation of your assessed posture against your posted SPRS score. If those two numbers disagree, that is the first thing to fix.
SSP and POA&M development: documentation that holds up under a Department of Defense audit or a DIBCAC review, not just an internal one.
Risk management and POA&M analytics: continuous monitoring, vulnerability and patch management, supply chain risk (C-SCRM), and KRI/KPI dashboards so remediation progress is visible to leadership rather than buried in a spreadsheet.
Security operations and remediation delivery: SOC monitoring, SIEM and SOAR, penetration testing, incident response, ICAM/IDAM, EDR and DevSecOps. The technical work behind the controls, not just the assessment of them.
Governance and continuous ATO: for organizations that also carry FISMA and Assessment & Authorization obligations on the civilian side of their portfolio.
As an 8(a) contractor, KSG can also receive sole-source awards from federal agencies up to $4.5 million for non-manufacturing services, which removes a procurement step for agencies and primes that need DIB-focused CMMC implementation support moving quickly.
Start with a conversation about your SPRS score
If you are unsure whether your posted score reflects your actual environment, that is the highest-value place to start and the shortest conversation to have.
Talk to our team · Download our capability statement · Explore CMMC Level 2* readiness
Frequently Asked Questions
What is the current CMMC status in 2026?
CMMC Level 2* is suspended, not cancelled. The suspension took effect July 13, 2026 and paused the requirement for third-party C3PAO certification at Level 2 as a condition of award. Phase 1 self-assessment requirements remain in force, and 32 CFR Part 170 has not been repealed. A CMMC Reform Task Force review reports to the Department CIO in mid-September 2026, and any resulting framework change would require formal rulemaking before it becomes enforceable.
Is CMMC still being enforced after the Phase 2 suspension?
Yes. The certification mechanism was paused; the underlying obligations were not. NIST SP 800-171 Revision 2, DFARS 252.204-7012, SPRS score submission and annual affirmations all remain enforceable. Department of Justice enforcement under the False Claims Act also continues; the Civil Cyber-Fraud Initiative did not pause, and an inaccurate SPRS score carries federal legal exposure regardless of Phase 2 status.
What was the latest DoD announcement on CMMC?
On July 13, 2026 the Department of War, formerly the Department of Defense, issued two memoranda. The first suspended Phase 2 and established the CMMC Reform Task Force. The second directed contracting officers to amend active solicitations and existing contracts to remove suspended Level 2 C3PAO and Level 3 designations. A public Request for Information followed and closed on August 14, 2026.
What happened to the CMMC 2.0 final rule from 2025?
The CMMC program rule at 32 CFR Part 170 remains on the books. The DFARS rule implementing it in solicitations and contracts, including DFARS 252.204-7025 and 252.204-7021, also remains in place. The July 2026 action was a policy memorandum suspending a phase of implementation, not a repeal of the rule. This distinction matters: a memo changes contracting officer discretion, while only a rulemaking changes the law.
What does the CMMC suspension mean for the Defense Industrial Base?
For most DIB contractors, day-to-day obligations are unchanged. You still self-assess against NIST SP 800-171, post a score in SPRS, and file an annual affirmation. What changed is that the scheduled third-party validation step is on hold, which shifts more accountability onto your own certification. Primes can and generally do continue flowing down existing cybersecurity requirements, and where multiple primes are involved the strictest requirement governs.
How does the Department of Defense audit CMMC compliance?
Two paths currently. Self-assessment results are posted to SPRS and are subject to review, and the Department's own assessment arm, DIBCAC, conducts government-led assessments. The Department has indicated it will continue relying on self-assessments and DIBCAC reviews during the suspension. The June 2026 False Claims Act settlement involving a self-reported score of 110 against a DIBCAC-assessed negative 170 illustrates how far apart those two figures can be.
Why is the Pentagon facing enforcement challenges with CMMC?
The publicly stated drivers behind the reform review are compliance cost and administrative burden, particularly for small, medium and non-traditional companies, along with the limited pool of authorized assessors relative to the size of the Defense Industrial Base. The Request for Information asked contractors directly about cost drivers and about which NIST SP 800-171 controls actually deliver meaningful risk reduction, which signals an interest in a leaner verification model rather than a lower security standard.
Should we pause our CMMC readiness project?
Separate the question. Pausing a C3PAO assessment that no customer is currently requiring is defensible. Pausing NIST SP 800-171 control implementation is not, because those controls are required today and underpin every version of the program that could emerge from the reform review. If your organization cannot distinguish certification spend from control-implementation spend, resolving that is the first step.
* Suspension means for Contractor" loading="eager">